bugoverflow

5.4K posts

bugoverflow banner
bugoverflow

bugoverflow

@bugoverfl0w

/dev/null Katılım Ocak 2020
850 Takip Edilen3.2K Takipçiler
Sabitlenmiş Tweet
bugoverflow
bugoverflow@bugoverfl0w·
s1r1us (mohan)@S1r1u5_

Pick a niche, become an expert, find bugs maybe even 0days or reverse n-days, and write blogs. Even if you don’t hit those $100k bounties, it’ll be a stepping stone toward a $100k job. What niche? How to pick? Examples? infosec being so vast from web3 sec to web2, mobile, desktop, recon, client-side, server-side, cryptography and so on. These are umbrella terms, but if we zoom in, there are specific areas where spending a lot of focused time will make you a top 20 expert -- 100% sure. The key thing is, that the current top 20 experts in any niche will eventually be replaced as they get bored or burned out. This leaves room for you, and the easiest way to pick a niche is to learn from an existing expert in the niche, take inspiration, and grind to build on top of it. 1. For instance, I got into the client-side JS niche by following @terjanq’s work. From there, I went down even further to focus specifically on ElectronJS. 2. Another example: @rootxharsh and @iamnoooob their niche is in reversing n-days and finding new ones based on that knowledge. I don’t think anyone in India can compete with them on reversing n-days, writing blogs, and submitting findings to bounty programs. 3. And off the top of my head, @ajxchapman, from his tweets, seems to have a specific niche in V8 n-day exploits. I don’t think there’s anyone else in the web security scene who can write V8 exploits 😅. 4. Like @orange_8361 , pick a complex target and grind on it for months eventually uncovering mind-blowing findings. 5. Or, like @albinowax, choose a complex specification, such as HTTP, and find bugs from every aspect of it from top to bottom (Sorry for tags xD) I could list so many more people, but my point is this: if you look at the top bug bounty hunters or experts, there’s a pattern. Their blogs or tweets consistently focus on a specific niche (or two) for years and years. No one ever becomes a pro in a night. How to Become an Expert in a Specific Niche? Spend a lot of time. There’s no shortcut. Follow the work of the expert you picked for inspiration, read their blogs, dive into the blogs they learned from, and explore everyone else in that specific niche. Solve CTFs and write about them. For example, not to make it all about myself, but just as an example. I’ve read every blog from the people I listed as inspirations(blog.s1r1us.ninja/inspiration) while learning client-side security. If it’s taking time to understand, you’re likely on the right path. That’s where most people give up, so keep pushing. Just dedicating days to it will put you ahead of at least 100 others. It’s that simple. Expert = Spent Time × IQ Find Bugs or 0days, Reverse n-days, and "Write Blogs Once you’re an expert, finding bugs will start to feel natural. But let’s be real, sometimes you might not get lucky. When that happens, reverse other n-days and write about it. I mean write about anything. Nothing gives you as much exposure as writing blogs: you’re helping others, plus you’re building a network that will eventually help you land a $100k job or $100k bounties.

ZXX
0
0
16
4.5K
bugoverflow retweetledi
Intigriti
Intigriti@intigriti·
Collection of all our cheat sheets & methodology cards for exploiting BAC, XSS, CORS, CSRF, etc.! 😎 A thread! 🧵👇
Intigriti tweet media
English
1
29
144
5K
Ynoof
Ynoof@YnoofAssiri·
Eid Mubarak 🌙 Had a great Ramadan spent the nights hunting and found 10 SQLi on @intigriti. SQLi is still alive… even in the AI era. Right, @ngosytuanbug?
Ynoof tweet media
English
13
2
149
4.3K
Shreyas Chavhan
Shreyas Chavhan@shreyas_chavhan·
Imagine the pain of getting a critical (10.0) duped just by one day 😭. PS. (this is a different one than my previous post)
Shreyas Chavhan tweet media
English
9
0
124
4.5K
bugoverflow
bugoverflow@bugoverfl0w·
6k club 🪲🪲🪲
bugoverflow tweet media
English
2
0
47
1K
Z A D D Y
Z A D D Y@Zaddyzaddy·
Over the last 14 days, our BugBunny collective submitted 37 HackerOne reports. So far: 7 payouts received 25 reports still open 7 bounties pending We're opening 10 free beta slots for experienced bounty hunters who want to test BugBunny on permitted targets. Reply "beta" or DM.
Z A D D Y tweet media
English
68
13
146
7.7K
bugoverflow retweetledi
f4lc0n
f4lc0n@al_f4lc0n·
I Saved Injective's $500M. They Pay Me $50K. I like hunting bugs on @immunefi . I'm decent at it. - #1 — Attackathon | Stacks - #2 — Attackathon | Stacks II - #1 — Attackathon | XRPL Lending Protocol - 1 Critical and 1 High from bug bounties (not counting this one) Life was good. Then I found a Critical vulnerability in @injective . This vulnerability allowed any user to directly drain any account on the chain. No special permissions needed. Over $500M in on-chain assets were at risk. I reported it through Immunefi. The next day, a mainnet upgrade to fix the bug went to governance vote. The Injective team clearly understood the severity. Then — silence. For 3 months. No follow up. No technical discussion. Nothing. A few days ago, they notified me of their decision: $50K. The maximum payout for a Critical vulnerability in their bug bounty program is $500K. I disputed it. Silence again. No explanation for the reduced payout. No explanation for the 3 month ghost. No conversation at all. To be clear: the $50K has not been paid either. I've seen others share bad experiences with bug bounty payouts recently. I never thought it would happen to me. I can't force them to do the right thing. But I won't let this be forgotten. I will dedicate 10% of all my future bug bounty earnings to making sure this story stays visible — until Injective pays what I deserve. Full Technical Report: github.com/injective-wall…
English
518
527
4.5K
1.8M
bugoverflow
bugoverflow@bugoverfl0w·
@ynsmroztas Thanks for sharing bro. May I know how can I do this step? # Start proxy in app → tap ▶ START I installed AndroHunter in my non-root device
English
0
0
0
87
Patrickbatman
Patrickbatman@hamidonsolo·
I'm 19, still in engineering school, and I just made $5,879 in February from bug bounties. I used AI to speed up my recon and workflow. No certs. No bootcamp. No CS degree. Here's the breakdown 🧵👇
Patrickbatman tweet media
English
18
17
435
36.5K
bugoverflow
bugoverflow@bugoverfl0w·
@hamidonsolo I am fine. Thanks, I am building automation tools. If you are interested in automation tools, we can discuss together.
English
0
0
0
66