Vitor Falcão "busfactor"

909 posts

Vitor Falcão "busfactor"

Vitor Falcão "busfactor"

@busf4ctor

Brazilian Full-Time Bug Bounty Hunter

Brazil Katılım Kasım 2015
610 Takip Edilen4K Takipçiler
Lupin
Lupin@0xLupin·
WE DID IT ! WE RAISED $5.9M PRE-SEED 🥳🎉🎉
English
77
41
406
33K
Vitor Falcão "busfactor"
Vitor Falcão "busfactor"@busf4ctor·
@0xTib3rius I did that when I had a very specific thing I needed. It requires a lot of steering. Make it update a markdown todo file or something like that so you can keep an eye on how it’s going
English
0
0
2
404
Tib3rius
Tib3rius@0xTib3rius·
I have a /loop in Claude Code that's been running every 30 min, all night. It goes and does research on web app testing techniques, then either writes or updates a set of custom scan checks for Burp Suite. Gonna let it run for a while then see what it's produced. 👀
English
28
13
260
17.7K
Vitor Falcão "busfactor"
Vitor Falcão "busfactor"@busf4ctor·
@nnwakelam You can just ask for that in the issue tracker. You have permission after 90 days, I think. Anyway, no reason not to tell them about it, they always accept it and even ask you to share it with them so they can help you
English
1
0
7
1.2K
Nate
Nate@nnwakelam·
Does anyone know who you speak to to get approval for writing up *.google.com bugs? just security@ ?
English
3
1
25
7.4K
Evan Klein
Evan Klein@EvanKlein338226·
@CristiVlad25 Gold mine when you find them. Internal API routes, auth flows, sometimes hardcoded secrets in the original source. What's your go-to for finding these? I usually start with /main.js.map and /static/js/*.map paths
English
1
0
2
110
🇷🇴 cristi
🇷🇴 cristi@CristiVlad25·
It's always a good idea (and low noise) to check for public source maps before doing blind endpoint discovery.
English
3
0
30
2.4K
Vitor Falcão "busfactor"
Vitor Falcão "busfactor"@busf4ctor·
One of the things I procrastinate on a lot is writing a blog post about dealing with ADHD as a hacker. I'm no specialist, but having had it and treated it for many years (meds and non-med methods), I guess I can help many people
Joseph Thacker@rez0__

@stokfredrik I think this is classic adhd. I feel totally overwhelmed and basically cannot force myself to pick up my office/organize paperwork, but I can build/maintain/enhance full blown hackbot stuff loll

English
1
1
28
2.9K
Vitor Falcão "busfactor"
Vitor Falcão "busfactor"@busf4ctor·
@stokfredrik @rez0__ Even medicated, it's not easy for me to manage life admin stuff. ADHD makes the barrier to starting too high. Try time boxing it: "I'll search for flight tickets for 10 minutes, and if I don't find a good one, I'll try again tomorrow." Giving your brain a finish line helps a lot!
English
0
0
3
77
STÖK ✌️
STÖK ✌️@stokfredrik·
@rez0__ Haha yep, def adhd lyfe, I’m doing pretty well with my strategies and I’m no longer medicating, but this never becomes easier, and the energy required to push through is wild compared to doing things my brain enjoys to do.
English
2
0
6
748
STÖK ✌️
STÖK ✌️@stokfredrik·
Logistics is my kryptonite, I really struggle with simple tasks like booking my trips and hotels. weird how I can be highly functional in one area and a total disaster in the next.
English
4
0
30
3.3K
m0z
m0z@LooseSecurity·
hi @Hacker0x01 one of your triagers is asking me to actually DoS the target website to prove the cache poisoning vulnerability is valid. It might be worth adding to your training that this is totally inappropriate. I have already shown it's possible using an obscure cache key...
English
12
1
98
11.2K
Valentino Massaro
Valentino Massaro@valent1nee·
Why is it so hard to find a decent car driving academy here... It seems way easier to find a decent flight academy.
English
1
0
1
571
Vitor Falcão "busfactor"
Vitor Falcão "busfactor"@busf4ctor·
ok, I need to get this off my chest. I'm hacking on this target, and I found something crazy. It should not work. The question is: WHY did the developers make CSP a feature flag you can disable???? LOL
English
5
0
60
4.1K
joao
joao@pwnj0·
@busf4ctor the real bug bounty tip, how become persistent while hunting is hardest step imho
English
1
0
0
201
Vitor Falcão "busfactor"
Vitor Falcão "busfactor"@busf4ctor·
I used to struggle to read more than 50 pages of a book before giving up and never touching it again, so I started setting micro goals. Reading just five pages a day felt like progress. If I finished five, I was satisfied and could put the book down. By the end of the year, I had read 4,200 pages. I realised that all I needed was to take the pressure off and just begin. It’s like going to the gym. Sometimes just putting on your workout clothes makes it harder to quit, even if you haven’t left the house yet. A few months ago, I used the same approach for bug bounty hunting. I was feeling burned out / jaded, so I set a micro goal to hunt for just one hour each day with real focus. This small goal built momentum, and I often ended up hunting longer. Even when I stopped after an hour, I felt good about it. I found many bugs, succeeded in an LHE, got into more LHEs, and earned some great bounties. Give it a try. Set micro goals and don’t put too much pressure on yourself. Just focus on completing that small goal with real effort, or at least on learning something new. If it doesn’t work out one day, you can always try again the next.
English
7
25
169
8.7K
Vitor Falcão "busfactor"
Vitor Falcão "busfactor"@busf4ctor·
@hugopicanzo It’s enough, maybe not enough to make a living from bounties, but 1% every day is powerful. Yeah, I try to have micro goals on all the parts I need consistency regardless of motivation levels
English
1
0
1
205
Hugo Picanzo
Hugo Picanzo@hugopicanzo·
@busf4ctor Great tip! That’s great when you have already some foundations and hands on bug bounty. When you start over one hour a day it’s not enough because of the learning curve. And do you put different micro goals (for different parts of your life) at the same time, or just one?
English
1
0
1
296
Michael Blake
Michael Blake@Michael1026H1·
Agents feel like the next Nuclei. Can be very helpful, but results really depend on customization and where you point it. I also expect a triagers will be dealing with a lot of reports that the reporter doesn't understand.
English
2
0
62
9.9K
ArtSec
ArtSec@_ArtSec_·
I'm getting very close to a burnout currently, haven't found a bug in 4 weeks and imposter syndrome is rising quickly. I gotta find a way to break out somehow.
English
20
1
140
10.4K
Vitor Falcão "busfactor"
Vitor Falcão "busfactor"@busf4ctor·
@TherealWaRL0k No VDPs. Don't work for free. People tend to go after VDPs thinking they are easier targets, and maybe they are, but don't make your time worthless like that. Let VDPs run in a "see it, report it" manner, not "hunt for it, report it".
English
0
0
2
89
𝙢0𝖏0𝖏0𝖏0
𝙢0𝖏0𝖏0𝖏0@TherealWaRL0k·
@busf4ctor @busf4ctor Thank you so much, for the detailed reply. I solved a ctf last month, I am looking forward to finding a VDP bug this month. I really want to build consistency over burst of random work, stopping during the part I enjoy is what I will do next. Thank you for the advice.
English
1
0
0
83
Vitor Falcão "busfactor"
Vitor Falcão "busfactor"@busf4ctor·
@TherealWaRL0k The second part of the tip is to take good notes so you don’t have to rely on humans’ weak memories. The next day, you can get up to speed faster. Also, stopping during a part you enjoy is a crazy trick to get motivated the next day to start again.
English
0
1
1
59
Vitor Falcão "busfactor"
Vitor Falcão "busfactor"@busf4ctor·
@TherealWaRL0k Marathons burn you out. You can go to the gym every day for a month, burn out, and spend a year being sedentary, or take it easy, go twice a week, and keep going for a whole year. The latter is consistency: better results and better health. Bug bounty hunting works the same way.
English
2
0
2
154