Jeevan.eth

313 posts

Jeevan.eth banner
Jeevan.eth

Jeevan.eth

@cyberzyro1

Web3 Enthusiast • eJPT • CEH • Security+ Certified🥇 Penetration Tester🕴💻 Red Teamer #cybersecurity #ethicalhacking #Web3 #BLOCKCHAIN

127.0.0.1 Katılım Eylül 2019
110 Takip Edilen147 Takipçiler
Sabitlenmiş Tweet
Jeevan.eth
Jeevan.eth@cyberzyro1·
Hi guys👋🤗, This thread is for those who want to get into web3 Security, and the roadmap I followed to get into the same, - some basic topics to go thru : - Cryptography - Decentralization - BlockChain - what are Smart Contracts - Different ERC standards 🧵1/n
English
10
51
116
0
H4x0r.DZ 🇰🇵
H4x0r.DZ 🇰🇵@h4x0r_dz·
This North Korean user uploaded a video that's over 1,000,000 hours @shinywr" target="_blank" rel="nofollow noopener">youtube.com/@shinywr
H4x0r.DZ 🇰🇵 tweet media
English
10
15
230
47.6K
Jeevan.eth
Jeevan.eth@cyberzyro1·
@Behi_Sec i dont understand who and why are these amateurs trying to fix authotization issues with client sided patxh wtf man
English
0
0
0
12
Behi
Behi@Behi_Sec·
To my surprise, it worked! The devs thought that adding a new parameter (usrID) containing the user's email would tighten the authorization, but they did not check whether the docID belonged to that usrID, or whether the authenticated user matched the usrID in the request :)
English
2
0
12
1.7K
Behi
Behi@Behi_Sec·
I found an IDOR on a program. They paid me $5,000. Twice. Here is the story: 🧵
English
4
37
317
23.2K
Jeevan.eth
Jeevan.eth@cyberzyro1·
faced-off with the most heart shattering fact/truth today. 💔 but guess what the comeback will be smoother than ever before. ~ 11th December 2025.
English
0
0
3
34
Jeevan.eth
Jeevan.eth@cyberzyro1·
🔍 Audit ACLs, not groups 🧹 Remove stale delegations 🚩 Flag weird write permissions 🔐 Protect service accounts Takeaway: If you don’t know all your admins… you don’t control your AD.
Jeevan.eth tweet media
English
0
0
0
10
Jeevan.eth
Jeevan.eth@cyberzyro1·
• Misconfigured delegation • Inherited ACL privileges • Old service accounts • “Temporary access” no one removed Why it’s scary: Attackers LOVE them. No alerts. No privilege escalation logs. Just silent domain takeover. Defend yourself:
English
1
0
0
20
Jeevan.eth
Jeevan.eth@cyberzyro1·
The most dangerous AD admin? The one you don’t know exists. 👀 “Shadow Admins” = accounts not in any admin group… …but with hidden permissions that can take over your domain instantly. Most orgs never detect them. How they appear:
English
1
0
0
24
Jeevan.eth
Jeevan.eth@cyberzyro1·
Takeaway: If you didn’t request it, don’t approve it. Ever.
Jeevan.eth tweet media
English
0
0
1
17
Jeevan.eth
Jeevan.eth@cyberzyro1·
Entire cloud accounts have been hijacked because someone approved one rogue request during a busy moment. No exploits. Just pressure. How to stay safe: ⚠️ Unexpected MFA prompt = attack attempt 🔢 Enable number matching or use FIDO keys 🙅‍♂️ Approve only the logins you start
English
1
0
1
10
Jeevan.eth
Jeevan.eth@cyberzyro1·
Many people think MFA = safe. Not when “MFA fatigue” hits. 🔄 Attackers don’t need to hack your code — they just spam you with nonstop MFA prompts until you accidentally tap Approve. It’s psychological, not technical. Real impact:
English
1
0
1
8
Jeevan.eth retweetledi
Pump.fun
Pump.fun@Pumpfun·
got rugged by a 12 year old then realised it doesn't matter because I'm just a chill guy
Pump.fun tweet media
English
1K
993
13.1K
837.9K
Session
Session@session_app·
Session tweet media
ZXX
10
74
462
14.8K
Gowtham Naidu Ponnana🇮🇳
Gowtham Naidu Ponnana🇮🇳@gowtham_ponnana·
Guys, Suggest me one good monitor for my MacBook Pro. NOTE: Doesn't matter whether curved or not, but atleast 4K + >= 60hz Noting once again, I'm poor...
English
4
0
13
3K
Jeevan.eth
Jeevan.eth@cyberzyro1·
speaking from personal experience on what i observed most of the startup orgs (mostly those using cloud services) which are fairly running arent really following simple security protocols such as Access Keys Rotation(every 90 days atleast) 🤐 one of tech firm #informationsecurity
Jeevan.eth tweet media
English
0
0
2
44
Jeevan.eth
Jeevan.eth@cyberzyro1·
and now some endpoints of #Discord are out ❌💀
English
0
0
0
199
Jeevan.eth
Jeevan.eth@cyberzyro1·
a really aspiring quote from a book i've been reading lately..👨🏻‍💻📚 "Security within our technologies is nothing until security is within our minds" Book: Inside the Security Mind- Making the tough decisions Author: Kevin Day #informationsecurity #CyberSecurity #ReadingHour
English
0
0
1
29
s4thv1k
s4thv1k@s4thv1k·
Glad that everything went well 😁 Excited about future 🙌🤞 Huge thanks for love and support 🫂 youtu.be/DT0thGOiW3Y
YouTube video
YouTube
English
1
0
15
1.3K