defyourtype

66 posts

defyourtype

defyourtype

@defyourtype_

Katılım Ağustos 2025
57 Takip Edilen21 Takipçiler
Azanul
Azanul@0xazanul·
after seeing @thedawgyg fuzzing posts, i started learning about fuzzing myself. the results so far have been encouraging: interesting crashes, memory corruption indicators, and plenty more to dig into. #TogetherWeHitHarder #bugbounty
Azanul tweet media
English
12
5
140
6.1K
dawgyg - WoH
dawgyg - WoH@thedawgyg·
Lol @Hacker0x01 rate limiting telling me my signal is 0 and im not allowed to have more than X open reports... wtf lol
English
9
2
86
8.4K
defyourtype
defyourtype@defyourtype_·
@wearehackerone its still a win, dup of triaged report….when was the original submitted ?
English
1
0
0
36
P4 ❤️
P4 ❤️@wearehackerone·
I'm failing again and again and again
P4 ❤️ tweet mediaP4 ❤️ tweet media
English
4
0
29
1.7K
godiego
godiego@_godiego__·
Love some of my interactions on @Bugcrowd Triager: NMI Me: provide updated PoC Triager: uses first one again, ignores new one from the comment, closes as not reproducible 💯💯💯
English
21
1
152
7.5K
defyourtype
defyourtype@defyourtype_·
@KIDRIANI_ congrats, i thought their bounties start from 617$
English
0
0
0
15
baehelprichard
baehelprichard@KIDRIANI_·
@ahmtbrt07 @rez0__ I received a bounty from them. Although they didn't pay much in April, they paid out over 20 reports this month. Something likely happened last month, but they are definitely not a fraud.
English
1
0
0
77
Sean
Sean@_sean0x·
@defyourtype_ I have permission of course, it shouldn't be private will likely be public soon
English
1
0
8
4.7K
Sean
Sean@_sean0x·
I reported a bug on Duel yesterday and they just rewarded me a $15,000 bug bounty. Monarch & Plank made sure to sort out a fair bounty for the bug and made the whole process seamless.
Sean tweet mediaSean tweet media
English
49
26
574
94.4K
Atharv
Atharv@0xatharv·
submitted a valid auth bypass yesterday anyone could cancel bookings without authorization, trigger marked it as duplicate to a completely different report just because the API path first two word looked similar @Bugcrowd please ask your triagers not to work while they are on ..
Atharv tweet mediaAtharv tweet media
Atharv@0xatharv

seriously .? @Bugcrowd using ai to trigger reports .?

English
5
1
53
5.3K
defyourtype
defyourtype@defyourtype_·
@bhavukjain1 ive faced this a lot, most of them are closed as design issues on programs i hunt.its because the team themselves arent sure what they are supposed to do. i mean whats the point of new permissions/features if the team isnt willing to own the security consequences that come along.
English
0
0
1
144
Bhavuk Jain
Bhavuk Jain@bhavukjain1·
If a report leads to a permission fix, how it is not a broken access control issue? Looking for different perspectives. Background - A staff member could perform actions without required permissions. #shopify
Bhavuk Jain tweet media
English
1
0
23
2.6K
Mehmet INCE
Mehmet INCE@mdisec·
I NEED TO TALK WITH SOMEONE FROM @supabase security team right now. Can someone link me please ?!!!
English
14
0
57
43K
defyourtype
defyourtype@defyourtype_·
@arshadkazmi42 insane, i am still trying to figure out my ai workflows, you use the 100$ plan?
English
1
0
2
1.1K
Arshad Kazmi
Arshad Kazmi@arshadkazmi42·
I finally seem to have a working AI bug hunter setup. All findings using Claude Code with Opus 4.7. Got a few duplicates but seems like the workflow is working in the right direction now. Two interesting findings I had on one program: - LLM Injection - My first LLM injection. Initially Claude Code flagged it and discarded it saying it's LLM injection, as if it's an invalid bug 😄. I had to ask it to focus on LLM injections and it was easily able to bypass it. Seems like there were no filters for LLM injection. But the workflow didn't have any MCP or tools so impact was not much. - RCE on Windows machine - It found an image proxy where user can control file names. It suggested it's a low finding and only thing we can do is defame the company by uploading malicious images with malicious names. Then I asked if we can control images we should be able to bypass it to upload executables, and it was able to find a full workflow to bypass the image check and upload a Windows executable which will be served from target owned image proxy and run on Windows machines to achieve RCE.
Arshad Kazmi tweet mediaArshad Kazmi tweet mediaArshad Kazmi tweet media
English
8
6
208
12.1K
defyourtype
defyourtype@defyourtype_·
@inscryption1 @Hacker0x01 you completed id verification, and tried to withdraw bounties from there? I guess thats the issue. but their Code of conduct says they give out 2 warnings.
English
0
0
0
102
Imamul Mursalin
Imamul Mursalin@inscryption1·
@defyourtype_ @Hacker0x01 I have two h1 accounts , When I created the second one I didn’t know that it could violates their policy , Also I didn’t do anything wrong with that account , like reputation farming,duplicate submissions etc. I explained to them but nothing happened.
English
1
0
1
740
Imamul Mursalin
Imamul Mursalin@inscryption1·
Hey @Hacker0x01, I’ve contributed 500+ reports to your platform. Due to an account restriction, I’m currently unable to access my hard-earned pending bounties or provide "Needs More Info" for critical security risks I’ve reported.
English
6
0
23
5.6K
Destiny ehiosun
Destiny ehiosun@Destinyxeiiios1·
duplicate of a critical 🥲🥲
Destiny ehiosun tweet media
Română
2
0
11
831
defyourtype
defyourtype@defyourtype_·
@Ehsan1579 Wait tf, you started a year ago and are making a mil every quarter now?
English
1
0
8
1.1K
Ehsan
Ehsan@Ehsan1579·
Around last year this month of April, I was under a lot of financial pressure. Family had a lot of debt, no money, wifi and phone lines cut off, nobody could talk to each-other, no food, I used to eat potatoes my brother made with some garlic, and no hope for any better future, last attempts at creating something valuable in the world failed despite being very close. Failure was all there was. When humans face immense pressure, I believe they turn into a robotic state, they stop processing emotions temporarily and the need to have a purpose or to think something through before doing it is gone so is your self-awareness, you just turn into this thing that needs to survive at least one last time. I went to libraries and worked there I didn’t expect much I just did whatever I had to do when libraries closed I used to park outside the library in the parking so I can still access the library’s wifi. April was a difficult month but then that’s when May came.
English
47
32
575
29.5K
Valentino Massaro
Valentino Massaro@valent1nee·
I'm so happy to have won the MVH at the latest Google LHE (Seoul 2026). Thank you, @GoogleVRP, for the amazing event!
Valentino Massaro tweet mediaValentino Massaro tweet media
English
17
11
227
31.2K