A.Elyas (2buggy)

147 posts

A.Elyas (2buggy) banner
A.Elyas (2buggy)

A.Elyas (2buggy)

@get_root1

Security Engineer by day | Bug Hunter by night | الحمد لله CEO of duplicate

Planet Earth Katılım Ekim 2021
1.9K Takip Edilen259 Takipçiler
A.Elyas (2buggy)
A.Elyas (2buggy)@get_root1·
@smartnakamoura No account identifier in the payload so how did the ‘backend’ know which account to credit when it received this JSON? 🤔
English
0
0
0
76
Smart👨‍💻 | Software Engineer
A Nigerian fintech just lost ₦20 million to a fake webhook. Attacker didn’t hack anything. They just POSTed this to the endpoint: { "event": "transfer.success", "amount": 500000, "status": "success" } Backend credited the user. Zero money moved. This is happening more in crypto payments too. What every backend dev must do in 2026: 1. Verify webhook signature + IP + timestamp (not just event name). 2. Never credit on webhook alone always confirm on-chain + NIBSS. 3. Add rate limiting and replay attack protection. 4. Reconcile every stablecoin inflow against blockchain truth. Crypto rails move fast. One lazy endpoint and you’re done. Save this like your production depends on it. Drop your worst webhook horror story 👇
English
112
94
646
261.4K
A.Elyas (2buggy)
A.Elyas (2buggy)@get_root1·
@monkehack It’s great. I put on smart downloads and in the background it downloads videos depending on content I’ve watched - watch out though it’ll fill up your memory 🤣
English
1
0
1
92
Ciarán Cotter
Ciarán Cotter@monkehack·
YouTube Premium is a game-changer for flights. I don't know why I didn't try downloading videos before but it's by far the most productive use of my time on a flight where WiFi is patchy if it exists at all, and reading long articles for too long makes me sleepy.
English
4
0
19
1.8K
Ciarán Cotter
Ciarán Cotter@monkehack·
Excited to launch this with @busf4ctor. We'll be posting some of our research over the next few weeks 😁 so make sure to follow. Really looking forward to seeing where this goes!
Starstrike AI@StarstrikeAI

Today, we (@busf4ctor and @monkehack), are launching Starstrike: an AI pentesting and research startup. We'll be releasing our first few research articles over the next few weeks, detailing several bugs that helped us net over $100k in total. Follow to ensure you don't miss them!

English
3
2
72
5.7K
Mischa van den Burg
Mischa van den Burg@mischavdburg·
SECURITY WARNING: Someone built a website called openclawd.ai to mimic @openclaw . THIS IS NOT OPENCLAW The installation instructions tell you to curl a bash script from their openclawd URL. It currently returns a webpage but that won't stay for long. This script will hack you.
Mischa van den Burg tweet media
English
42
92
469
58K
Aaron Ng
Aaron Ng@localghost·
Got a mac mini for clawdbot. Had a lot of fun setting this up today. Instead of access to my accounts, I gave it: ✅ its own apple account for messages ✅ its own gmail to sign up for stuff ✅ its own github to push code
Aaron Ng tweet media
English
148
104
2.7K
472.4K
Muhammed Alkesht
Muhammed Alkesht@MuhammedAlkesht·
(إِنَّ اللَّهَ لَذُو فَضْلٍ عَلَى النَّاسِ وَلَكِنَّ أَكْثَرَ النَّاسِ لَا يَشْكُرُونَ.) Alhamdullilah I earned $$$ for my submission on #BugBounty #bugbountytips @bugcrowd #ItTakesACrowd
Muhammed Alkesht tweet media
العربية
4
1
78
2.1K
keysmashbandit
keysmashbandit@keysmashbandit·
I'll have my Claude contact your Claude
English
116
456
6.6K
156.5K
A.Elyas (2buggy)
A.Elyas (2buggy)@get_root1·
@zack0x01 Rest. Otherwise you will get sick and then you will be forced to stop for a period and therefore you'll lose more time. Take it easy🤝
English
0
0
0
63
Huzaifa_C0r§^
Huzaifa_C0r§^@KhanHuz44486924·
Hey #BugBounty hunters! I've been grinding on public programs for 9 months, hunting bugs solo—now looking for collab partners to team up. Anyone can join, let's smash some vulns together! DM me if interested. #Hacking #CyberSecurity #BugBountyTips
English
3
0
15
965
Biscuit
Biscuit@OreoB1scuit·
I recently tried magnesium glycinate and zinc, and bro… I slept for 8 hours but woke up feeling like I’d been on sleeping for 8 days. I even remembered my dreams in 4K for the first time ever. What is this magnesium some kind of premium sleep subscription?
English
7
2
27
3.9K
A.Elyas (2buggy)
A.Elyas (2buggy)@get_root1·
@SirBagoza I was just thinking when’s the don gonna drop another vid! I welcome it 🤝
English
0
0
0
135