otr
300 posts

otr
@its_otr
Security Engineer that loves offensive security, bug bounties, CTFs and e-sports. Critical Thinker IYKYK HackerOne/Bugcrowd/Synack SRT
Katılım Ağustos 2019
179 Takip Edilen80 Takipçiler
otr retweetledi

We spend a lot of time talking to the hackers, but today, we're dropping a goodie for the program managers!
Here are our top tips for running a kickass bug bounty program.
See the matrix at the end for high impact to hackers, low effort to impl. changes.
blog.criticalthinkingpodcast.io/p/program-mana…
English
otr retweetledi

UNBELIEVABLE OS Command Injection technique!? 😱
(with @fransrosen)
#bugbountytips #bugbounty #bugbounties
English
otr retweetledi

.@joaxcar takes proving impact to the extreme by showing that a GitLab bug could've resulted in an attacker being able to:
- Trigger new and existing pipelines
- Overwrite variables
- Upload images for RCE
- Gain full access to all CI variables
- [INSERT IMAGINATION]
English
otr retweetledi
otr retweetledi
otr retweetledi

I am looking to #Connect with people who are interested in: 💫 Bug Bounty VAPT Security Consulting Red Teaming CTF #LetsConnect #cybersecurity #connection
English
otr retweetledi

Hyyype! @0xteknogeek and I are gonna be there dropping some bb 🔥 so swing by if you're at DEFCON!
Bug Bounty Village@BugBountyDEFCON
It's official folks. We are officially listed in the Defcon website 😱. How awesome is that? The bug bounty village website is coming soon. Stay tuned for updates! #bbv" target="_blank" rel="nofollow noopener">defcon.org/html/defcon-32…
English
otr retweetledi

Can I just say @PaulosYibelo has been dropping some bangers lately. We'll mention them on the pod this upcoming Thursday, but both of these client-side techniques are really innovative and sick:
paulosyibelo.com/2024/02/cross-…
octagon.net/blog/2022/05/2…
English

I forgot how constricting Synack LP+ is after spending some time on HackerOne. I don't understand why a VPN isn't sufficient. #bugbounty
English
otr retweetledi

Whenever @avlidienbrunn comes on the pod, we always walk away with some gold.
For episode 68, Mathias drops some 0-days in HTMX and a gadget on cloudflare based networks which will help exploit GET or POST based CSPT and SSRF!
ctbb.show/68
English
otr retweetledi

Live hack-along starting in 40 minutes in the CTBB Discord (ctbb.show/discord) for the Critical Thinkers subscription tier!
English
otr retweetledi

Can't wait for the the live hack-along session happening tomorrow on the @ctbbpodcast Discord channel🔥

English
otr retweetledi

Caido Pets is now publicly available via @bebiksior's EvenBetterExtensions. My suite of plugins is called The Primate Pack. I'll be releasing more features under this plugin in the future. 😄 @CaidoIO
github.com/bebiksior/Even…
github.com/projectmonke/P…
#bugbounty #bugbountytips
English

Another gold episode youtu.be/mFC0G4oBlIY?si…. Check it out BBP program managers! @ctbbpodcast

YouTube
English



