otr

300 posts

otr banner
otr

otr

@its_otr

Security Engineer that loves offensive security, bug bounties, CTFs and e-sports. Critical Thinker IYKYK HackerOne/Bugcrowd/Synack SRT

Katılım Ağustos 2019
179 Takip Edilen80 Takipçiler
otr
otr@its_otr·
I just want to find vulnerabilities. Having to fix them is a headache.
English
0
0
0
13
otr retweetledi
Critical Thinking - Bug Bounty Podcast
.@joaxcar takes proving impact to the extreme by showing that a GitLab bug could've resulted in an attacker being able to: - Trigger new and existing pipelines - Overwrite variables - Upload images for RCE - Gain full access to all CI variables - [INSERT IMAGINATION]
English
0
4
38
4.8K
otr retweetledi
Critical Thinking - Bug Bounty Podcast
Neat browser behaviour gadget for cross-origin exploitation: If you know the target's full path, onhashchange can be triggered cross-origin by using window[.]open + full path + changed hash. window[.]open("//site[.]com/full/path#ourhash","targetWindow") Credit: @joaxcar
English
2
6
46
10K
otr
otr@its_otr·
Happy Monday, hackers
English
0
0
0
17
otr retweetledi
Ryan M. Montgomery
Ryan M. Montgomery@0dayCTF·
This app is incentivizing children to send pictures to strangers for money, if you see it please remove it immediately! Stay safe.
English
30
217
495
38.8K
otr retweetledi
bugcrowd
bugcrowd@Bugcrowd·
Did you know you can use ffuf to fuzz multiple keywords simultaneously? Here's how you can fuzz the protocol and subdomain at the same time👇
bugcrowd tweet media
English
3
16
89
7.3K
Aditya
Aditya@ADITYASHENDE17·
Whats the last vulnerability you reported ?
English
46
1
34
12K
otr
otr@its_otr·
I forgot how constricting Synack LP+ is after spending some time on HackerOne. I don't understand why a VPN isn't sufficient. #bugbounty
English
0
0
2
63
otr retweetledi
Critical Thinking - Bug Bounty Podcast
Whenever @avlidienbrunn comes on the pod, we always walk away with some gold. For episode 68, Mathias drops some 0-days in HTMX and a gadget on cloudflare based networks which will help exploit GET or POST based CSPT and SSRF! ctbb.show/68
English
0
4
7
1.2K
otr
otr@its_otr·
@Bugcrowd Live passive crawl and Live audit are enabled by default and set to All Traffic. You may want to disable this or change it to scope only. I find them noisy and unnecessary. Be intentional about your scans/crawls.
English
1
0
8
619
bugcrowd
bugcrowd@Bugcrowd·
What's your top tip for those setting up Burp Suite for the first time?
English
30
11
87
27.5K