Jon Bottarini

1.5K posts

Jon Bottarini banner
Jon Bottarini

Jon Bottarini

@jon_bottarini

Product Manager @ Google. I post about bug bounties, infosec, and everything in between. This is a personal account. Formerly: @Hacker0x01

Austin, TX Katılım Eylül 2012
756 Takip Edilen12.6K Takipçiler
Sabitlenmiş Tweet
Jon Bottarini
Jon Bottarini@jon_bottarini·
Just fully disclosed ~30 reports encompassing over two years of hacking on New Relic - hackerone.com/jon_bottarini - most of the reports are PrivEsc/IDOR but there are some business logic bugs in here as well. No recon here! Just getting really familiar with the application itself :)
English
19
168
598
0
Jon Bottarini
Jon Bottarini@jon_bottarini·
@0xLupin Congratulations!! Remember the early demo, great to see the success so far :)
English
1
0
1
168
Lupin
Lupin@0xLupin·
WE DID IT ! WE RAISED $5.9M PRE-SEED 🥳🎉🎉
English
77
40
413
35.3K
Roy Davis
Roy Davis@Hack_All_Things·
Peace out world. Best wishes to all. ALS has won this battle, but hopefully not the war!
Roy Davis tweet media
English
131
59
1.6K
146.7K
Jon Bottarini retweetledi
Dirk-jan
Dirk-jan@_dirkjan·
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-glob…
English
140
901
3.2K
471K
zseano
zseano@zseano·
Unexpectedly lost my dad early hours this morning… completely out of the blue. He was fit & healthy and now he’s gone 😭 lost for words on how I feel. RIP Dad ❤️❤️ love & miss you forever
zseano tweet media
English
380
0
869
45.5K
Jon Bottarini retweetledi
James Kettle
James Kettle@albinowax·
The whitepaper is live! Learn how to win the HTTP desync endgame... and why HTTP/1.1 needs to die: http1mustdie.com
English
19
241
751
85.5K
Jon Bottarini retweetledi
xEHLE
xEHLE@xEHLE_·
New writeup: Early last month, @samwcyo, @sshell_, and I found a Django ORM injection in an online shooter game that let us steal cryptocurrency from the game's wallet. Read the blog post here: blog.p1.gs/writeup/2025/0…
English
35
78
268
19.7K
Carl Vellotti 🥞
Carl Vellotti 🥞@carlvellotti·
an epic battle between the Growth PM and Legal
Carl Vellotti 🥞 tweet media
English
41
175
3.9K
270.4K
Jon Bottarini
Jon Bottarini@jon_bottarini·
Entire confession is absolutely wild. Talk about an insider threat risk...
Parker Conrad@parkerconrad

Deel CEO and company founder @Bouazizalex personally orchestrated his company’s alleged spy scheme, the spy said in a full confession Alex allegedly recruited the spy, received the stolen info, and arranged payment via a person known only by their pseudonym: “The Watchman”

English
0
0
2
1.1K
Jon Bottarini
Jon Bottarini@jon_bottarini·
@infosec_au @mgianarakis I remember you telling me at a LHE years ago you were working on an ASM product. Amazing where you've taken it and how it's grown. Huge congratulations to you and the team 🎉
English
0
0
1
449
shubs
shubs@infosec_au·
In 2018, @mgianarakis and I set off to build a platform that would provide enterprises with a realistic attacker perspective of their entire network. At the time, we had just begun to try the phrase "attack surface management" in peer conversations. But the vision was always clear. Find and monitor *every* asset and operationalize leading vulnerability research to provide customers with verifiable exposures before attackers even get a chance to exploit them. Over the past 7 years of bootstrapping Assetnote, I am proud to say we were able to build something that has made a significant positive impact for customers like Checkpoint, Canva, LinkTree, and more. I am also proud of the hard work and dedication of the Assetnote Security Research Team, who over the years, have discovered significant vulnerabilities in Citrix, Fortinet, Zoom, and many more. Being able to quickly operationalize these findings and protect our customers before the CVE is even assigned has always been a highlight of the work we do here. Today, I’m excited to share that Assetnote has been acquired by Searchlight Cyber as the next step in our journey. Not only will we continue to improve our market-leading Attack Surface Management solution, it will include the power of Searchlight’s dark web intelligence capabilities to provide our customers with even more high-signal and actionable information. You can check out the full press release here: assetnote.io/acquisition
shubs tweet media
English
80
34
397
47.8K
Jon Bottarini retweetledi
Sam Curry
Sam Curry@samwcyo·
New blog post with @infosec_au: We found a vulnerability in Subaru where an attacker, with just a license plate, could retrieve the full location history, unlock, and start vehicles remotely. The issue was reported and patched. Full post here: samcurry.net/hacking-subaru
English
47
312
1K
117.6K
Ben Sadeghipour
Ben Sadeghipour@NahamSec·
I'm honestly still in disbelief... grateful to receive a $100k bounty from @meta. Feels surreal. Sharing this to show that with time and dedication, it's possible. This was my first and only submission to Facebook - something I've been chasing for a decade! 🙏 Big thank you to @metabugbounty!
Ben Sadeghipour tweet media
English
545
443
12.1K
1.1M
Jon Bottarini
Jon Bottarini@jon_bottarini·
@dukrov_ This is awesome, congratulations! 👏 Really good for your first year
English
1
0
3
846
Dukrov 🍏
Dukrov 🍏@dukrov_·
2024 was my first year in bug bounty, and what a year it’s been. Had set a $1K goal🥲 and got $1100 as my first bounty. Raised the bar to $3k😅 and well here i am at $7k, all while hacking on weekends only.😌 #BugBounty #bugbountytips
Dukrov 🍏 tweet media
English
19
21
407
20.6K
Deev Pal
Deev Pal@techycodec08·
0-100 in Bug Bounty with a 9-5 job Finally, after 125 Hours of Rigorous testing in 56 days of starting bug bounty from scratch, I received my first bounty that too in 4 digits, in the main domain of one of the largest Public Bug Bounty Programs Way more to go!!!!! @Rhynorater
Deev Pal tweet mediaDeev Pal tweet mediaDeev Pal tweet media
English
63
34
556
62K
Ben Sadeghipour
Ben Sadeghipour@NahamSec·
I have some time in November. Someone give me a good hacking challenge 🤔
English
40
0
166
24.7K