James

207 posts

James

James

@jtcsec

Security professional + SRT

Katılım Mart 2020
192 Takip Edilen466 Takipçiler
James
James@jtcsec·
@0xLupin Trying to balance the full time job, getting the startup off the ground, hitting the bug bounty goals, all while trying to be a good family man. Life is good though I can’t complain, hoping to be able to make tweets like yours soon 😎
English
0
0
1
24
Lupin
Lupin@0xLupin·
@jtcsec Hehe thank you James ! Long time no see, how have you been ???
English
1
0
0
36
Lupin
Lupin@0xLupin·
WE DID IT ! WE RAISED $5.9M PRE-SEED 🥳🎉🎉
English
77
40
413
35.4K
James
James@jtcsec·
@rez0__ Get a hefty $500 for a crit IIRC fun stuff
English
1
0
0
100
James
James@jtcsec·
Doing a source code review, and found they encode every single static variable value with a custom base64 function that also obfuscates it, it’s so irritating. Just makes me more determined to find bugs in it 😈
English
0
0
0
183
James
James@jtcsec·
Siemens recently published an advisory containing several vulnerabilities I reported to them on devices using their ROX Firmware, was fun to dig deep into the backend code of an industrial networking device :) cert-portal.siemens.com/productcert/ht…
James tweet media
English
0
0
0
162
James
James@jtcsec·
Accidentally finding a command injection vulnerability because you have an @ in your password and the rest of it fails to resolve into a valid hostname 🤔
English
1
0
5
0
James
James@jtcsec·
@Jhaddix @jtsec Happened to be scrolling through this thread on my own and was shocked to find my one piece of content - thanks for the shoutout! I’m glad people can make good use out of it
English
0
0
2
0
JS0N Haddix
JS0N Haddix@Jhaddix·
A thread🧵 💸Secrets of automation-kings in bug bounty💸 Finding 1day (or 1month) web exploits that haven't made their into scanners yet can make you big money. Read more to understand where and how to get an edge in this area! 🚨Retweet, follow, & like for more! 🚨 1/x
English
70
544
1.6K
0
James
James@jtcsec·
@ceos3c @BugBountyHunt3r I struggle with attention span and wasn’t confident in myself. Trying to start on real targets I’d do lots of searching and couldn’t tell if no bugs there or my error. BBH forces you to practice your skills and you know bugs are there - easier to stay motivated
English
0
4
20
0
Stefan Rows 🧑🏼‍💻
Stefan Rows 🧑🏼‍💻@StefanRows·
As a Bug Bounty Hunter, what is the single most valuable resource (course, blog, cert, book) that has boosted your skills the most? 👇✍️
English
32
49
261
0
James
James@jtcsec·
James tweet media
ZXX
0
0
2
0
James
James@jtcsec·
@ITSecurityguard Gotten bounties from this before, disclosed localhost request to really wack custom paths to an admin dashboard, which in turn was externally accessible. Excellent tip!
English
0
1
3
0
Patrik Grobshäuser
Patrik Grobshäuser@ITSecurityguard·
Do you want to create a wordlist for yourself? Not sure where to start? Not sure what others are doing? Go to any public program and find a /metrics endpoint accessible, extract the paths, profit #BugBounty #bugbountytip #bugbountytips
Patrik Grobshäuser tweet media
English
10
47
212
0
James
James@jtcsec·
@Jhaddix Its true the bugs still pay, which is why I keep going back to them, but won't spend the time to take a deep dive for crits. Even if I get lots of dupes, they are still at least paying some of them, which is better then my test H1 target that is only VDP
English
0
0
0
0
JS0N Haddix
JS0N Haddix@Jhaddix·
@jtcsec It’s just to get my tooling back up to snuff & shake off the dust. Tbh tho, I know a TON of people complain about it, I have had 3k+ P1s, plus the low/easy stuff adds up. I guess my pro tip would be, for them, you have to really focus on the writeup. Explain to them the impact
English
1
0
1
0
JS0N Haddix
JS0N Haddix@Jhaddix·
Pulling out an old but good target tonight to get warmed up. Starts with a “w” and ends with a “rt”. Didn’t always pay consistently but has a giant scope and is a good confidence builder. #BugBountyDiary
GIF
English
4
1
24
0
James
James@jtcsec·
I spend so much of my time away from the keyboard theorycrafting things to try, particularly automation, and then when I can sit down and actually work on it I instantly lose all motivation
English
0
0
1
0
James
James@jtcsec·
@hakluke I clicked the link then…
English
0
0
18
0
Luke Stephens (hakluke)
Luke Stephens (hakluke)@hakluke·
Write a security professional's nightmare in 5 words or less. 👇
English
965
45
463
0
James
James@jtcsec·
@joehelle How many pentests are fully remote vs travel to client and test on site? How much time do you spend hacking vs preparation/writing reports for an engagement?
English
1
0
0
0
Lupin
Lupin@0xLupin·
Here is a little graphic to understand How to Become a Full time Bug Hunter 👀 #BugBountyTips
Lupin tweet media
English
8
25
144
0
James
James@jtcsec·
Anyone in the US have suggestions for good conferences to go to? Never been to one and I’d love to change that this year. East coast is ideal but I don’t mind traveling for good quality
English
0
0
1
0