kedrisec

365 posts

kedrisec

kedrisec

@kedrisec

Katılım Kasım 2015
445 Takip Edilen649 Takipçiler
kedrisec
kedrisec@kedrisec·
@trace37_labs Is it system for evolving agents? Or just for evolve xss payloads?
English
1
0
0
15
trace37
trace37@trace37_labs·
@kedrisec what details would you like?
English
1
0
0
12
trace37
trace37@trace37_labs·
I've just re-seeded my four 'survival of the fittest' sanitiser bypass engines. Some good healthy genes being put back into the gene pool... and we run again... Project Fermat has been running for weeks. One sanitiser bypass payload in the db has a max fitness of 0.9825. 1.0 means CVE. Reseeding this particular one with my fit payloads saw it jump back up to above 0.90 within a couple of generations... not all top payloads have worked their way through yet. Other sanitisers have some work still to do but all are climbing. So much fun getting an hourly discord alert telling me how the generational offspring are performing. Proud dad!
trace37 tweet media
English
1
0
2
271
kedrisec
kedrisec@kedrisec·
@CristiVlad25 @AnthropicAI @bcherny I guess, one way to figure it out is to granulate tasks for even small pieces to make it harder for Claude to fool you. It's better to feed ai with small pieces one by one instead of big bunches of them. Claude is lazy or it's affected by context rotting with such effects
English
1
0
2
136
trace37
trace37@trace37_labs·
If I add in the iOS apps (including "Uber" for my kids - with me as an unpaid driver on-demand!), my entire life-management system and a range of other stuff, I reckon 250k lines of code/prompts "written" in the last 12-14 months. Not a flex - it just shows how insanely productive AI/LLM makes us today.
trace37 tweet media
English
1
1
1
253
HackerOnTwoWheels
HackerOnTwoWheels@HackerOn2Wheels·
@roohaa_n Is there any good tool that would crawl and gather all JS? Katana?
English
2
0
7
1.8K
HackerOnTwoWheels
HackerOnTwoWheels@HackerOn2Wheels·
Bug hunter friends, what is the best tool to get all the javascript files given a list of domains, hosts or URLs ?? I want to download all of JS files to a directory.
English
18
16
190
23.1K
kedrisec
kedrisec@kedrisec·
@0xtavian I thought the axiom works in a similar way. Thanks for answering. Now I'm using fleex for this kind of tasks. Will try your tool, thanks for sharing!
English
0
0
0
40
Octavian
Octavian@0xtavian·
@kedrisec Ax Framework speeds things up by distributing the workload across many cloud instances, leveraging cheap computational power. It’s all about parallelizing tasks to get results faster.
English
1
0
0
119
Octavian
Octavian@0xtavian·
Hack faster with Ax Framework. Check this out. We ran subfinder on the top 100 domains and received 200,000 results in just 2 minutes using Ax (compared to almost half and hour)! 😲👇 🏎️ Now imagine how much faster it would be with 1 million domains!? 💨
Octavian tweet media
English
5
13
64
11.2K
kedrisec
kedrisec@kedrisec·
@0xw2w @damian_89_ I fucking hate that shit. It always looks like we are playing the stupid game "find the bug only on our specified endpoints" that doesn't have any relation to the company's real security.
English
0
0
4
142
Max Yaremchuk
Max Yaremchuk@0xw2w·
@damian_89_ A few months ago, I sent a bug that allowed the PII of 4 million users to be downloaded. They rolled a fast hotfix and marked it as ineligible for bounty since the API endpoint is located on the OOS target, although the API call is made within the in-scope target
English
2
0
8
963
Damian Strobel
Damian Strobel@damian_89_·
BugBountyLife... Full PII of 80k consumers of a huge brand but hey... Not in scope, no bounty... One of those programs I wish the worst and won't help anymore ;)
Damian Strobel tweet media
English
15
5
79
10.2K
d3fp4r4m
d3fp4r4m@defparam·
d3fp4r4m tweet media
ZXX
7
28
252
20.9K
kedrisec
kedrisec@kedrisec·
@defparam Nice one! I use just a curl request to lambda endpoint and take the response into slack.
English
0
0
0
264
Hussein Daher
Hussein Daher@HusseiN98D·
One of the best investments you can do when doing #bugbounty is getting yourself a strong VPS with very fast internet. Those 2GB ram 3$/month won't help you much if you're serious into it.
English
5
2
84
9.4K
kedrisec
kedrisec@kedrisec·
@nnwakelam Moreover, I would like to suggest to thinking about bb like playing against companies (who totally don't give a fuck about you as person, they were made and think(most of them)only about money making, so why don't you think same way?), but not people.
English
0
0
1
106
Nate
Nate@nnwakelam·
The biggest piece of advice I would give any bounty hunter going from $XX,000 to a multiple of that is to start to view your reporting as adversarial to the bug bounty program. 1/2
English
5
3
72
18.7K
kedrisec
kedrisec@kedrisec·
@hakluke It's nice to know, that not only me is addicted to the idea of automation bug bounty. Also so funny to see how my way to make architecture better is close to someone else's :)
English
0
0
0
145
Luke Stephens (hakluke)
Creating the perfect bug bounty automation (via trial and error) Attempt #1: Bash Attempt #2: Django Attempt #3: Golang and the Unix Philosophy Attempt #4: Cloud Native loom.ly/AiTZb8g
English
7
34
181
13.7K
kedrisec retweetledi
Frans Rosén
Frans Rosén@fransrosen·
I often export proxy items from Burp to extract certain data. Example: filter out all response headers where request param is X, get a list of all response params for custom wordlist creation etc. I built this tool to make it do what I want: github.com/fransr/unpack-…
English
6
72
352
41.2K
kedrisec
kedrisec@kedrisec·
@xnl_h4ck3r Thank you for your work! It's one of my lovely extensions!
English
0
0
1
23