Kanhaiya Sharma 🇮🇳
3.3K posts

Kanhaiya Sharma 🇮🇳
@krishnsec
Hacker | Top 25 @Bugcrowd all-time
India 🇮🇳 Katılım Mart 2021
672 Takip Edilen19.2K Takipçiler
Kanhaiya Sharma 🇮🇳 retweetledi

@PinkDraconian @Bugcrowd cool, hardware bugs can get messy
English

@krishnsec @Bugcrowd It's a cool bug and it's hardware related so needs quite some explaining :)
English

@Bugcrowd What is up with your triage? I send a 𝟭𝟰 𝗽𝗮𝗴𝗲 𝗿𝗲𝗽𝗼𝗿𝘁.
Triage comes back with a generic message:
"Your steps are unclear."
How am I supposed to guess what steps are not clear enough? Where are they getting stuck? What section needs more information?
English

@ReebootToInit5 @Jujutsu_Kaisen_ I tried to watch few eps but I noticed everyone is talking about locked gojo, even to run eps they need gojo name 😂 , honestly without gojo it’s garbage
English

I used to love watching #Jujutsukaisen and the best part was it wasn’t boring or filled with fillers episodes
This season it’s literally shit , garbage, every single episodes are coming out more boring than the previous one @Jujutsu_Kaisen_
@krishnsec how are u enjoying so far
English
Kanhaiya Sharma 🇮🇳 retweetledi
Kanhaiya Sharma 🇮🇳 retweetledi

Standoff Hacks is almost here! 🔛
Want in?
Standoff Hacks is our private two-week live hacking event — top researchers, closed corporate targets, serious rewards, and a final party somewhere in the world (TBA!).
How to get an invite:
➡️ Hunt bugs in the OZON program: bugbounty.standoff365.com/en-US/programs…
➡️ Submit valid reports
➡️ Earn points
➡️ Increase your chances of getting one of the invitations
That’s it 🎉
Dates
Feb 20, 10:00 AM – Mar 6, 11:59 PM (Moscow Time)
Go hunt! 🐞

English
Kanhaiya Sharma 🇮🇳 retweetledi

🔥🔥🔥 This hits on something that has bothered me for most of my career... Much of what orgs do to "assess risk" is largely performative, and has very little do with actual risk. Impact is what matters.
Your AI Pentester Found 1,000 Bugs. None of Them Were the One That Mattered. m.cje.io/4shFCv1

English

First time, I trusted burp AI and watched ~10,000 credits vanish while trying to exploit cmdi , got 0 results .
but later spent 3 mins writing my own payload and popped it `uid=0(root) gid=0(root) groups=0(root)`
Conclusion: Burp is elite, but AI is still an intern.
#bugbounty


English











