Luciano Corsalini

142 posts

Luciano Corsalini

Luciano Corsalini

@lucio_89

Katılım Ocak 2011
115 Takip Edilen1.4K Takipçiler
Luciano Corsalini
Luciano Corsalini@lucio_89·
@daeken There would be a high risk to get lost depending on the company you fly with
English
0
0
2
0
Sera Brocious
Sera Brocious@daeken·
I'm pretty sure I've tweeted this before, but I'd pay so much for a service that knocks me out in my hotel room, brings me to the airport, puts me on a plane, transports me home, and wakes me in my bed. Fuck first class; give me an oxygen mask in a box in the cargo hold.
English
3
3
22
0
Kevin
Kevin@rohk_infosec·
may the dupe gods be ever in my favor
English
3
0
7
0
Intigriti
Intigriti@intigriti·
We're feeling generous! 🤗 We're manually sending out some private bug bounty program invites today... who should we invite? 👂#HackWithIntigriti
Intigriti tweet media
English
151
11
107
0
d0nut 🦀
d0nut 🦀@d0nutptr·
Please don’t actually report this. There isn’t any real impact. It’s basically the same as if you registered an entirely new email and set up email forwarding on one of the addresses.
Somdev Sangwan@s0md3v

@cybercdh Good one. Here's one from me: example@gmail.com AND e.xa.m.p.le@gmail.com are the same things. If a web application registers them as different emails, you can report it as a vulnerability that let's you create multiple accounts with one email.

English
9
2
75
0
Luciano Corsalini
Luciano Corsalini@lucio_89·
@cyb3rsick So stupid that leads to ATO as the URL always contains a token to keep going with the password reset flow. Not sure whether you or the company really realized the impact of this.
English
1
0
0
0
Cyb3rsick
Cyb3rsick@cyb3rsick·
At password reset pages always try manipulating HOST header, you might get lucky and find that the password reset URL contain your own host instead of the original domain name. Just got easy 500$ for this stupid bug. #bugbountytip #Bugbounty #ItTakesACrowd
English
5
69
247
0
Luciano Corsalini retweetledi
Jane Manchun Wong
Jane Manchun Wong@wongmjane·
People have been trying to get me to tell them all of my secrets on how I reverse engineer apps. I wrote a small article on how I do everything. Enjoy wongmjane.com/post/secret-of…
English
125
652
3.1K
0
Michele Spagnuolo (miki.it)
If you want to live what you experience the moment you die when you see your entire life passing by in a flash, just run: . ~/.bash_history
English
2
1
12
0
Ed
Ed@EdOverflow·
Throwback to that one time I decided to be a bit creative and include something different for a change in my stored XSS proof of concept. Didn't turn out as expected. 😅
Ed tweet mediaEd tweet mediaEd tweet media
English
5
10
65
0
Luciano Corsalini
Luciano Corsalini@lucio_89·
Finally managed to get some cool stuff @HackenProof sent me! Thank you guys, it definitely worth the time spent in line at the post office 😜
Luciano Corsalini tweet media
English
4
1
43
0
Olivier Beg
Olivier Beg@smiegles·
It fasinates me that a trillion dollar company is not competent enough to build a working keyboard. So yeah, really excited to go to the Apple store to fix my space bar and be without a laptop for a week..
English
3
0
18
0
Jack Cable
Jack Cable@jackhcable·
Stanford’s launching a bug bounty program! Open to all students and faculty, the program kicks off this Saturday. Join us Saturday at Lathrop 282 from 10am - 4pm for a launch hackathon. Details at bounty.stanford.edu. #bugbounty
English
6
12
52
0
Kevin
Kevin@rohk_infosec·
As much as I like the iPhone X.. the Face ID is horrible in the mornings
English
1
0
3
0
Patrik Grobshäuser
Patrik Grobshäuser@ITSecurityguard·
Love selling things on eBay. I've been chatting with this scammer for the last hour or so :D Don't fall for such a scam :)
Patrik Grobshäuser tweet media
English
4
2
18
0
Luciano Corsalini retweetledi
Uranium238
Uranium238@uraniumhacker·
Bugbounty tip: Want to find some internal code of companies or some sample codes of new features? Checkout with: site:repl.it intext:<companydomain>. In companydomain, if you know the internal domain it is even better. #bugbountytip
English
3
138
324
0