Marius du Preez

305 posts

Marius du Preez banner
Marius du Preez

Marius du Preez

@mdp_sec

Bug bounty hunter breaking Web2 apps, APIs & business logic. $83k in my first 5 months. Sharing what works and doesn't. 🇦🇺 https://t.co/bFQ2v80QRB

Australia Katılım Mart 2026
125 Takip Edilen847 Takipçiler
Sabitlenmiş Tweet
Marius du Preez
Marius du Preez@mdp_sec·
Bug bounty’s dirty secret.. The hardest part isn’t finding the vulnerability. It’s what happens after you submit a clean, valid report. I now spend more time defending my work, chasing silence, and restarting the same loops than I spend actually finding bugs. 🧵
English
11
14
224
16.7K
Marius du Preez
Marius du Preez@mdp_sec·
I made $101,388 hunting bugs in 162 days. Before anyone treats that as a blueprint, I want to be honest about something. The compute I used to do it cost $199,501.
Marius du Preez tweet media
English
16
16
387
21.2K
Marius du Preez
Marius du Preez@mdp_sec·
@Aahmed646 Multiple accounts resolve this with cliproxy so requests route round robin. But anything xss usually refusal. It has no issues finding sometimes building poc it refuses on but claude or kimi then for poc
English
0
0
1
148
Ahmed Mahmoud
Ahmed Mahmoud@Aahmed646·
@mdp_sec Have you encountered any issues related to cyber restrictions/cyber-trusted-access with Codex/Sol 5.6? Because it still blocks many authorized security requests, even after being TAC verified, and a lot of safeguard false positives. how did you handled this
English
1
0
2
172
Md Ismail Šojal 🕷️
- $101,388 in 162 days of bug hunting. - $199,501 in AI compute. - $6,000 out of pocket. - 203 reports submitted. - 76 paid. - 274.5 billion tokens burned. the full, unfiltered breakdown heavy AI-assisted bug hunting the good, the ugly, and the part almost no one talks about. and the method that actually worked.
Md Ismail Šojal 🕷️ tweet mediaMd Ismail Šojal 🕷️ tweet media
Marius du Preez@mdp_sec

I made $101,388 hunting bugs in 162 days. Before anyone treats that as a blueprint, I want to be honest about something. The compute I used to do it cost $199,501.

English
2
4
17
1.9K
Marius du Preez
Marius du Preez@mdp_sec·
@damian_89_ @sec_jota spot on just slot machine if can put $1 in and get more than $1 out then just keeep throwing at it just need more programs togo through haha
English
0
0
0
16
Damian Strobel
Damian Strobel@damian_89_·
@mdp_sec @sec_jota There are hunters out there, that max out 10 accounts (each max20) ;) S0 1-2k/month on subs is not even "a lot". @sec_jota if you spend 4k/m on claude/codex but earn 20k... thats totally fine ;) (real numbers are more like 20-40k/month income from 4-6k subs :P)
English
1
0
1
41
Damian Strobel
Damian Strobel@damian_89_·
Is anyone still using Claude for BB work? It got worser, the token consumption increased dramatically... I am burning 5-10% of the weekly limit within 10 minutes... makes no sense any more.
English
6
1
24
3.3K
Marius du Preez
Marius du Preez@mdp_sec·
@sec_jota @damian_89_ not 20 accounts fam. claude max 20 accounts, i got always either have 2-3 claude max 20, and 2-3 codex max 20 and 2 grok, pretty much 1.2k pm in subs
English
2
0
0
26
𝕵𝖔𝖙𝖆 | jotita3
@mdp_sec @damian_89_ 20 Claude instances? Wow. From my perspective, that seems like a huge expense. In my workflow, I use it as a support tool too, around six instances or less, but not as a replacement for me 😅
English
1
0
1
15
AR
AR@ar3za12·
@mdp_sec Both public and privates? Also category is web2,code repo?
English
1
0
1
368
AR
AR@ar3za12·
@mdp_sec Love ur transparency and detail,You deserve this
English
1
0
1
437
ABDul Rehman
ABDul Rehman@TheTradMod·
@mdp_sec interesting perspective ser, thanks for sharing the real numbers
English
1
0
1
358
meljith
meljith@meljith·
@mdp_sec Is codex is good or claude if yes then which model is still good
English
1
0
1
431
Marius du Preez
Marius du Preez@mdp_sec·
@damian_89_ I was a big time fan boy of claude then switched to codex. It does all the same with wayyyyy more usage and less refusals. Claude i just use to act as adversarial against codex and if agree assume gucci if not send me a ping
English
0
0
0
44
Damian Strobel
Damian Strobel@damian_89_·
@mdp_sec Doing exactly that (and vice versa) but more and more I don't see the need for Claude since sol on its own found and validated real complex non http sec issues on e.g. SF infra. During my one week off quality of opus decreased significantly... Anthrophic is milking us
English
2
0
3
446
Marius du Preez
Marius du Preez@mdp_sec·
everythign i do is headed, i have hundreds of profiles that keep so can reusue them each has a proxy allocated with low risk ip that keep track of, each browser stays to its own geo multiple browsers to diff geo so warmed up browsers help with alot of bypassing, datadome is the most strict tbh but it handles it on right ip
English
0
0
4
685
MrUniverse
MrUniverse@00MrUniverse00·
@mdp_sec Do you have any advice for handling auth on so many targets at once? Were you mainly using headed or headless browsers? Thanks for the information post
English
1
0
1
755
Marius du Preez
Marius du Preez@mdp_sec·
@tecchirp i have everythign running on a dedicated box with everything installed already including browsers proxies etc anything a human would use ai has
English
1
0
2
416
Lakshan Perera 🇱🇰
@mdp_sec Brilliant, Do you usually download all the target's assets locally before using an AI tool, or do you just give it the target domain? I'm using Grok, but it doesn't seem to have a web tool
English
1
0
0
490
def1ant
def1ant@0xdef1ant·
@mdp_sec AI slop post. LinkedIn is down the hall and to the left
English
1
0
6
831
Phineas
Phineas@PhineasX·
@mdp_sec Thank you so much for this! I will keep pushing forward!
English
1
0
1
148
Marius du Preez
Marius du Preez@mdp_sec·
its automated yes but the right system has to be built for it, if you use exactly what everyone else uses you get the same results so dupe city is the normal, gotta built own system that works with how you hunt, every single report i submit goes into my RAG to ensure I train it for that or similar only proven impact reports, train on low quality produce low quality. just saying something like go find me 2 criticals on x gives you exactly that, but it does not take into equation preconditions, business logic etc long list, this is where humans and prompting and adversarial judges come into place. if you got blue team you know business logic you have seen flaws in all systems and the benefit of actually getting hands on source, so you understand what usually gets missed, put that in a db with LLM access and then you tell it to look for these things will be a great start. legit just spend $$ on subs and take it as personal development cost over time you will learn. if i look at my numbers i spent just over 15k on api costs just building the system im at now. so glad got subs lol
English
1
0
3
173
Phineas
Phineas@PhineasX·
@mdp_sec Isn't it all essentially automated though? Congrats on your success for only starting in Feb! How would you recommend I get started? I have 10+ years of blue team xp. Very little red team other than some TryHackMe
English
1
0
1
179
Marius du Preez
Marius du Preez@mdp_sec·
@PhineasX nah its only going to get more fun, look i only started in feb and made massive progress once built the right system. i think biggest issue is everyone wants a easy win 1 prompt and spit out money, thats not how this works at all
English
1
0
2
172
Phineas
Phineas@PhineasX·
@mdp_sec I picked a bad time to get into bug bounty... Feels like the barrier to entry is extremely high. Almost unobtainable to do on the side
English
1
0
1
187