mongo

1.5K posts

mongo

mongo

@mongobug

I like bug bounty programs and breaking things that other people have built. I love kudos.

::1 Katılım Şubat 2015
194 Takip Edilen10.7K Takipçiler
mongo
mongo@mongobug·
@justdionysus Solved it (a friend sent it to me) and it was pretty fun and different :) ty
English
2
1
7
2.9K
_ZN4DionC1Ev
_ZN4DionC1Ev@justdionysus·
Well, here's a goofy reverse engineering challenge I started a year or two ago and "polished" up last night (I'm sorry it's JavaScript but that's part of the point): gist.githubusercontent.com/justdionysus/d… Please solve it and let me know if it's dumb or boring.
English
2
2
6
3.6K
mongo
mongo@mongobug·
@Masonhck3571 I will wait until 7am next time.. but still, any updates?
English
1
0
3
1.8K
Masonhck357
Masonhck357@Masonhck3571·
I can’t believe people are calling me on Instagram at 2am because they don’t like their triage decision. Please don’t ever do that
English
24
2
126
30.3K
Alex Birsan
Alex Birsan@alxbrsn·
so am I the only one who's gotta restart burp like 10 times a day 'cause it starts glitching like this?
Alex Birsan tweet media
English
10
0
42
13.5K
Harsh Bothra
Harsh Bothra@harshbothra_·
Tell us who your favourite security hero is and I'll invite them to share their story on SecurityStories.
English
36
0
40
15.2K
Jobert Abma
Jobert Abma@jobertabma·
I’m giving away a Burp Suite Pro license! A Pro license auto renewed and the hacker that I personally sponsored makes enough money from @Hacker0x01 to afford it themselves 🎊 Mention someone that deserves the license in the replies to this tweet and I’ll pick someone in 24h.
English
309
77
442
105.8K
mongo
mongo@mongobug·
Apparently people are now holding on to low-medium-high bugs and submitting only crits because otherwise they get less invites on BB platforms? (heard this about H1, but probably true for others). Algorithmic failure if so
English
3
0
17
5.7K
mongo
mongo@mongobug·
@Hogarth45_ Well, the algo is wrong then. 10 crits and 1 xss is not worse than 10 crits. That was my point :) appreciate the extra insight
English
3
1
2
794
mongo
mongo@mongobug·
@Blaklis_ @njcve_ As the french ambassador can't you get him a french passport?
English
1
0
0
177
mongo
mongo@mongobug·
@Hogarth45_ Agreed, but I'm now hearing of people sitting on RXSS / SXSS / etc too. Admittedly I heard from a small percentage of hunters, but that doesn't seem like a net win for overall security
English
1
0
0
346
Jess
Jess@Hogarth45_·
@mongobug I know its very common for people to sit on open-redirects for use with SSRFs at a later date. I would suspect there is a great number of borderline bugs that get sat on. But ultimately more bugs are found with h1 than if it didn't exist. So not perfect, but better than nothing
English
1
0
2
334
mongo
mongo@mongobug·
@Hogarth45_ If true, then I wonder how many vulns are going unreported by people who are not willing to get 2 accounts (which is against the rules iirc)
English
1
0
2
505
Jess
Jess@Hogarth45_·
@mongobug To actually get traction you need 2 accounts on h1. One for high/crit and one for low/med.
English
1
0
1
623
mongo
mongo@mongobug·
@MrTuxracer @plmaltais @Hacker0x01 @Bugcrowd Unfortunately CVSS is hardly objective either, though. And it gets worse because half the bug bounty people and security teams do not fully understand the ratings for each field. Usually becomes a tug-of-war
English
1
0
5
870
ramsexy
ramsexy@plmaltais·
I'm curious to see bug bounty hunters opinion on this one. @Hacker0x01 and @Bugcrowd are attributing points differently (explanation in thread). Which one do you prefer?
English
9
1
30
19K
Maxime Rousseau
Maxime Rousseau@maxrousseau·
Can someone explain to me why people are losing their minds over this? It’s literally LESS SECURE to use sms two-factor. Doing a big public service here. Everyone should be actively planning to migtate away from sms for security.
Sam E. Antar@SamAntar

Memo to @twitter: Give me a break! Now, you’re trying to monetize account safety? Seriously?

English
4
1
9
4.5K
mongo
mongo@mongobug·
@DRUNKKZ3 Any plan to make TDM a permanent mode in 2042? I feel like you're going to remove it in season 4, that would drive a lot of people off
English
0
0
0
44
mongo
mongo@mongobug·
@MrTuxracer Top clown.. imagine dealing with this guy as a bug bounty triager or program owner...
English
2
0
7
3.6K
mongo retweetledi
Erin Jacobs
Erin Jacobs@SecBarbie·
I’ve loved watching how the @elonmusk @Twitter thing has impacted #InfoSec — meaning — people who do nothing but tweet all day and are defined by their egos and twitter identity have been freaking the fuck out — people who actually do the work really don’t care. Thoughts?
English
26
12
149
0
mongo
mongo@mongobug·
Can't wait for all the crybabies to finally "go to Mastodon" so my feed can stop being all about Elon and Twitter. If you're leaving, close your account and stop tweeting
English
2
4
34
0