PwrSpl0it

508 posts

PwrSpl0it banner
PwrSpl0it

PwrSpl0it

@newbiepath

Bug bounty hunter, web app security enthusiast, chess player, soccer player sometimes

Morocco Katılım Şubat 2017
1K Takip Edilen874 Takipçiler
Sabitlenmiş Tweet
PwrSpl0it
PwrSpl0it@newbiepath·
today I crossed 23 years, one year ago I got arrested for illegal hacking and I was about going to jail but thanks god and I thank everyone from the bug bounty hunting community for changing my life from the worst to the better especially @NahamSec @Jhaddix @Bugcrowd @Hacker0x01
PwrSpl0it tweet media
English
20
8
162
0
PwrSpl0it
PwrSpl0it@newbiepath·
@karan_srma try for sensitive cases DELETE endpoints / PATCH etc ...
English
0
0
0
388
Karan Sharma
Karan Sharma@karan_srma·
Bug hunters, how do you usually test for IDOR? I know the basics (checking params, object IDs, user IDs etc.), but curious what patterns or workflows you use in real hunts. #BugBounty #WebSecurity #InfoSec
English
3
4
51
5.7K
PwrSpl0it
PwrSpl0it@newbiepath·
My Progress : Almost 2 month of hunting 10 informative bugs, let's keep grinding
PwrSpl0it tweet media
English
3
3
102
5.9K
PwrSpl0it
PwrSpl0it@newbiepath·
@Bug_X_hunter And the problem happened i did not realize there is time bounding and the triager while doing the assessment the information already deleted
English
0
0
1
68
PwrSpl0it
PwrSpl0it@newbiepath·
@chanukaisdumb @Bug_X_hunter @skulldentist No they did not , and it's not full positive , the problem as i said about time bounding, after u order the 48 hours i can see driver info and the geolocation info after 48 hours those information automatically deleted by system
English
1
0
1
38
PwrSpl0it
PwrSpl0it@newbiepath·
let's see if we will got another informative bug or triaged
PwrSpl0it tweet media
English
1
0
36
2.1K
Amr
Amr@Gomawyy·
Another dublicate
Amr tweet media
English
7
10
89
4K
PwrSpl0it
PwrSpl0it@newbiepath·
@stilla1ex unicode is much more effective but i think most of host providers patch it since you can register any domain with other keyboards schemes and it will exactly match the keywords
English
1
0
0
24
whitehats
whitehats@wh1t3h4ts·
Hackers can create urls that look almost identical to legitimate ones. Can you spot the legitimate url? What type of attack is this.
whitehats tweet media
English
143
87
952
89.8K
Elon Musk
Elon Musk@elonmusk·
There you have it
Elon Musk tweet media
English
24.5K
15.4K
229.1K
38.5M
Fat
Fat@fattselimi·
What do you all do when you don't feel like Hacking? #BugBounty
English
41
3
115
15.3K
PwrSpl0it
PwrSpl0it@newbiepath·
@Cubed_h1 @Michael1026H1 That's mean they had a strong security engineer and that's a compliment to him hahahaha instead of offending hahaha
English
1
0
0
86
Cubed
Cubed@Cubed_h1·
@newbiepath @Michael1026H1 Lmao you were sharing that like it’s feedback he needed. “There aren’t enough bugs at the company you’re working at :(“
English
1
0
0
82
Michael Blake
Michael Blake@Michael1026H1·
Today marks my last day as a security engineer at Headspace as I move on to full time bug bounty.
English
14
3
226
14.6K
PwrSpl0it
PwrSpl0it@newbiepath·
@Michael1026H1 No don't feel offended im just shared my experienced i know my fault for not digging more
English
1
0
2
276
Michael Blake
Michael Blake@Michael1026H1·
@newbiepath And? Should we have introduced more vulnerabilities for you to find?
English
1
0
5
393