ph0r3nsic 🕷️

145 posts

ph0r3nsic 🕷️ banner
ph0r3nsic 🕷️

ph0r3nsic 🕷️

@ph0r3nsic

Founder @DeepLookLabs | OSWE | Offensive Security Bug Hunter 🎯 · HackerOne · Intigriti · Bugcrowd

Katılım Mart 2018
678 Takip Edilen476 Takipçiler
Sabitlenmiş Tweet
ph0r3nsic 🕷️
ph0r3nsic 🕷️@ph0r3nsic·
A channel dedicated to cybersecurity — sharing daily updates, insights, and powerful tools from the infosec world. Instead of keeping interesting links and resources to myself, I decided to share them with the community — helping others discover great reads and useful tools. 👇🏻
English
2
0
1
130
the_IDORminator
the_IDORminator@the_IDORminator·
Found an interesting path traversal by manually tinkering. I was getting blocked by software filtering, then by WAF. This bypassed both. #bugbountytips Instead of: page.php?file=\..\..\..\..\dir1\dir2\dir3\dir4\fileName.ext Try: page.php?file=\.\..\.\\.\..\.\\.\..\.\\.\..\.\dir1\dir2\dir3\dir4\fileName.ext For whatever reason, this bypassed both software and WAF controls. May be a fringe thing but worth adding to your traversal checklists. Having the slashes the wrong direction and intermixing with single dots and double slashes caused (I'm guessing regex) to have an aneurysm.
English
6
65
615
20.9K
bsysop
bsysop@bsysop·
AI Tuning TIP: Many people change the model but leave effort untouched, missing a big part of the tuning. The effort setting controls how much reasoning the model applies. Low -> faster responses Medium -> balanced (default) High -> better for complex problems #AI #BugBounty
bsysop tweet mediabsysop tweet media
English
3
2
76
4.8K
Vitor Falcão "busfactor"
Vitor Falcão "busfactor"@busf4ctor·
It's finally out there! We’ve been planning this for a while, and honestly, it’s just the start. Keep an eye out for the blog posts we’re dropping soon because they’re basically a playbook on how to make a killing on AI targets in bug bounty.
Starstrike AI@StarstrikeAI

Today, we (@busf4ctor and @monkehack), are launching Starstrike: an AI pentesting and research startup. We'll be releasing our first few research articles over the next few weeks, detailing several bugs that helped us net over $100k in total. Follow to ensure you don't miss them!

English
2
9
97
7.2K
ph0r3nsic 🕷️
ph0r3nsic 🕷️@ph0r3nsic·
A channel dedicated to cybersecurity — sharing daily updates, insights, and powerful tools from the infosec world. Instead of keeping interesting links and resources to myself, I decided to share them with the community — helping others discover great reads and useful tools. 👇🏻
English
2
0
1
130
ph0r3nsic 🕷️
ph0r3nsic 🕷️@ph0r3nsic·
Carefully curated links, not just random blog updates — saving powerful chains you can revisit anytime! Stay sharp and grow with the ethical hacking community. Discord: discord.gg/58eFp42PQm
English
0
0
1
39
ph0r3nsic 🕷️
ph0r3nsic 🕷️@ph0r3nsic·
If you have an LFI (Local file include), you can discovery internal paths with this technique: #bugbountytips
ph0r3nsic 🕷️ tweet media
English
0
1
6
1.7K
Sam Curry
Sam Curry@samwcyo·
When applying for a job at McDonald's, over 90% of franchises use "Olivia," an AI-powered chatbot. We (@iangcarroll and I) discovered a vulnerability that could allow an attacker to access the over 64 million chat records using the password "123456". ian.sh/mcdonalds
English
18
117
469
41.9K
Harley Kimball
Harley Kimball@infinitelogins·
Just imported a fresh list of users to the #Disclosed Hacker Directory! Check to see if your account is there. If you want an account and don't have one, make sure to subscribe to the newsletter and fill out the onboarding survey (link in thread).
Harley Kimball tweet media
English
4
4
47
4.7K
ph0r3nsic 🕷️ retweetledi
Joseph Thacker
Joseph Thacker@rez0__·
root. for. your. friends. 🤼 it's more than a phrase, it's a deeply held belief. it's way of living, really. if you want to reject jealousy and thrive in your work and relationships, check out my latest blog post.
Joseph Thacker tweet media
English
13
49
314
41.4K
ph0r3nsic 🕷️ retweetledi
YesWeHack ⠵
YesWeHack ⠵@yeswehack·
Medusa by @Ch0pin is a game-changer for mobile bug hunters 📱🕵️ With its FRIDA-powered framework, you can automate tasks like bypassing SSL pinning, tracing function calls, and modifying app behaviour in real time. Perfect for uncovering vulnerabilities in Android & iOS apps! 🔍 Check it out 👉 github.com/Ch0pin/medusa #BugBountyTips #YesWeRHackers
GIF
English
2
122
528
25.6K
ph0r3nsic 🕷️ retweetledi
James Kettle
James Kettle@albinowax·
Voting is now live for the Top Ten (New) Web Hacking Techniques of 2024! Browse the nominations & cast your votes here: portswigger.net/polls/top-10-w…
English
7
65
274
140K