ph0r3nsic 🕷️
145 posts

ph0r3nsic 🕷️
@ph0r3nsic
Founder @DeepLookLabs | OSWE | Offensive Security Bug Hunter 🎯 · HackerOne · Intigriti · Bugcrowd
Katılım Mart 2018
678 Takip Edilen476 Takipçiler
Sabitlenmiş Tweet

Very good points
The state of Bug Bounty in 2026 aituglo.com/state-of-bug-b…
Aituglo - Cassim@aituglo
I've been doing bug bounty for years. I just published a long piece on what it actually feels like in 2026, and why something fundamental has shifted. aituglo.com/state-of-bug-b… Would love to get your feedback on it here on X or directly on the blog
English

Found an interesting path traversal by manually tinkering. I was getting blocked by software filtering, then by WAF. This bypassed both. #bugbountytips
Instead of:
page.php?file=\..\..\..\..\dir1\dir2\dir3\dir4\fileName.ext
Try:
page.php?file=\.\..\.\\.\..\.\\.\..\.\\.\..\.\dir1\dir2\dir3\dir4\fileName.ext
For whatever reason, this bypassed both software and WAF controls. May be a fringe thing but worth adding to your traversal checklists. Having the slashes the wrong direction and intermixing with single dots and double slashes caused (I'm guessing regex) to have an aneurysm.
English

It's true: today you create the most powerful tool. Tomorrow, it becomes the simplest tool.
Aituglo - Cassim@aituglo
Hardware setup, lack of knowledge, and building apps aituglo.com/aituweek-80/
English

AI Tuning TIP:
Many people change the model but leave effort untouched, missing a big part of the tuning.
The effort setting controls how much reasoning the model applies.
Low -> faster responses
Medium -> balanced (default)
High -> better for complex problems
#AI #BugBounty


English

It's finally out there! We’ve been planning this for a while, and honestly, it’s just the start.
Keep an eye out for the blog posts we’re dropping soon because they’re basically a playbook on how to make a killing on AI targets in bug bounty.
Starstrike AI@StarstrikeAI
Today, we (@busf4ctor and @monkehack), are launching Starstrike: an AI pentesting and research startup. We'll be releasing our first few research articles over the next few weeks, detailing several bugs that helped us net over $100k in total. Follow to ensure you don't miss them!
English

Simple trick to iframe sandbox
wallesonmoura.com.br/2026/01/21/tri…
#iframe #sandbox #bugbounty #bugbountytips
English

Carefully curated links, not just random blog updates — saving powerful chains you can revisit anytime!
Stay sharp and grow with the ethical hacking community.
Discord: discord.gg/58eFp42PQm
English

If you have an LFI (Local file include), you can discovery internal paths with this technique:
#bugbountytips

English

When applying for a job at McDonald's, over 90% of franchises use "Olivia," an AI-powered chatbot. We (@iangcarroll and I) discovered a vulnerability that could allow an attacker to access the over 64 million chat records using the password "123456".
ian.sh/mcdonalds
English

Just imported a fresh list of users to the #Disclosed Hacker Directory! Check to see if your account is there.
If you want an account and don't have one, make sure to subscribe to the newsletter and fill out the onboarding survey (link in thread).

English
ph0r3nsic 🕷️ retweetledi

Bug hunters, level up with GBRlink! 🔍
- Advanced link analysis
- Subdomain takeover detection
- Registrable domain mapping
- Get 20% off with STARTER0325.
Join now: deeplooklabs.com/gbrlink
#bugbounty #bugbountytips

English

If you can get UUID of users in NBA program, ping me to collab :)
#BugBounty
English
ph0r3nsic 🕷️ retweetledi

A hunter shares exact stats and earnings of his first 12 months of hunting feat. @shreyas_chavhan #bugbounty #bugbountytips #bugbountyhunter
English
ph0r3nsic 🕷️ retweetledi

Medusa by @Ch0pin is a game-changer for mobile bug hunters 📱🕵️
With its FRIDA-powered framework, you can automate tasks like bypassing SSL pinning, tracing function calls, and modifying app behaviour in real time. Perfect for uncovering vulnerabilities in Android & iOS apps! 🔍
Check it out 👉 github.com/Ch0pin/medusa
#BugBountyTips #YesWeRHackers
GIF
English
ph0r3nsic 🕷️ retweetledi

Voting is now live for the Top Ten (New) Web Hacking Techniques of 2024! Browse the nominations & cast your votes here: portswigger.net/polls/top-10-w…
English


