pd
116 posts

pd retweetledi

@ComradeOetzi @IntCyberDigest I thought the same while read this post and no one talk about that.
English


‼️ Linus Torvalds told Linux kernel developers this week that Linux is not one of those anti-AI projects and that AI is now a clearly useful tool.
He says AI's usefulness was still arguable a year ago but no longer is, and that the doubters simply haven't used the tools. Nobody is forced to use AI, but he will ignore anyone trying to stop others from using it. Anyone who wants an anti-AI project, he says, can fork the code or walk away.
In 2024, Torvalds dismissed AI as mostly marketing. By this January he was shipping AI-generated Python in his own hobby repo, and the kernel now accepts AI-written code under disclosure rules.


English
pd retweetledi
pd retweetledi
pd retweetledi
pd retweetledi

Tomorrow I’m free, so let’s do something fun.
I’ll be doing a live Google API key hunting challenge here on Twitter.
you can Drop your favorite target domain in the post comments(tomorrow) and I’ll try to find Live Google API keys for it within minutes after your comment. and also try 403 bypass as well and some other techniques..
Until then, check out my latest video where I’ve covered all the methods in detail.
see u Tomorrow..
youtu.be/3KMUnLdlOSE?si…

YouTube
English
pd retweetledi
pd retweetledi

things are getting more serious.
[github dorking + manual hunting + burp extensions + private tools + a custom panel to use discovered API keys like gemini chat interface…
just enter a target domain or a list of subdomains and the tool handles the rest.
it scrapes API keys from page source and JS files at full high speed, then lets you verify them for vulnerable to issues like file disclosure, upload, delete and more.
this is just a small demo.
full video coming soon with much more things combined. you have no idea how much impact a single leaked API key can have at scale.
stay tuned.


English
pd retweetledi

My friend built an AI agent.
Took 2 hours.
It scanned 10,000 endpoints, found critical vulnerabilities, wrote the report, and sent remediation steps automatically.
Bug bounty payouts started hitting same week.
$200k in 3 months. Zero manual work.
The AI does recon, exploitation, reporting. All automated.
He just reviews the output over coffee.
Okay hear me out?
This guy doesn't exist. I made all of this up.
Because every other "I vibe coded and hit $500K MRR" post is also made up.
Stop believing everything you see online, and start hacking real targets.
English
pd retweetledi

infosecwriteups.com/hacking-micros…
This is the longest and most in-depth article I’ve published on Medium so far. It covers IIS and ASP dotNET vulnerabilities from absolute basics to advanced techniques. Even if you have zero background in IIS, you’ll be able to understand the fundamentals and move toward practical, real-world testing by the end.
English
pd retweetledi
pd retweetledi
pd retweetledi

@h4x0r_dz Medium suspended me thrice for this article. Read before it's too late
DARK SECRETS OF BUG BOUNTY | EXCLUSIVE INSIDERS REPORT
Find out how they rob honest security researchers
#bugbountyfraud #bugbountyscam
@elelyonmusk/%EF%B8%8F-dark-side-of-bug-bounty-programs-exclusive-report-af317b7fb2b0" target="_blank" rel="nofollow noopener">medium.com/@elelyonmusk/%…
English
pd retweetledi
pd retweetledi
pd retweetledi

youtu.be/ryIhM-C8gLo?si…
Just dropped a new video on Microsoft IIS vulnerabilities, focused on real-world testing across live targets..
In this video I walk through:
• Deep recon using multiple sources and smart dorking techniques
• Burp IIS extension + Shortscan for single and bulk target analysis
• Advanced ffuf fuzzing methods with my personal extension list
• Finding login panels via fuzzing and testing SQL injection with the PUT method [json based]
• Response manipulation techniques
• Practical 403 bypass strategies
• Path restriction and forbidden bypass methods
• Information disclosure and sensitive data exposure findings
• WAF bypass approaches
• Discovering hidden paths from source code and JavaScript
I hope you enjoy it and find it useful. Content like this takes a lot of time and effort to put together, especially when it comes to finding live targets to demonstrate real proofs of concept, so you get genuine exposure to how these issues are discovered and tested in real scenarios.

YouTube
English















