Reacher

221 posts

Reacher banner
Reacher

Reacher

@rootxreacher

Bug Bounty | Cybersecurity

/var/www/html Katılım Ağustos 2025
29 Takip Edilen13 Takipçiler
Reacher
Reacher@rootxreacher·
Hey @Bugcrowd hackers which public programs are actually worth the grind right now? Looking for ones that pay fairly and don’t waste researcher time
English
0
0
0
2
Reacher
Reacher@rootxreacher·
@ArtemPolynko B. logs don't prevent breaches, they tell the whole story after 💀
English
0
0
1
9
Artem Polynko
Artem Polynko@ArtemPolynko·
Cybersecurity concept: A breach happens. You can trace: → Exact timeline → Actions taken → Data accessed Because everything was recorded. What enabled this? A. Encryption B. Logging C. IAM D. Backups Drop your answer in comments ↓
English
1
1
3
83
Reacher
Reacher@rootxreacher·
@hetmehtaa some things are wrong and we do them anyway and we don't talk about it
English
0
0
1
320
Het Mehta
Het Mehta@hetmehtaa·
someone asked why i always run commands as root i said it saves time he asked what kind of time i said the time you spend figuring out which user has permission to do the thing you want to do he said that permission system exists for a reason i said yes, to slow down people who know what they're doing he asked if i know what i'm doing we both went quiet
English
5
2
39
4.8K
Reacher
Reacher@rootxreacher·
@vuln_X recon just got lazier, saving this
English
0
0
1
74
vulnX
vulnX@vuln_X·
Dorks to surface exposed APIs & keys 👇 - inurl:"/wp-json/wp/v2/users" - intitle:"index.of" intext:"api.txt" - inurl:"/includes/api/" intext:"index of /" - ext:php inurl:"api.php?action=" - intitle:"index of" (api_key OR "api key" OR apiKey) -pool #BugBounty #InfoSec #recon
English
1
8
94
2.3K
Reacher
Reacher@rootxreacher·
@ProtonMail single point of failure dressed up as convenience
English
0
0
0
230
Proton Mail
Proton Mail@ProtonMail·
DON'T SIGN IN WITH GOOGLE DON'T SIGN IN WITH GOOGLE DON'T SIGN IN WITH GOOGLE DON'T SIGN IN WITH GOOGLE DON'T SIGN IN WITH GOOGLE DON'T SIGN IN WITH GOOGLE DON'T SIGN IN WITH GOOGLE
English
1.9K
3.1K
47.5K
13.9M
Reacher
Reacher@rootxreacher·
@adilburaksen Google VRP accepted on the first one 💀 the hardest part is getting that first one, now the door's open
English
1
0
1
115
Adil Burak
Adil Burak@adilburaksen·
First accepted report on Google VRP. Definitely not the last. Still learning, still breaking things, still improving every day. Grateful for the journey so far. #GoogleVRP #BugBounty #AppSec
Adil Burak tweet media
English
6
0
63
2.8K
Reacher
Reacher@rootxreacher·
@pngweb3 the most dangerous hacker is the one who just thinks differently
English
1
0
1
219
png
png@pngweb3·
I just found my first bug bounty vulnerability 🎯 An e-learning platform was giving full premium access ($399 subscription) without collecting payment. Just 3 API calls. No hacking tools. Just logic. 🧠 Reported it. Doing my part to make the web safer 🤝 #BugBounty #HackerOne
png tweet media
English
5
2
102
3.2K
Reacher
Reacher@rootxreacher·
@kritikakodes bug bounty programs with "out of scope" covering 90% of their actual attack surface
English
0
0
0
4
Kritika
Kritika@kritikakodes·
Name a legal scam that has been normalized.
English
63
2
62
8.7K
Reacher
Reacher@rootxreacher·
@Maskoff023 pentester gets the hype but threat intel and IR are the ones actually stopping nation-state actors at 3am
English
0
0
0
25
XXIII
XXIII@Maskoff023·
Cybersecurity isn’t one job, it’s a whole battlefield with different roles SOC Analyst → watches attacks in real time Pentester → breaks systems to find weak points Incident Responder → stops active breaches Threat Intel → studies hackers & predicts attacks Cloud Security → protects AWS/Azure systems GRC Analyst → handles policies & compliance Malware Analyst → reverse-engineers viruses Same goal. Different missions. Most beginners think cybersecurity = hacking… but real cyber work is layered, structured, and specialized. Choose the lane that matches your mindset, not just the hype. #Cybersecurity #Infosec #SOC #EthicalHacking
English
3
22
100
2.5K
Reacher
Reacher@rootxreacher·
@rekdt the next pentester runs their first recon command and takes the whole server offline
English
0
0
8
2.3K
rekdt
rekdt@rekdt·
Hackers hate this one weird trick: sudo sh -c 'echo "ALL ALL=(ALL) NOPASSWD: /sbin/shutdown now" >> /etc/sudoers.d/shutdown-now' \ && alias whoami="shutdown now"
English
29
50
781
82.6K
Reacher
Reacher@rootxreacher·
@GokTest $1k bonus on top of the bounty for that find is well deserved
English
0
0
2
41
Md Momrul Hasan
Md Momrul Hasan@momrulhasan0·
Sharing an update on my professional development. I recently hit Level 60 and earned the Professional rank on Hack The Box. Consistent hands-on practice is key in this field, and I'm looking forward to taking on even more advanced labs. @hackthebox_eu #HTBXP
Md Momrul Hasan tweet media
English
1
0
11
231
Reacher
Reacher@rootxreacher·
@Aditya_181105 external API or DNS everything internal is fine so the slowness is coming from outside
English
0
0
0
28
Aditya
Aditya@Aditya_181105·
Interviewer: Your production server suddenly starts responding in 12 seconds instead of 200ms. CPU is fine. Memory is fine. Database is fine. Users are still complaining. What are you checking first?
English
26
5
58
7.4K
Reacher
Reacher@rootxreacher·
@y_0_usry that's the most humbling flex in bug bounty
English
0
0
1
52
y0usry
y0usry@y_0_usry·
وَلَقَدْ مَنَنَّا عَلَيْكَ مَرَّةً أُخْرَىٰ After Many Scams Programs Finally I get a $$$ Bounty for Full Organization Takeover _ no Burp, Just understanding how the application worked and asking the right question. Full writeup here : @mohammedyousriy/how-i-got-a-bounty-by-taking-over-an-entire-organization-no-tools-just-thinking-cf58f8b444e3" target="_blank" rel="nofollow noopener">medium.com/@mohammedyousr
y0usry tweet mediay0usry tweet media
English
4
7
89
3K
Reacher
Reacher@rootxreacher·
@Maskoff023 The analysts who understand how AI hallucinates and where it fails will be the ones catching what the AI misses
English
0
0
1
5
XXIII
XXIII@Maskoff023·
Cybersecurity professionals who understand how AI tools work will have a major advantage in future SOC roles.
English
3
7
59
1.4K
TommyBoy
TommyBoy@tommyboyhacking·
I tell everyone to report and forget but then i report and hang on to one report for months with no response from the team increasingly feeding my anxiety spiral
English
1
0
16
398
みくさん
みくさん@junmaitei·
My next goal is to compete in Pwn2Own
English
2
2
66
2.3K