Samet Sahin

69 posts

Samet Sahin banner
Samet Sahin

Samet Sahin

@sametsahinnet

Founder @findhunterscom 🦅 h1/samet

🌍 Katılım Haziran 2013
721 Takip Edilen4.4K Takipçiler
Sabitlenmiş Tweet
Samet Sahin
Samet Sahin@sametsahinnet·
I'm excited 🎉 to introduce JSSCM! A browser extension that detects expired domains for Stored XSS. So you can find XSS and earn money while casually browsing. I've earned $5K+ in bounties with this extension. Check it out #BugBounty #OpenSource
English
4
48
298
19.2K
Samet Sahin
Samet Sahin@sametsahinnet·
@albinowax i noticed the same problem when i was doing bounties. so i drafted something called BBSS, bug bounty scoring system. but then i realized the real problem is not CVSS but the programs' tight budgets, which is a common problem in non-revenue-generating areas like cybersecurity 🤷‍♂️
English
0
0
0
348
James Kettle
James Kettle@albinowax·
CVSS' Attack Complexity metric is the bane of bug bounty hunters: "you tried really hard to find that bug, so we'll pay you less".
James Kettle tweet media
English
18
17
318
26.1K
Samet Sahin
Samet Sahin@sametsahinnet·
today i got this cute little mug from the @Hacker0x01 london meet up 😅 it was nice to catch up with folks
Samet Sahin tweet media
English
3
0
4
267
Samet Sahin
Samet Sahin@sametsahinnet·
I'm excited 🎉 to introduce collectvars! A browser extension that finds all JS variables and detects dangerous ones. So you can find secrets and earn money while casually browsing. Check it out github.com/sametsahinnet/… #BugBounty
English
2
30
137
9.6K
Samet Sahin
Samet Sahin@sametsahinnet·
I'm excited 🎉 to introduce JSSCM! A browser extension that detects expired domains for Stored XSS. So you can find XSS and earn money while casually browsing. I've earned $5K+ in bounties with this extension. Check it out #BugBounty #OpenSource
English
4
48
298
19.2K
Samet Sahin
Samet Sahin@sametsahinnet·
@ITSecurityguard Looks good. You might want to display EPSS score. I always check it to see if there is a known exploit. Just in case huntdb do not find all known exploits automatically.
English
1
0
2
642
Patrik Grobshäuser
Patrik Grobshäuser@ITSecurityguard·
Made a simple dashboard to help track/search CVEs and security vulnerabilities in near real-time. No fancy stuff - just a clean interface to see what's burning in the security world right now. (it's Ivanti🙈) huntdb.com/cve/CVE-2025-0…) huntdb.com Feedback welcome!
Patrik Grobshäuser tweet media
English
14
112
434
39.2K
Samet Sahin retweetledi
watchTowr
watchTowr@watchtowrcyber·
In August, watchTowr Labs hijacked parts of the global .mobi TLD - and went on to discover the mayhem that we could cause. Enjoy.... labs.watchtowr.com/we-spent-20-to…
English
9
126
345
49.2K
Samet Sahin
Samet Sahin@sametsahinnet·
Here how it works
English
0
0
3
610
Samet Sahin retweetledi
James Kettle
James Kettle@albinowax·
I'm attempting to kick off some research on a topic unrelated to request smuggling & cache poisoning, and wow it's a struggle. Specialism is dangerous stuff.
English
8
5
280
0
Samet Sahin retweetledi
shubs
shubs@infosec_au·
There is an ugly side to collaboration in bug bounties, which is often never spoken about publicly. It's my least favourite part of bug bounties. Keen to hear peoples thoughts. shubs.io/the-ugly-side-…
English
13
46
250
0
Samet Sahin retweetledi
Anton
Anton@ByQwert·
Open redirect vulnerability and how to use it "correctly" in bug bounty 🙃 link.medium.com/ftOSGKkZtqb
English
32
398
1.1K
0