SherlockSecure

827 posts

SherlockSecure banner
SherlockSecure

SherlockSecure

@sherlocksecure

Security Engineer | I'm that SherlockSecure ;(

Chennai, India Katılım Mart 2013
198 Takip Edilen4K Takipçiler
Deepak bug_vs_me
Deepak bug_vs_me@bug_vs_me·
Is bug bounty going to be dead in the next 5 years?
English
33
2
118
16.8K
Warp
Warp@warpdotdev·
Launching something big tomorrow...
Warp tweet media
English
318
43
1.2K
5.7M
SherlockSecure
SherlockSecure@sherlocksecure·
@Burp_Suite SSO? Honestly You guys need more AI integrations at this moment. Add BYOK with DAST via burp agents.
English
1
0
0
339
Burp Suite
Burp Suite@Burp_Suite·
Authenticated vulnerability scans made easy… Let Burp AI handle the login flow for active scans!
English
4
32
223
16.1K
SherlockSecure
SherlockSecure@sherlocksecure·
@fmdz387 You're secure! Here's what your config shows: gateway: port: 18789 mode: "local" bind: "loopback" ← This is the key setting! auth: mode: "token" ← Plus token auth required bind: "loopback" means the gateway only listens on 127.0.0.1 your local machine only.
English
0
0
1
268
fmdz
fmdz@fmdz387·
Clawd disaster incoming if this trend of hosting ClawdBot on VPS instances keeps up, along with people not reading the docs and opening ports with zero auth... I'm scared we're gonna have a massive credentials breach soon and it can be huge This is just a basic scan of instances hosting clawdbot with open gateway ports and a lot of them have 0 auth
fmdz tweet media
English
413
770
7.1K
1.6M
Nalini Unagar
Nalini Unagar@NalinisKitchen·
I always wonder what these lines are for.
Nalini Unagar tweet media
English
6.3K
342
23.2K
32.6M
Aziz
Aziz@nXtExploit·
@sherlocksecure @Burp_Suite @albinowax That would be really cool 👌. The only issue is these models often refuse to answer anything related to hacking, even with 'custom instructions' for every response, so most of the time we have to clarify it’s for CTFs or authorised testing.
English
1
0
0
47
SherlockSecure
SherlockSecure@sherlocksecure·
@Burp_Suite @albinowax Can Burp Suite add a ‘bring your own API key’ option for Burp AI, allowing users to plug in their own Anthropic, Gemini, or other model keys?
English
1
0
0
105
SherlockSecure
SherlockSecure@sherlocksecure·
Is it the new normal at @HackenProof? Reported an issue in January, yet no response from Dev, but the issue is fixed, and the dev & triage team are not responding to any queries or updates. @1inch #BugBounty
SherlockSecure tweet media
English
2
1
38
2.9K
SherlockSecure
SherlockSecure@sherlocksecure·
Thanks for the idea, my own automation is almost ready, deployed in aws servers and will overtake yours with report creation just requiring my approval to submit 😜. This cover all the attacker surface you have mentioned and additional few more as well. PS: I’m not gonna sell it, just wrote for own journey.
English
3
0
3
876
Arshad Kazmi
Arshad Kazmi@arshadkazmi42·
We just launched a new landing page for iScan[.]today Check it out 👇
English
1
0
5
598
SherlockSecure
SherlockSecure@sherlocksecure·
@NahamSec @Google There is an option now “You can request to review the bounty decision”. For me sadly they rewarded $500 where I have access to their entire GitHub repositories and 200+ secret keys in it.
English
0
0
2
1K
Ben Sadeghipour
Ben Sadeghipour@NahamSec·
No bounty from @google for getting an RCE on google.com. I know there were some requirements for this to work and I wasn't expecting a $50,000 bounty, but wasn't expecting to "not meet the bar for a financial reward" at all. At least I can say I "RCE'd" google.
Ben Sadeghipour tweet media
English
70
67
1.3K
115.5K
SherlockSecure
SherlockSecure@sherlocksecure·
@Info_IntelX If you can add a new date column with sorting feature would be good.
English
1
0
0
486
Intelligence X News
Intelligence X News@Info_IntelX·
💥 We added a powerful new feature to the Identity Portal: Reverse Lookup You can now search for a domain or URL and get all leaked accounts for a particular service. ➡️ Read more at blog.intelx.io/2025/01/03/new…
Intelligence X News tweet media
English
4
0
11
3.2K
Intelligence X News
Intelligence X News@Info_IntelX·
We are just finishing the work on one of our most powerful and important new features. It will be available to users with an Identity Portal license and in the beginning upon invitation only.
English
3
0
9
2.1K