TommyBoy

173 posts

TommyBoy banner
TommyBoy

TommyBoy

@tommyboyhacking

Hack/Planets 🪐

Katılım Haziran 2025
117 Takip Edilen267 Takipçiler
Sabitlenmiş Tweet
TommyBoy
TommyBoy@tommyboyhacking·
The bug bounty cinematic universe
TommyBoy tweet mediaTommyBoy tweet media
English
12
2
98
6.8K
Roll4Combat
Roll4Combat@BadAt_Computers·
Saturday was a hell of a day. Found a bug, got engaged and @Wrexham_AFC won their game. Couldn’t have asked for a better Saturday !
Roll4Combat tweet mediaRoll4Combat tweet mediaRoll4Combat tweet media
English
13
2
65
5.6K
TommyBoy retweetledi
ChaoticV
ChaoticV@_ChaoticV·
Been working on a new tool for bug bounty hunters and will be looking for some testers in the near future, message me if you are interested! chaoticrecon.com
English
0
3
10
1.2K
the_IDORminator
the_IDORminator@the_IDORminator·
By the way, I didn't get paid for this, it was a duplicate. The first of several issues with this company. I logged 3 bugs, not sure I got paid for any, and never went back. When companies have SSRFs like this they don't fix, its a warning sign. Run.
English
2
0
38
3.9K
the_IDORminator
the_IDORminator@the_IDORminator·
SSRF - Internet to Internal #CyberSecurity Try to find the internal domains for targets using tools like crt.sh, shodan, censys, etc. Once you have some domains, blast them into any params you suspect may be susceptible. This one allowed total internal network access from internet. As a side note, don't forget to check any JS files on your target for domains the files reference. Often times, the dev/uat/preprod environment paths are in there, as well as other internal paths (docker, kube, etc) as well as which cloud provider is being used (azure, aws, goog, etc). As you work longer on a single target, you really get to know it...
the_IDORminator tweet media
English
3
35
313
14.5K
TommyBoy
TommyBoy@tommyboyhacking·
Happy New Year to all who celebrate 🎉
English
0
0
5
285
TommyBoy
TommyBoy@tommyboyhacking·
At times I've considered other avenues of cyber to get into as things were going poorly. Not so much in the finding bugs part but more on the getting compensated side. Ultimately I feel like I'm where I'm supposed to be here, so it's time to lock in and pop off in 2026. LFG
English
1
0
6
226
TommyBoy
TommyBoy@tommyboyhacking·
Pretty shit bug bounty year for me. I don't submit a high quantity of bugs, because I still get hung up on the outcome of reports. But to end on a positive: -Found my first crits -Was nominated for LHE (didn't get in) -Learned a lot of Android Hacking, hoping to capitalize.
English
1
0
25
1.3K
TommyBoy
TommyBoy@tommyboyhacking·
Restart the router, save the holidays
English
0
0
5
197
TommyBoy retweetledi
Nowasky
Nowasky@nowaskyjr·
Sanitizers may allow <https://> thinking it's an Markdown autolink. But if it's rendered as raw HTML instead of an anchor tag, it becomes a XSS vector. In this PoC, the browser creates a custom https: tag and parses the URL components as HTML attributes. storage.googleapis.com/nowaskyjr/xss-…
Nowasky tweet media
English
5
39
245
17.5K
TommyBoy retweetledi
Faav
Faav@efaav·
Please come watch my first talk tommorow at NahamCon!
Faav tweet media
English
5
3
48
1.7K
TommyBoy
TommyBoy@tommyboyhacking·
I stayed on @Hacker0x01 fought my way out of the negative signal state, and when I finally got back positive, I request meditation or some help, I get ignored for months if I ever get a response :D
English
0
0
6
168
TommyBoy
TommyBoy@tommyboyhacking·
Yes, it is a BS bug, but it really didn't warrant an N/A imo. There was an issue, it was pointed out, it was actually fixed by Shopify but obviously had no security impact. Should've been informational. Took months to get out of negative signal as at the time I duped a lot.
English
1
0
6
194
TommyBoy
TommyBoy@tommyboyhacking·
@hacker_ Really put those stories to bed...
English
0
0
1
102
TommyBoy
TommyBoy@tommyboyhacking·
@hanzceo - nope i wish - because im a dingus who didn't consider that - not sure what repo you're referring to
English
0
0
1
31
Hanz
Hanz@hanzceo·
@tommyboyhacking - emulator on linux? - why not save a backup - is repo open or nah
English
1
0
0
45
TommyBoy
TommyBoy@tommyboyhacking·
just nuked my only working rooted android emulator set up AMA
English
2
0
3
335
TommyBoy
TommyBoy@tommyboyhacking·
First lesson to any aspiring Android hackers: Never Wipe System Data on your rooted device
English
0
0
0
148
TommyBoy
TommyBoy@tommyboyhacking·
the amount of times i had failed to get this all running properly, finally happy i had it all running, then just nuked it CHRIST
English
1
0
1
158