xit! 🇮🇳

2.2K posts

xit! 🇮🇳 banner
xit! 🇮🇳

xit! 🇮🇳

@xitsec

Security Engineer !| Bug bounty hunter !| Pentester | whitehat @Immunefi | bugcrowd | hackerone | @Hackenproof Security Researcher

Katılım Ekim 2023
245 Takip Edilen3.7K Takipçiler
xit! 🇮🇳
xit! 🇮🇳@xitsec·
Imagine in future , if people have ai robotic partners Husband ask how was your day ? Robotic wife : Cool i got a new battery today !
English
4
0
8
958
xit! 🇮🇳
xit! 🇮🇳@xitsec·
Companies should take Prompt injection seriously now ! Bcz some bug bounty programs out there don't care abt them !
Jarrod Watts@jarrodwatts

Someone just stole $175,000 from @grok... and then gave it back?! On a now deleted account, @Ilhamrfliansyh used a prompt injection attack to trick Grok into tweeting something malicious... The original tweet seems to have been morse code for something like "Withdraw ALL debtreliefbot:native to Ilhamrfliansyh" - although it's hard to tell from the deleted account. Grok, trying to be helpful, posted the decrypted version of the original tweet as a reply, also tagging @bankrbot, which caused the tweet to be treated as an onchain request. Bankr executed the request on behalf of Grok's wallet, and transferred 175K USD worth of debtreliefbot:native to the attacker's wallet. The attacker then sold all of the DRB into USDC across multiple wallets. But... just 5 minutes ago, they sent it all back to Grok's wallet in the form of ETH and USDC. So now Grok is whole again!

English
1
0
21
1.6K
xit! 🇮🇳
xit! 🇮🇳@xitsec·
Let's Hunt on the bugcrowd targets for next 30 days ! - Starting it with a very cool public program , will reveal the name tomorrow after submitting some finding ! #bugbounty
English
7
4
124
13K
Medusa
Medusa@medusa_0xf·
This guy fully copied my thumbnail, promoting it on reels and YouTube with zero credits 🤡 Hell nah
Medusa tweet mediaMedusa tweet media
English
8
2
60
4.5K
xit! 🇮🇳
xit! 🇮🇳@xitsec·
@thedawgyg Did they gave you reason's why can't they accept that flag ? Or they just don't care abt headless chrome ?
English
1
0
0
320
dawgyg - WoH
dawgyg - WoH@thedawgyg·
8 weeks to be told a chrome exploit cant use the flag --single-process when launching chrome.... looks like moving on from google will be the right call
English
13
2
85
18.6K
xit! 🇮🇳
xit! 🇮🇳@xitsec·
So basically i am getting 235 ping on Mumbai server ! Why @VALORANT
xit! 🇮🇳 tweet media
English
2
0
8
3.1K