Pwnr

438 posts

Pwnr

Pwnr

@yacynx

I hack stuff'-- -

404 - Not Found Katılım Mayıs 2020
2.5K Takip Edilen472 Takipçiler
Pwnr retweetledi
s1r1us (mohan)
s1r1us (mohan)@S1r1u5_·
when react2shell hit last year, i think vercel handled it brilliantly. to protect their users, they paid $50,000 for every bypass researchers could find. we decided to participate, and ended up earning $170,000. read how we did it here: hacktron.ai/blog/react2she…
English
4
46
246
9.5K
Pwnr retweetledi
Unit 42
Unit 42@Unit42_Intel·
Obfuscated #WebSocket backdoors are injecting credit card skimmers into hundreds of compromised websites. The payload sends stolen card information back to attacker's C2 domains. Details at: bit.ly/42HyNb3
Unit 42 tweet media
English
6
147
671
55K
Pwnr
Pwnr@yacynx·
Sure, I could publish everything and force them to fix it within hours... but I won’t. I did my part: I tested the app, found the issues, and reported them responsibly. I can live with that. If anything happens, it’s on them for failing to act.
English
0
0
1
21
Pwnr
Pwnr@yacynx·
This happened to me a few months ago. I tested an app because I was a regular user, and I ended up discovering several serious vulnerabilities, millions of chats, hundreds of thousands of users, their PII, and numerous files were exposed.
impulsive@weezerOSINT

if you've ever used Reframe to get sober, your private journals, your craving logs, what triggered you, how bad it got, your name, your email, all of it is sitting in a database that anyone can read without logging in i unzipped the app and found a database key in a config file. thats it. thats all it took 357,939 users exposed. disclosed april 7, no response

English
3
0
1
119
Pwnr
Pwnr@yacynx·
Months passed… and nothing changed. The vulnerabilities are still there to this day.
English
0
0
1
20
Pwnr
Pwnr@yacynx·
I reached out to their support team, staff, and even the CEO through both LinkedIn and email, but got no response after a week. So I put together a detailed report with all the findings and PoCs and sent it directly to the CEO again via email and LinkedIn.
English
0
0
1
29
Pwnr retweetledi
watchTowr
watchTowr@watchtowrcyber·
The Internet is falling down, falling down, falling down Welcome back to another disaster - this time, an Auth Bypass in cPanel/WHM, tracked as CVE-2026-41940 Enjoy with us.. labs.watchtowr.com/the-internet-i…
English
11
178
617
143K
Pwnr retweetledi
Phith0n
Phith0n@phithon_xg·
Ghost Bits is a brilliant research: i.blackhat.com/Asia-26/Presen… Now you can reproduce CVE-2025-41242 in Vulhub, Spring/Jetty Path traversal caused by Ghost Bits: github.com/vulhub/vulhub/… This issue exists in spring-boot-starter-jetty <= 3.2.4 with zero configuration
Phith0n tweet mediaPhith0n tweet media
English
3
75
297
29.7K
Pwnr retweetledi
Hazem
Hazem@H4cktus·
Tomcat JMX Proxy exposed without auth? Wrote a blog about how I got shell on a production Tomcat behind Cloudflare despite the deploy API being locked down, WAF blocking payloads, and CDN filtering template syntax. 8 dead ends. Then AccessLogValve + docBase + relaxedQueryChars + EL injection. 14 requests to RCE. Tool + nuclei template included! hackt.us/from-tomcat-jm… #bugbountytips #bugbounty
English
3
25
119
6.8K
introvert
introvert@livewithnoregrt·
name one thing more valuable than money.
English
3.1K
263
3.3K
577.1K
Fat
Fat@fattselimi·
Face reveal of @badcrack3r 💯🧿
Fat tweet media
English
3
0
56
6.2K
Pwnr
Pwnr@yacynx·
@georgegalloway The world know what this people are already. The question is what did we do about them ? Nothing.
English
0
1
1
33
YS
YS@YShahinzadeh·
I published one of the techniques that I've been using against OAuth providers, honetly, it's led me to discover many flaws, and recently I used it to find a 1-click ATO on one of the most widely visited websites,I hope you find it useful :-) blog.voorivex.team/story-of-abusi…
YS tweet media
English
19
119
647
28.3K
dawgyg - WoH
dawgyg - WoH@thedawgyg·
@pwnx00 @Masonhck3571 @h4x0r_dz if they ever did it for religion they wouldn't be open anymore. Could sue them into bankruptcy and I would back the person financially to sue if needed (if they had evidence it was based on religion).
English
1
0
2
388