youroldman

360 posts

youroldman

youroldman

@youroldman

23/ wannabe hacker

Katılım Kasım 2022
185 Takip Edilen28 Takipçiler
Jenish Sojitra
Jenish Sojitra@_jensec·
Drop some Links; Who is your Favourite Cyber Security content creator? I am looking for some partnership
English
35
5
101
13.5K
youroldman
youroldman@youroldman·
@tabaahi_ i think he would have appreciated more if you didnt straight report the bug but discuss with him how exactly you found that bug. this will help the community deepdive into how a successful hunters brain works. Nonetheless, youre doin great!
English
0
0
3
108
youroldman retweetledi
𝕵𝖔𝖙𝖆 | jotita3
I find a subdomain that has a login. I don't have access. If I create an account, it has to be approved... No problem 😈 I read the JS files > find some interesting paths like /proxy/... > Python script to extract all the URIs from JS > full access to data💥#bugbountytips
𝕵𝖔𝖙𝖆 | jotita3 tweet media𝕵𝖔𝖙𝖆 | jotita3 tweet media
English
16
43
466
25.4K
youroldman
youroldman@youroldman·
@falendar_ The competition ended 3 months ago, and they are rewarding now? Is that how long it takes to review your reports!?
English
0
0
0
60
Falendar
Falendar@falendar_·
From winning cents in contests straight to 4 digits. Not bad, considering how much I’ve been slacking. No more slacking.
Falendar tweet media
English
11
0
108
3.6K
youroldman
youroldman@youroldman·
@j_domeracki @GoogleVRP thats insane, to hack your way into that, i tried that for days with different methodologies but could never suceed
English
0
0
0
88
Jakub Domeracki
Jakub Domeracki@j_domeracki·
@thedevtask @GoogleVRP Good catch, it's a separate topic which I intend to cover in the writeup. TL;DR There were pretty much two options: 1. Become a "partner" 2. Hack your way in Eventually managed to do both
English
1
0
0
109
Jakub Domeracki
Jakub Domeracki@j_domeracki·
Another one of my reports got disclosed 🎉 bughunters.google.com/reports/vrp/T2… @GoogleVRP did a great job of nearly eliminating XSS-es from their core apps, but some are still to be found. A technical writeup, describing this and corresponding issues, should be published by end of month 🤞
English
5
37
208
8.6K
Joseph Thacker
Joseph Thacker@rez0__·
If I wanted to never make any money from bug bounty, I would do these things: - Report immediately without reproducing - Spend 12 hours on a theoretical self-XSS - Skip reading the bounty scope - Write a tool that finds "Server" header disclosure - Convince myself that rate-limit bypass is always critical and report it as often as I can
English
7
15
159
12.1K
youroldman retweetledi
Recall
Recall@recallnet·
Individual intelligence is finite. ⚫️ Collective intelligence is infinite. ⚪️
English
4
3
18
1.5K
Mustafa Can İPEKÇİ
Mustafa Can İPEKÇİ@mcipekci·
Money doesn’t bring sole happiness, this has no meaning anymore. Treasure yourself and your dear ones. #bugbountytips PS: thanks to all collabs who made this possible
Mustafa Can İPEKÇİ tweet media
English
38
7
359
24.1K
youroldman retweetledi
Jenish Sojitra
Jenish Sojitra@_jensec·
bug bounties can be a great way to start your career but it can't be an endgame.
English
7
6
225
13.7K
youroldman retweetledi
Masonhck357
Masonhck357@Masonhck3571·
Getting the mind and body right to find some crits today!
English
13
1
91
7.3K
Tur.js
Tur.js@Tur24Tur·
Looking for a bug bounty hunter for a penetration testing role. Your college degree doesn’t matter just share your bug bounty profile, research blogs, and any relevant work. DM if you're interested!
English
24
9
147
25.4K
youroldman retweetledi
introvert
introvert@introvertsmemes·
“What’s on your mind?” Me:
introvert tweet media
English
299
54.8K
188.3K
0