zbcrypt

24 posts

zbcrypt banner
zbcrypt

zbcrypt

@zbcrypt

react, ts, py & hacking

Katılım Ekim 2022
76 Takip Edilen5 Takipçiler
zbcrypt
zbcrypt@zbcrypt·
@BgmiKaam41919 @zack0x01 I'm curious too because if you think about it nothing really is wrong on the surface because just like passwords its on the user responsibility to protect his QR code for authentication, no?
English
0
0
0
8
adityasunny06
adityasunny06@adityasunny_06·
@zack0x01 Netflix also uses a similar Device Code flow. Was this rewarded because of Zero-Consent (automatic login on click) or a lack of IP/Network binding? Curious about the root cause.
English
1
0
0
120
john
john@anonymous02121·
@FightBell Haha idc what the kid did you don’t talk to them like that if you aren’t the father. If I was the kid I would have encouraged him to do something and then empty a clip on him when he tries 🤣 who’s yapping with blood coming up out your mouth
English
71
0
18
17.8K
FightBell🔔
FightBell🔔@FightBell·
bro absolutely had enough 😭
English
1.7K
2.1K
42.3K
2.9M
zbcrypt
zbcrypt@zbcrypt·
@AbhiX10010 i don't understand did your report get labeled as duplicate of your previous report?
English
0
0
0
10
zbcrypt
zbcrypt@zbcrypt·
@Bl4ckSec i submitted few of these uuid idors but only got informative they argued there is no way for an attacker to obtain the id
English
1
0
1
310
Black
Black@Bl4ckSec·
🔴 IDOR Vulnerability Missing validation of user's relationship with org_id. The system relies only on memoryId without verifying organization ownership. { "org_id": "152ace33-d28f-4c21-bb8a-0130fe64bb24", "memoryId": "9f3c2a41-7b8e-4d6a-a2f1-3e6c8d9b1a42" } Modify or delete other organizations' data by simply changing the memoryId. #BugBounty #bugbountytips #Hacking #infosec
Black tweet media
English
12
17
329
12K
zbcrypt
zbcrypt@zbcrypt·
I've been finding a lot of potential SSRF vulnerabilities recently but I couldn't find good impact, what is best writeup you know about SSRF? The usual exploits seem heavily protected now.
English
0
0
0
33
zbcrypt
zbcrypt@zbcrypt·
@Stephen_DJ_ @zack0x01 there are many github repositories that are regularly updated fetching bug bounty assets just search for them on github
English
1
0
0
59
secret
secret@Stephen_DJ_·
@zack0x01 Hi, could you give us the method to collect all subdomain from bug Bounty platforms, do we have any technique or method to get them all ?
English
1
0
1
1.1K
zbcrypt
zbcrypt@zbcrypt·
@zack0x01 your internet provider must really like you in able to flood your network like that
English
1
0
3
920
zbcrypt
zbcrypt@zbcrypt·
@mugh33ra I like that you used emoji to add impact to the title 😂
English
1
0
0
114
zbcrypt
zbcrypt@zbcrypt·
@roohaa_n i experienced the same on hackerone i found an idor then next day it was fixed, i even had video poc of the bug 😭
English
0
0
0
290
Rohan.exe 🖤
Rohan.exe 🖤@roohaa_n·
They fixed it internally but i just have burp logs as a proof will that work ? #BugBounty
Rohan.exe 🖤 tweet media
English
7
0
35
3.8K
Wahid Fayad
Wahid Fayad@0xcdn·
When your intense research pays off. Tip: ignore the noise, focus on yourself and skills, build the tool, update the tool, read, read, hack, update tool, hack, update tool, read, update tool, hack, report😀 Alhamdulillah
Wahid Fayad tweet media
English
2
4
90
3.6K
SoNaHRi
SoNaHRi@sonahri501·
bugcrowd triaged the bug as P1 and this program downgraded this to P4 and also took 2 months to reward it. this was worst experience on @Bugcrowd never working with them again
SoNaHRi tweet media
English
7
0
92
5.5K
zbcrypt
zbcrypt@zbcrypt·
@intigriti there are no easy bugs nowadays triagers wont accept a bug report that doesn't scream rce /s
English
0
0
0
101
Intigriti
Intigriti@intigriti·
What's the easiest vulnerability type to find in 2025? 👀
English
18
1
67
12.3K
FearBuck
FearBuck@FearedBuck·
Chinese company XPENG unveiled their female humanoid robot
English
713
270
3.9K
435.5K
zbcrypt
zbcrypt@zbcrypt·
@gabbytech01 good find keep it up, for those who doesn't know, sometimes servers performs extra protections by checking origin and referer value to block cors note that the headers are browser based protection only
English
0
0
2
634
thehelpdeskgirl 💻✨
thehelpdeskgirl 💻✨@thehelpdeskgirl·
hey. if you’re going through a lot, you should rest now so you can continue going through a lot tomorrow. follow my acct for more great tips.✨
English
11
4
123
2.7K