DiMaX

456 posts

DiMaX

DiMaX

@dmxjon

Bug Bounty Hunter

Присоединился Aralık 2017
1.1K Подписки676 Подписчики
DiMaX
DiMaX@dmxjon·
@Kle0z Congratulations, how many awards were given for this?
English
1
0
0
75
Kle0z
Kle0z@Kle0z·
Finally confirmed!
Kle0z tweet media
English
1
0
9
13.5K
DiMaX
DiMaX@dmxjon·
@Shabosec @lostsec_ Congratulations, can you share what self-hosted bbp is?
English
0
0
0
17
DiMaX
DiMaX@dmxjon·
@sysdig Hello, Do you have a Bug Bounty program? If so, could you please share the details on how to report findings?
English
0
0
0
37
Sysdig
Sysdig@sysdig·
Are security teams hitting the limits of what humans alone can handle in the cloud? The data points to yes. Read the report to see what’s changing and what it means for how you defend the cloud: okt.to/ZyD2sf
English
1
1
7
238
DiMaX
DiMaX@dmxjon·
@Mar0_0uane You can try reporting it, maybe they will accept it.
English
1
0
4
3.2K
Marouane Mouhtadi
Marouane Mouhtadi@Mar0_0uane·
Does anyone know if this domain is in scope for Anthropic’s private program on HackerOne? (I’m not a participant.)
Marouane Mouhtadi tweet media
English
9
1
252
35.3K
DiMaX
DiMaX@dmxjon·
@ma1fan This happened to me too, at a major Chinese crypto exchange. I had a leak of AWS keys, which can be used to change the code of any JavaScript file the exchange has. They rewarded me with $800 for it. 🤦‍♂️
English
0
0
6
1.2K
Nolan | Exvul
Nolan | Exvul@ma1fan·
I reported a critical vulnerability to a top-tier crypto exchange—an exploit that could allow an attacker to crack and steal wallet private keys within minutes. By all industry standards, this was a severe, high-impact bug. Yet, they initially offered me a measly $4,000 bounty. I refused to accept it and pushed back hard. After a prolonged back-and-forth, they spent ages escalating it to their leadership. Following endless rounds of "approvals," they finally added a whopping $1,000 to the offer, bringing the grand total to $5,000. I am honestly "moved to tears" by their generosity, considering an exploit of this magnitude is easily worth at least $50,000. Seriously, my advice is to avoid participating in Bug Bounty programs run by certain Chinese teams. It seems they would much rather risk getting drained for tens or hundreds of millions of dollars by actual hackers than pay a white hat a single extra cent for protecting them.
English
48
19
328
40K
DiMaX
DiMaX@dmxjon·
@sysdig Hello, Do you have a Bug Bounty program? If so, could you please share the details on how to report findings?
English
0
0
0
36
Sysdig
Sysdig@sysdig·
The good news? ✨ Security teams can see more risk than ever. The bad news? ⛔ Risk doesn’t go away until something gets fixed. Start delivering security outcomes today: okt.to/CrzHEy
Sysdig tweet media
English
1
1
5
148
itsabinashb
itsabinashb@itsabinashb·
Yesterday I tried @hakiraio 's AI agent on a bounty in @HackenProof platform. It handed me a critical & a low severity bug. Best thing is I cross tested the same with opus 4.6 and it also verified it. Outstanding work by @hakiraio team.
English
2
3
25
2.5K
DiMaX
DiMaX@dmxjon·
@Ehsan1579 Congratulations! Can you honestly tell us if you use any kind of AI or if you find vulnerabilities completely manually?
English
0
0
0
46
DiMaX
DiMaX@dmxjon·
@BugBunny_ai Hello, can you check your DM?
English
0
0
1
84
DiMaX
DiMaX@dmxjon·
@7urb01 Can you share which prompt we should use to get the best result from claude code?
English
1
0
1
61
DiMaX
DiMaX@dmxjon·
@rez0__ @ZackKorman Does NVIDIA have a private BBP? What platform is it on?
English
0
0
0
35
Joseph Thacker
Joseph Thacker@rez0__·
@ZackKorman you should submit to their vdp and then get invites to their private programs so you can make some cash off your efforts
English
2
0
19
2.4K
Zack Korman
Zack Korman@ZackKorman·
NVIDIA Nemoclaw's security is worse than I expected. The AI can modify its own config to bypass security controls. I asked it to accept websocket connections from any origin and change its token to something trivial (123). Now any site I visit can give instructions to my bot.
Zack Korman tweet media
English
57
84
617
65.6K
DiMaX
DiMaX@dmxjon·
@rez0__ You always say that, but tell us what prompt should we use so that Claude Code actually finds at least some bug in the source code or do you use your reports from Hackerone as skills for Claude Code?
English
1
0
0
314
oxship
oxship@oxxxssh·
First 4 digits payout on @intigriti
oxship tweet media
English
5
3
125
3.2K
archethect 🏴
archethect 🏴@archethect·
Devil's Advocate protocol on sc-auditor V2 is working so well 🔥 Reached an impressive 90% True Positive rate on a benchmarked contest by @pashov and @0xiehnnkta with 16 true positives on 18 total finds. Full numbers, comparison and release of sc-auditor V2 tomorrow 🕵️
English
1
0
3
199