Hx01

580 posts

Hx01 banner
Hx01

Hx01

@Hxzeroone

Not evil just misunderstood.

Alcatraz Prison,SF เข้าร่วม Ağustos 2017
153 กำลังติดตาม5.3K ผู้ติดตาม
ทวีตที่ปักหมุด
Hx01
Hx01@Hxzeroone·
LOOK MOM, I’M ON TV!!
bugcrowd@Bugcrowd

Last year, @Hxzeroone challenged himself to earn $100k in bounties by his 18th birthday. We sat down with him to talk about his Bug Bounty Journey, tips for staying motivated, and hitting his next Bugcrowd milestone! 🎉 bugcrowd.com/blog/researche…

English
9
5
152
0
Hx01
Hx01@Hxzeroone·
@ldionmarcil @sml555_ @codecancare Yes , we had reported issues to such platforms and got them fixed where their connectors and recipes were directly vulnerable.
English
0
0
1
55
Louis Dion-Marcil
Louis Dion-Marcil@ldionmarcil·
@Hxzeroone @sml555_ @codecancare or is the issue here that those automation frameworks (Zapier, Workato, Make) somehow make Sheets evaluate the CSV formulas prior to the user opening the sheet and granting access? were you able to reproduce this directly, ie with a trial on these services?
English
1
0
0
56
Hx01
Hx01@Hxzeroone·
This has been a recent implementation in Google sheets prior to that there wasn’t any warning , it would auto-run once they were implemented. Also to be noted , if the formulaes are allowed once ,they are not asked to be accepted again meaning an sheet that has previously added their own formuales and is ingesting data from attacker supplied sources would still be vulnerable. Apart from that the same can be achieved on Microsoft Excel.
English
0
0
0
69
Louis Dion-Marcil
Louis Dion-Marcil@ldionmarcil·
@Hxzeroone @sml555_ @codecancare I can't reproduce this in Google Sheets, getting a pop-up: "Warning: Some formulas are trying to send and receive data from external parties." Doesn't successful exploitation imply someone manually allowed access, justifying the "social engineering" responses your team got?
Louis Dion-Marcil tweet media
English
2
0
1
91
Roy Davis
Roy Davis@Hack_All_Things·
Peace out world. Best wishes to all. ALS has won this battle, but hopefully not the war!
Roy Davis tweet media
English
131
59
1.6K
146.7K
Bee 🐝
Bee 🐝@securibee·
After 3 years of writing the Hive Five newsletter 36 months of thoughtful curation 155 Sundays of focused work 12277 links shared It's time...
English
2
18
63
31.7K
Ali Tütüncü
Ali Tütüncü@alicanact60·
Just participated in a live hacking event with @Hacker0x01 in London🇬🇧! This is my first LHE with HackerOne! Proud to finish 3rd on the @Zoom leaderboard and 4th overall. Feeling thrilled and accomplished! #h14420 #bugbounty
Ali Tütüncü tweet mediaAli Tütüncü tweet mediaAli Tütüncü tweet media
English
33
0
281
42.2K
Mustafa Can İPEKÇİ
Mustafa Can İPEKÇİ@mcipekci·
I'm proud to announce that with today's payouts I hit 1M$ all time earning combined from all platforms and external programs I participated. 3/4 of these earnings coming from @SynackRedTeam and rest on @Bugcrowd, @Hacker0x01 and some good external programs :). #BugBounty
English
50
18
382
33.1K
Luke Stephens (hakluke)
Luke Stephens (hakluke)@hakluke·
@rez0__ It looks good to me! I'll defer to the OAuth master @Hxzeroone for the final opinion though. I think the last arrow should go all the way to the user.
English
2
1
3
1.2K
Hx01
Hx01@Hxzeroone·
Since we are acknowledging the great relationships we’ve formed in bug-bounties i’d also like to thank the friends ive formed along the way @infosec_au @codecancare @HusseiN98D @sw33tLie @ITSecurityguard @m0chan98 @0xd0m7 @bsysop @d00xing @sml555_ @RelentlessT7
shubs@infosec_au

i’ve been able to achieve great things through teamwork and greatly respect the following people @rhyselsmore, @HusseiN98D, @fransrosen, @Hxzeroone, @codecancare, @seanyeoh, @samwcyo. We’ve had a lot of fun together, the bounties don’t even matter at some point.

English
8
2
41
12.5K
shubs
shubs@infosec_au·
when i find someone i enjoy collaborating with in bug bounties, we build a relationship that lasts a lifetime. i deeply appreciate all the people that i’ve had the chance to work with positively. although there are many people i actively avoid working with now.
English
2
1
132
21.4K
Hussein Daher
Hussein Daher@HusseiN98D·
Tag a hacker that you're grateful to, and always look up to in your journey.. We're all humans after all, show some recognition to those you love! ❤️‍🩹 I'll start..
English
171
44
381
0
MRD7
MRD7@_mrd7_·
@thedawgyg "Storm Area 51" --> This event in 2019 comes to my mind. @Hxzeroone Are you planning to raid Area 51 again?
GIF
English
2
0
2
0
dawgyg - WoH
dawgyg - WoH@thedawgyg·
I wanna debate aliens with someone.. who follows me and doesn't believe in aliens and wants to debate/discuss it? it still amazes me that theres so many people today that dont believe in aliens. #Aliens #Area51
English
42
0
75
0
Hx01 รีทวีตแล้ว
Hussein Daher
Hussein Daher@HusseiN98D·
I and @Hxzeroone somehow broke the internet this week. A total of approximately 200 reports sent so far across #Bugbounty platforms for this 0day. All the giants are affected. I mean it.
English
18
16
277
0
Hx01 รีทวีตแล้ว
Hussein Daher
Hussein Daher@HusseiN98D·
It's finally live - I'm sorry for the time this took! The workshop I gave at @THREAT_CON is now live on Udemy for a discounted price. The price will go back to $149 at the end of the week . More details to follow. udemy.com/course/bug-bou…
Hussein Daher tweet media
English
39
86
386
0
Hx01
Hx01@Hxzeroone·
🙏🏻
bugcrowd@Bugcrowd

Congrats @Hxzeroone for reaching an ambitious goal! 👏 With the amazing collaboration and efforts (not to mention memes 🔥) we saw in the #TeamHunt2021, we’re honored to be a part of this milestone! Great work! 😎

ART
1
1
28
0