Oceanwho

129 posts

Oceanwho banner
Oceanwho

Oceanwho

@RemonAdnan2

เข้าร่วม Eylül 2019
1.6K กำลังติดตาม132 ผู้ติดตาม
Oceanwho
Oceanwho@RemonAdnan2·
@_ctf platform name ?
English
1
0
0
56
_kheneh
_kheneh@_kheneh·
Just got my first paid bug on @Bugcrowd Privilege escalation via mass assignment. Tip: Always pay attention to the various ways the same action can be performed. #bugbounty
_kheneh tweet media
English
9
4
163
4.3K
Oceanwho รีทวีตแล้ว
Yunus Emre Öztaş
Yunus Emre Öztaş@ynsmroztas·
🚨 Neo4j Recon Tip: It’s worse than you think! 🚨 Finding default creds (neo4j:neo4j) isn't just a simple info leak. Typically, public accounts should be restricted to READ-ONLY. But during recon, I discovered that these accounts often hold full ADMINISTRATIVE & WRITE privileges. 🔥 An anonymous visitor can view data, but also modify, completely destroy the DB, or create persistent backdoors. Here is the Cypher payload to drop a new admin user: 👇 CALL dbms.security.createUser('ynsmroztas_test', 'P@ssw0rd123!', false) Game over. 💀🏴‍☠️ #bugbountytip #bugbountytips #InfoSec #recon @yeswehack
Yunus Emre Öztaş tweet media
English
3
9
159
8.1K
Oceanwho
Oceanwho@RemonAdnan2·
duplicates
Oceanwho tweet mediaOceanwho tweet media
Español
0
0
2
197
Oceanwho
Oceanwho@RemonAdnan2·
Finally reported SQLi
Oceanwho tweet media
English
0
0
3
194
dawgyg - WoH
dawgyg - WoH@thedawgyg·
This @Uber breach is insane. Appears to be a total compromise. Does #uber store our payment data? I know I have like 30 credit cards (most expired now since they wont let me remove them) saved on my account, could this attacker have had access to all user data?
English
14
40
294
0
Eslam Monex 🕵️🧑‍💻
Alhamdulillah, I was able to find a bug that allowed me to register as an admin on any customer panel of the company. I might write a full write-up later 🫶 #BugBounty
Eslam Monex 🕵️🧑‍💻 tweet media
English
4
0
89
3.7K
The XSS Rat - Proud XSS N00b :-)
1. Go to thexssrat.com 2. Pick a COURSE (not bundle) 3. Comment here 4. Share 5. Like At 200 likes, i will take the 3 most popular courses and give away 1000 seats each :-)
English
29
10
99
9.1K