VC0D3R

1.6K posts

VC0D3R banner
VC0D3R

VC0D3R

@VC0D3R

Full Stack Web Developer & Bug Hunter

root เข้าร่วม Aralık 2020
1.5K กำลังติดตาม1.6K ผู้ติดตาม
VC0D3R รีทวีตแล้ว
AmirMohammad Safari
AmirMohammad Safari@AmirMSafari·
Is there any chance for CSRF? 🤔 Test it out live at: pwnbox.xyz
AmirMohammad Safari tweet media
English
2
7
69
22.9K
VC0D3R รีทวีตแล้ว
Critical Thinking - Bug Bounty Podcast
New research just dropped by @alien2exe on hijacking OAuth popups via predictable window. open() targets. The chain uses iframe name collision forcing the auth flow into a controlled context, eventually linking an attacker-controlled addon to leak workspace PII and config data lab.ctbb.show/research/can-a…
English
0
31
132
6.5K
VC0D3R รีทวีตแล้ว
Jenish Sojitra
Jenish Sojitra@_jensec·
An empty `X-Forwarded-For` header causes internal Pod/server IPs to be disclosed in the response header or body, which can then be targeted for SSRF.
English
6
29
348
16.1K
VC0D3R รีทวีตแล้ว
sebsrt
sebsrt@s3bsrt·
I’ve been digging into HTTP Trailers and found some new smuggling techniques: sebsrt.xyz/blog/trailing-…
English
4
104
406
40.3K
VC0D3R รีทวีตแล้ว
André Baptista
André Baptista@0xacb·
GraphQL Introspection Bypass via Field Suggestions Even with introspection disabled, GraphQL APIs leak schema information through error messages. When introspection returns errors, exploit the suggestion feature: > Send queries with intentional typos > GraphQL suggests similar field names in error responses > Tools like Clairvoyance can automate schema reconstruction > Build a complete schema map from suggestions alone Source👇 assetnote.io/resources/rese…
English
1
35
205
7.5K
Immunefi
Immunefi@immunefi·
Security researcher ily2 has just earned a staggering $3,000,000 from submitting a critical smart contract bug via Immunefi. That's the largest single payout in web3 security in recent memory. In total, he's submitted 3 reports. All 3 were paid. 100% accuracy. His leaderboard update is coming soon, but you can pledge IMU to him now and earn when he finds the next one: immunefi.com/pledge/ily2
Immunefi tweet media
English
194
152
1.2K
341.4K
0xCharlesDCheerful
0xCharlesDCheerful@carlos__alegre·
@immunefi Im waiting for someone to post the: "ily2 was my AI agent" post
English
6
1
50
6.4K
Harley Kimball
Harley Kimball@infinitelogins·
I analyze thousands of bug bounty content items every month. Less than 5% makes it to the newsletter. I distilled those curated selections down to the top 25 resources for 2026 and put them in this PDF. It includes the top platforms, tools, and people that consistently deliver high signal content. Comment RESOURCES and I'll DM you the PDF for free. (Make sure your DMs are open) #BugBounty
Harley Kimball tweet media
English
339
28
286
19.9K
VC0D3R รีทวีตแล้ว
Google VRP (Google Bug Hunters)
🔒 Want to move beyond passwords? Check out this beginner's guide to Cross-Device Passkeys! Learn how "Hybrid transport" uses QR codes and Bluetooth to let you sign in securely on any device – even public ones – without ever sharing your private keys. bughunters.google.com/blog/passkeys
English
1
17
78
6.4K
AmirMohammad Safari
AmirMohammad Safari@AmirMSafari·
I recently discovered several vulnerabilities in MCP servers across different attack scenarios (DOM XSS, Stored XSS, SSRF, etc.) and decided to publish a blog post to share my knowledge. Hope you enjoy it! :D blog.voorivex.team/shaking-the-mc…
AmirMohammad Safari tweet media
English
10
38
232
14.3K
VC0D3R
VC0D3R@VC0D3R·
@Teeegra شت😐😐😐
العربية
0
0
0
721
nader abdi
nader abdi@AtaTurk1925·
Testing a single App version is blind recon. Full coverage requires reviewing all versions to track newly added, removed, or modified endpoints across releases. Most critical mobile bugs live between versions not in the latest one.
nader abdi tweet media
English
14
4
144
6.1K
YS
YS@YShahinzadeh·
after a long discussion on a report, I managed to convince the program that the bug is High and they issued a bonus on top of the bounty. they'd mistakenly considered PR as High because the victim needed to be authenticated when opening my link, this actually affects AC not PR :)
YS tweet media
English
7
1
210
7.9K
VC0D3R รีทวีตแล้ว
Kirill Firsov
Kirill Firsov@k_firsov·
Our latest research is out! If you missed a good write-up for nice vulnerabilities, I brought you one! Enjoy the reading! @FearsOff @Cloudflare
Kirill Firsov tweet media
English
10
105
501
136.7K
VC0D3R รีทวีตแล้ว
Hamid Kashfi
Hamid Kashfi@hkashfi·
این دامنه و وب سایت رو ثبت و راه اندازی کردم بعنوان راهنمای امنیت سایبری اولیه، ساده و قابل استفاده برای عموم. محتوا و قالب اصلی سایت کار من نیست و فقط ترجمه و قالب فارسی رو اضافه و درست کردم. amni.at محتوای فنی، بخصوص متناسب با شرایط و نیاز کاربر ایرانی، هنوز جای کار و تکمیل شدن داره که به مرور انجامش میدم. پیشنهادی هم اگر دارید برای تکمیل و اصلا محتوا، میتونید از طریق مخزن گیت هاب پروژه ارسال کنید :)
فارسی
10
36
200
25.3K
VC0D3R รีทวีตแล้ว
PortSwigger Research
PortSwigger Research@PortSwiggerRes·
Nominations for the Top 10 (new) Web Hacking Techniques of 2025 are now live! Review the submissions & make your own nominations here: portswigger.net/research/top-1…
English
0
38
120
36.4K
VC0D3R รีทวีตแล้ว
Jenish Sojitra
Jenish Sojitra@_jensec·
Sharing my Burp Extension that earned me $200k in 2025 while API testing heavy JS-rich targets. github.com/jenish-sojitra… The tool helps find endpoints, files, internal emails, and some secrets from minified JS. Its goal is to achieve maximum efficiency with reduced noise in results. Contributions and feedbacks are welcome.
Jenish Sojitra tweet media
English
39
409
2.3K
125.5K