ทวีตที่ปักหมุด
XssFan
1.4K posts

XssFan รีทวีตแล้ว
XssFan รีทวีตแล้ว

For more info on how this class of bugs works check @Neodyme's blog
twitter.com/samczsun/statu…
#solana-account-confusions" target="_blank" rel="nofollow noopener">blog.neodyme.io/posts/solana_c…
samczsun@samczsun
tl;dr - Wormhole didn't properly validate all input accounts, which allowed the attacker to spoof guardian signatures and mint 120,000 ETH on Solana, of which they bridged 93,750 back to Ethereum.
English
XssFan รีทวีตแล้ว

THE U UP INTERVIEW SERIES featuring @samczsun as our first and very gracious guest is now LIVE.
We discuss: deep philosophy, like the phenomenology of bug hunting, and the secret behind his identity.
medium.com/immunefi/the-u…
English
XssFan รีทวีตแล้ว

Probably the best FREE interactive resource/courses for learning Solidity.
CryptoZombies is an interactive school that teaches you all things technical about blockchains, fundamentals of Solidity, web3.js.
cryptozombies.io
#blockchain #solidity

English
XssFan รีทวีตแล้ว

A comprehensive list of known attack vectors and common anti-patterns.
github.com/sigp/solidity-…
#solidity #defi #blockchain #ethereum

English
XssFan รีทวีตแล้ว
XssFan รีทวีตแล้ว

A curated list of blockchain security Capture the Flag (CTF) competitions
github.com/blockthreat/bl…
#blockchain #ethereum #solidity

English
XssFan รีทวีตแล้ว

3 months ago, I wrote my first smart contract
Today, I won the biggest web3 hackathon in Toronto and joined @musicoins as a blockchain developer 🚀
Here is my updated web3 developer roadmap
A mega thread 🧵
English
XssFan รีทวีตแล้ว

October was - by far - my best #BugBounty month ever! I made 160k USD from 40 bugs across @Hacker0x01 and @synack with almost zero automation involved.
I usually don't talk about my bounty income, but I'm quite proud of my work TBH 🙂 So here's a little bit of statistics. (1/3)
English
XssFan รีทวีตแล้ว
XssFan รีทวีตแล้ว
XssFan รีทวีตแล้ว

Misconfigured Reset password that leads to Account Takeover
by 'Aditya Sharma'
bounty: $5000
Aug 2021
@noob.assassin/5k-misconfigured-reset-password-that-leads-to-account-takeover-no-user-interaction-ato-e6a36b8ef183" target="_blank" rel="nofollow noopener">medium.com/@noob.assassin…
#AccountTakeover
#BugBounty #BugBountyTip #BugBountyTips
English
XssFan รีทวีตแล้ว
XssFan รีทวีตแล้ว

This blog post by @detectify is gold mine 🔥🔥
👉 10 Types of Web Vulnerabilities that are Often Missed
Thanks, @hakluke and @Farah_Hawaa
labs.detectify.com/2021/09/30/10-…
English
XssFan รีทวีตแล้ว
XssFan รีทวีตแล้ว

How to learn anything in computer science or cybersecurity effectively: betterprogramming.pub/5-steps-to-lea…
English
XssFan รีทวีตแล้ว

Write-up on how a Facebook bug could have exposed your email/phone number to your friends. Quick and easy.😉
Bounty: $18250
#BugBounty
iamsaugat.medium.com/a-facebook-bug…
English
XssFan รีทวีตแล้ว

New Module, Burp Suite! Learn this industry-standard tool for Web App Pentesting
🔴 Setup & Basics
🔴 Realistic hands-on labs
🔴 Repeater, Intruder, Extender, Modules
tryhackme.com/module/learn-b…
The first 2 rooms in this module are FREE!
💼 Part of our Jr Penetration Tester path

English




