Tabahi

273 posts

Tabahi banner
Tabahi

Tabahi

@_tabahi

high and hacking! writeups @witcoat !

เข้าร่วม Ocak 2017
151 กำลังติดตาม5.8K ผู้ติดตาม
ทวีตที่ปักหมุด
Tabahi
Tabahi@_tabahi·
got 3 bugs rewarded on @Hacker0x01 ∑ $47500 We Out Here
Tabahi tweet mediaTabahi tweet media
English
27
23
709
59.9K
Tabahi
Tabahi@_tabahi·
@al_f4lc0n @immunefi I don’t understand why all these protocols keep pulling these dumb tricks with white hats. Looks like they don’t want to be saved, they want to be ripped off.
English
0
1
1
32
f4lc0n
f4lc0n@al_f4lc0n·
I Saved Injective's $500M. They Pay Me $50K. I like hunting bugs on @immunefi . I'm decent at it. - #1 — Attackathon | Stacks - #2 — Attackathon | Stacks II - #1 — Attackathon | XRPL Lending Protocol - 1 Critical and 1 High from bug bounties (not counting this one) Life was good. Then I found a Critical vulnerability in @injective . This vulnerability allowed any user to directly drain any account on the chain. No special permissions needed. Over $500M in on-chain assets were at risk. I reported it through Immunefi. The next day, a mainnet upgrade to fix the bug went to governance vote. The Injective team clearly understood the severity. Then — silence. For 3 months. No follow up. No technical discussion. Nothing. A few days ago, they notified me of their decision: $50K. The maximum payout for a Critical vulnerability in their bug bounty program is $500K. I disputed it. Silence again. No explanation for the reduced payout. No explanation for the 3 month ghost. No conversation at all. To be clear: the $50K has not been paid either. I've seen others share bad experiences with bug bounty payouts recently. I never thought it would happen to me. I can't force them to do the right thing. But I won't let this be forgotten. I will dedicate 10% of all my future bug bounty earnings to making sure this story stays visible — until Injective pays what I deserve. Full Technical Report: github.com/injective-wall…
English
519
528
4.5K
1.8M
Tabahi
Tabahi@_tabahi·
@Apple in the center, LG ultra wide on the right, BenQ
English
0
0
0
40
Tabahi
Tabahi@_tabahi·
My @Apple MacBook is a Beast. What’s your configuration?
Tabahi tweet mediaTabahi tweet mediaTabahi tweet mediaTabahi tweet media
English
5
0
11
1.2K
Tabahi
Tabahi@_tabahi·
I have 3 submissions on @Tripadvisor program on @Bugcrowd triaged since months. Raised multiple response to requests on them. I think they should have been paid out by now. It’s way beyond the report’s estimated date.
Tabahi tweet mediaTabahi tweet mediaTabahi tweet media
English
7
0
56
4.3K
Tabahi
Tabahi@_tabahi·
@PulkitJangid18 @Tripadvisor @Bugcrowd I mostly get paid on triage, or some days after. All reports have an estimated date. Here, Months have passed by after the triage, no bounty yet. So much wait time degrades the motivation.
English
1
0
1
210
Tabahi
Tabahi@_tabahi·
@elonmusk Would it let me send my Humanoid to moon ?
English
0
0
0
251
Elon Musk
Elon Musk@elonmusk·
SpaceX will build a system that allows anyone to travel to Moon. This will so insanely cool 🚀💫🤩
English
21.9K
12.5K
148.2K
76.8M
Elon Musk
Elon Musk@elonmusk·
𝕏 is the set of all things
English
10.7K
8.9K
135.3K
45.6M
Déborah
Déborah@dvorahfr·
Life can be a field of roses or a field of thorns, but life is beautiful. Grok Imagine
English
114
149
1.2K
173.7K
Tabahi
Tabahi@_tabahi·
CVE 2025-55182 & CVE 2025-66478 , Unauthenticated Remote code execution in react server components. An attacker could craft requests that trigger unintended server execution paths. Applications using React Server Components with the App Router are affected when running: •Next.js 15.x •Next.js 16.x •Next.js 14.3.0-canary.77 and later canary releases React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 are affected. Patch Immediately 🚨
English
0
0
4
1.1K
Tabahi
Tabahi@_tabahi·
If this goes good and you can make mushrooms available for longevity and be able to ship it to India, I’m buying it
Bryan Johnson@bryan_johnson

I’m taking magic mushrooms and livestreaming it on sunday. + 6 hours Live + 10am PST, Sun 30th + 5.24 g mushrooms, dried + 28 mg of active psilocybin + Strain B+ (psilocybin cubensis) + 2nd dose (3 total across 3 months) We’re measuring 249 biomarkers to determine the effect on longevity. This is the most quantified psychedelic experiment in history. Guest appearances from: + @Grimezsz DJ'ing a Live set + @HamiltonMorris and @gjurvetson discuss psychedelics + @MrBeast @naval @Benioff @friedberg are being good friends and checking in on me during the experience Moderated by: goth girl @_katetolo and OG @ashleevance The science suggests psilocybin may be a longevity therapy: + Extended lifespan in mice + Preserved telomeres + Extended replicative lifespan in human cells + Reduced systemic inflammation markers + Promotes anti-inflammatory environment in the brain + Increases brain entropy + Breaks rigid brain patterns and increases creativity + Boosts long-term cognition and flexibility + Protects neurons and microglia + Reshapes gut microbiome for improved mental health + Improved sexual satisfaction in depressed people We’re measuring: + 249 independent biomarkers + 29 vials of blood + brain scans + urine, stool, saliva, fertility + multi-omics profiling: DNA, epigenetics, metabolism, hormones, microbiome, proteins, cognition + biological age: epigenetic, telomeres, brain Come watch me trip balls.

English
0
0
0
554
Tabahi
Tabahi@_tabahi·
Yo @NanoBanana, peep the scene in 2040 Delhi, feel me? Skies choked with flyin' autos, smog thicker than envy, Hover-rickshaws poppin' wheelies, traffic still movin' deadly, Chai bots slingin' masala lattes, drones droppin' butter chicken heavy, Billion dreams stacked in towers touchin' heaven, Ganges glowin' neon, not ready— 2040 Dilli still chaotic, still magic, still flexin' on the globe, deadly!
Snowdrop@Snowdropshadow

Hey @NanoBanana pro can you imagine Delhi,India in the year 2040

English
0
0
1
585