Couple of weeks without finding a bug and I feel like I've forgotten everything I once knew. I need some #bugbountytips and some bug bounty courses ASAP.
"Execute After Redirect" vulnerabilities occurs when a server fails to halt execution after issuing a redirect to the client. This can lead to serious security flaws if developers rely on redirects without implementing proper access control on the content served post-redirect. I…
Absolutely dominated by @carbonmanx this Synack Red Team recognition period. Congrats on hitting TITAN, and absolutely steam rolling the UK leaderboard! #LegendInTheMaking
🎉I’m excited to announce that I’ll be presenting my talk “𝐔𝐩 𝐚𝐧𝐝 𝐃𝐨𝐰𝐧 𝐓𝐞𝐜𝐡𝐧𝐢𝐪𝐮𝐞: 𝐄𝐱𝐩𝐨𝐬𝐢𝐧𝐠 𝐇𝐢𝐝𝐝𝐞𝐧 𝐃𝐚𝐭𝐚 𝐟𝐫𝐨𝐦 𝐑𝐀𝐆 𝐒𝐲𝐬𝐭𝐞𝐦𝐬” at @_leHACK_ in Paris, France at the end of June.
In this talk, I’ll demonstrate a technique I discovered…
🎉I’m excited to announce that I’ll be presenting my talk “𝐔𝐩 𝐚𝐧𝐝 𝐃𝐨𝐰𝐧 𝐓𝐞𝐜𝐡𝐧𝐢𝐪𝐮𝐞: 𝐄𝐱𝐩𝐨𝐬𝐢𝐧𝐠 𝐇𝐢𝐝𝐝𝐞𝐧 𝐃𝐚𝐭𝐚 𝐟𝐫𝐨𝐦 𝐑𝐀𝐆 𝐒𝐲𝐬𝐭𝐞𝐦𝐬” at @_leHACK_ in Paris, France at the end of June.
In this talk, I’ll demonstrate a technique I discovered…
It's the first time I've seen triager react poorly to a researcher complaining on X with a DM. I can imagine it does get a bit upsetting after a while. An interesting situation for @Bugcrowd to deal with. If the other way round, I am sure a researcher would be penalised.
After a lot of sweat and efforts, the Barracks Corp WarZone is live.
I’ve always found the worst kind of vulns in an internal portal. Just like the Social WarZone, this one also contains realistic vulns from my own reports.
Hope you all love this <3
After a lot of sweat and efforts, the Barracks Corp WarZone is live.
I’ve always found the worst kind of vulns in an internal portal. Just like the Social WarZone, this one also contains realistic vulns from my own reports.
Hope you all love this <3
💭 It all started during an assessment of a web application. In the latest Exploits Explained, Synack Red Team member "nerrorsec" recounts the discovery of a DOM-based XSS vulnerability that was patched…and then found in another product from the same company a year later.…
👀 Synack Red Team member Busra (@turakbusra) walks us through her discovery of an access control violation vulnerability that led to account takeover. Follow along → hubs.ly/Q03fZ7fR0
It's always nice to find SQLi with @SynackRedTeam as the triage and pay out is fast. It's even better when the bounties are paid at treble what they normally are. Check out the 300% targets!
🚨CVE ALERT!
While working with Nuclei @wiz_io, I discovered CVE-2024-43405, a vulnerability that bypasses template signature verification, potentially allowing malicious code execution on machines running Nuclei 🛡️
Here’s what you need to know: 🧵
📢 Call for Papers!
Got a great idea? We want to hear it! Check out our tips to help your talk shine—whether you're a pro or a first-timer.
Submit your talk by 30th Jan 2025 and join us for the first-ever BSides Birmingham on 3/5/25
#BSidesBirmingham#CallForPapers#CyberSecurity
Synack Red Team has no year wrapped to share, but... $ target achieved and then some. No more $ targets as it's a bit much with young kids and a job! Highlights of the year: meeting fellow hackers at the UK SRT meetups and witnessing epic SRT Slack meltdowns. #SynackRedTeam
I just published my latest article on a recent finding at @SynackRedTeam :
From Template to Threat: Exploiting FreeMarker SSTI for Remote Code Execution!
Don’t hesitate to reach out if you have any questions!
blogs.sayaan.in/freemarkerssti#BugBounty
2K Followers 833 FollowingSecurity Stuff @ Microsoft || Red Team Operator || Founder @ https://t.co/skjEVTiYF8 || BB/SRT @ Synack Red Team || Opinions and tweets are my own
6 Followers 174 FollowingRecruiting webshell engineers to penetrate websites, with a monthly salary of up to $100,000. If interested, please contact https://t.co/Ak39WRcPM8
144K Followers 456 FollowingWe are the National Cyber Security Centre – part of the UK’s intelligence & cyber agency @GCHQ. We help to make the UK the safest place to live and work online.
504 Followers 474 Following#BestBall Degenerate - Running Drafts for Best Ball Europe - @pointsoverDfs - Projections & all things fantasy for #FanTeam & #GameDay.app
247K Followers 3K FollowingPentester, Forensic investigator, and former college professor. Trained hackers at every branch of US military and intelligence.
Visit me at https://t.co/G478wufszw
37K Followers 125 FollowingDetect real, exploitable vulnerabilities. Harness the power of Nuclei for fast and accurate findings without false positives.
2K Followers 10 FollowingSmall team building powerful AI offensive security tools that help pentesters score more vulnerabilities!
Try live demo ➡️ https://t.co/hAYMMC8dxT
20K Followers 271 FollowingOffensive security company. Dojo of many ninjas. Red teaming, reverse engineering, vuln research, dev of security tools and incident response.
1K Followers 228 FollowingNothing, just a noob and trying to learn new things🙂
Bug Bounty Hunter🪲|Synack Red Team Member| Rank #2 on https://t.co/zE76rcPoOi
9K Followers 969 FollowingOffensive Security Researcher, Pentester, Red Teamer and Bug Bounty Hunter | SRT Hero at @Synack Red Team | Hackerone - sayaanalam