What would I do if I wanted to become a terrible, inefficient #bugbounty hunter?
1. I'd try to learn everything about every feature and every bug type at once.
2. I'd chase every low hanging fruit, regardless of impact.
3. I'd ignore high impact bugs bcz they seem hard.
i get asked all the time how to be an ai hacker.
go read my "how to hack ai apps" post then just read and understand every post on embracethered[.]com by @wunderwuzzi23 and you will be an expert AI hacker.
im not joking. it's that simple. links below.
Thanks @PortSwigger and @BugBountyDEFCON for this awesome event — and also to my @d3vc0r3 buddies for standing on stage to collect the trophy for me!
A little follow-up article on this research is coming soon... stay tuned! 🤘
You may have seen @Google paid out an incredible $250,000 #BugBounty for a Chromium issue. However a lot of people seem confused by the available discussion thread. So I made a nice easy to understand video explaining what the issue is and why it matters.
youtu.be/zN9c8jTo1cg
We keep adding new tools and all of them can be used for free !
Subdomain enumeration, IP history, reverse IP lookup and many others.
Start exploring data now at profundis.io.
I'm happy to release a script gadgets wiki inspired by the work of @slekies, @kkotowicz, and @sirdarckcat in their Black Hat USA 2017 talk! 🔥
The goal is to provide quick access to gadgets that help bypass HTML sanitizers and CSPs 👇
gmsgadget.com
1/4
Avoiding mobile apps in your bug bounty hunts?
You’re leaving high-value vulnerabilities on the table.
This blog provided the tools and tactics you need to target iOS and Android apps 👇
bugcrowd.com/blog/mobile-ha…
Same payload, 3 different browsers: #Chrome, #Edge, #Firefox. So don’t just test using your default browser, make sure to test on every browser you have 😉
Payload: `%3cimg%2fsrc%2fonerror%3dalert%2f%2f%26NewLine%3b(2)%3e` #BugBounty
2K Followers 833 FollowingSecurity Stuff @ Microsoft || Red Team Operator || Founder @ https://t.co/skjEVTiYF8 || BB/SRT @ Synack Red Team || Opinions and tweets are my own
501 Followers 7K FollowingGhanaian orgin, Freelance C++ fixed income developer. Founder of GeorgeTown Analytics, using Erlang and Esper for messaging and Nosql. Web isolation
9K Followers 969 FollowingOffensive Security Researcher, Pentester, Red Teamer and Bug Bounty Hunter | SRT Hero at @Synack Red Team | Hackerone - sayaanalam
680 Followers 0 FollowingMapping the internet - turning DNS/host data into intel for sec teams, OSINT & bug-bounty hunters. Automated recon & real-time alerts.
10K Followers 6 FollowingBringing AI to offensive security by autonomously finding and exploiting web vulnerabilities. Watch XBOW hack things: https://t.co/D5Mco1u8zM
3K Followers 203 FollowingSecurity Engineer at big tech | Part Time Security Researcher | Build Pipeline Menace | All thoughts and opinions are my own.
69K Followers 92 FollowingFounder - Septemberish & r/developersIndia
Design + Branding + Development
Support my work - https://t.co/FYm4f9RTfu
https://t.co/RSZmB7qEkn
4K Followers 228 FollowingTop 90 on https://t.co/FjfGmQxi75 || https://t.co/pPR9UWROQt || Just a Teenage Hacker Spirit || Full Time Bug Hunter since July 2023 || No_DMs
9K Followers 1K Following📍 @yeswehack (aka Hisxo) - I love to break things (and I'm paid for that) - Bug Hunter
🔗 Check my Github repository https://t.co/Sj3prhiZyu
#BugBounty