On July 25, we hacked OpenAI.
Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc.
We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵
"$250,000+" - Quarter million dollars. One program.
Here's what nobody tells you.
Here's the full breakdown from my @Atlassian journey on @Bugcrowd:
~ 400 reports submitted:
~ 240 paid reports
~ 80 duplicates
~ 70 N/A
Every duplicate and N/A was a lesson, not a loss.
No automation. No recon tools. Just deep manual research, consistency, and an obsession with understanding how Atlassian products work at their core.
Atlassian runs one of the most professional and well-managed bug bounty programs out there. A huge shoutout to their security team for taking every report seriously. and a special thanks to Mike for building a company that genuinely invests in security.
What made the difference?
→ I stopped hunting broad, started going deep
→ I treated Atlassian attack surface like a full-time research project
→ I documented everything, even the rejections
→ I came back to closed reports and found bypasses
One program. One mindset. $250K+.
The specialization strategy wins every time.
#BugBounty #InfoSec
It’s time to lock in. If you’re struggling with bug bounties, spend the next few weeks finding a target you personally enjoy. Bigger the scope the better! Then focus on them everyday for the entire year. Aim to hack 2-3 hours minimum a day. You’ll learn lots and find bugs.
GL!
Thread about hunting on the main application 🧵
1. Check the login process
- Do they allow signup with email or Google etc
- Do they allow you to signup with the @company email
- what is the content-type of the signup/login page
- when you enter valid cred, on which page you
- Being honest with myself: the last 43 days weren’t executed the way I planned.
- Too much learning, too little real hunting.
- Exams are finished and went very well.
- Illness and poor execution slowed things down — noted and accepted.
#BugBounty#100DaysOfHacking
43/100 — #HuntingArc ⭕
🥷 Hunting → 0h
📑 CyberStudy → 2h
✅ Good Habits → 7/8
Quick update: pausing hunting and cyber study for a few days due to exams. Not stopping just shifting focus temporarily. if I get any gap time, I’ll try to hunt in between.
36/100 — #HuntingArc ⭕
🥷 Hunting → 0h
📑 CyberStudy → 7h
✅ Good Habits → 7/10
- For the last tow days i am refining my techniques and methodology Reading & watching lots of resources
#BugBounty#infosec