I just published a new addon for Firefox/Burp.
If you use multiple accounts for your pentests, it will make your life way easier.
Check it out at https://t.co/rzTzrSiLGL
#bugbounty#burp#firefox
#ACCESSGRANTED - 😱 Objectif des 100 inscriptions atteint 🙏 Nous poussons donc les murs pour 20 dernières places ! Gratuit sur inscription : https://t.co/PGcexgfUXo
Il est encore possible de vous positionner sur une rump ➡️ [email protected]
Uncover unintended behaviors of HTML sanitizers with Dom-Explorer!
Try it here: https://t.co/cjVjuzw6O1
Shout out to @BitK_ and @yeswehack for this super helpful tool!
Watch this! 👇
@EdSec666@yeswehack Sadly I don't have a lot of time to work on this project right now, but check https://t.co/QD09nrxNyq, @sakiirsecurity came across the same issues and provided some fixes. I'll try to merge them when I can.
A new open-source tool from @BitK_ reveals how popular browsers parse HTML – simplifying the hunt for mutation XSS and opening up new horizons in security research 🔬 Read about this valuable addition to your 'Hacker's Toolbox' in our latest blog post 👇
https://t.co/rQyRdhseP5
The highlight of my @defcon experience this year was joining a panel at the @BugBountyDEFCON alongside industry leaders from @yeswehack, @synack, @Hacker0x01, and @intigriti. It was an honour to engage with such passionate and talented individuals.
Don't miss "Prototype pollution in depth, from beginner to 0-day hunter" by Lucas Philippe (@BitK_)! 📅 Friday, Aug 9 ⏰ 3:00 PM 📍 Bug Bounty Village Classroom, Room W215 #BugBounty#DEFCON
Got questions for top bug bounty leaders? Submit them here! We are excited to announce a panel at the Bug Bounty Village during @DEFCON 32 with leaders from @Hacker0x01, @YesWeHack, @intigriti, and @SynackRedTeam! Share your questions now: https://t.co/HnDDsWuXGk
💥 @YesWeHack's biggest reward ever!
We are thrilled to announce the successful completion of our Series C financing round – which raised an impressive €26 million!
A heartfelt thank you to our new investors - @WendelGroup, Adelie, and @SeventureP - as well as our longstanding supporters, Open CNP, @Bpifrance and Eiffel Investment Group. Special thanks to @TrachetCS for their invaluable support throughout this journey.
This funding will fuel our investment in artificial intelligence, the launch of innovative security solutions, and our continued international expansion.
And we will of course continue to #HackThePlanet! 🤘
🔗 For more details, check out our press release: https://t.co/qtOSVR7LDX
#BugBounty #YesWeRHackers
The Society has investigated and uncovered a cheater. We believe this person might be present in other teams. Check out https://t.co/Aqf974uNeK for more information
Dear Swiss friends, we’re coming to @1ns0mn1h4ck! 🇨🇭
Visit booth 10 - our team will be happy to present the @yeswehack platform, discuss the latest updates on our training environment #Dojo & introduce some hacking tools to fuel your #BugBounty game. 👾
https://t.co/dMCZQ172VJ
We've made the web challenges with @BitK_, if you have some times, come take a look 🚩
Can't wait to see how many times it will take someone to clear the category 👀
Time’s up for #HMIF2, our prestigious Live #BugBounty with luxury brand @LouisVuitton! Well done to all participants for another impressive bug haul – especially to our award winners:
🧥 Shellcode Stylist (1st place): @_godiego__
🧵 Exploit Tailor (2nd place): @djurado9
🎀 Pwnage Designer (3rd place): @hipotermia
🧶 Patchwork Pwners (Team with highest points): @_godiego__, @djurado9 and @hipotermia
💎 Best-Dressed Bug (Biggest impact): @PikuHaku
👜 Bug Trend-Setter (First valid bug): @_godiego__
Many thanks to #LouisVuitton and all partners for making this event a tremendous success!
Here is the final leaderboard: https://t.co/37Q8jRp1Up
#LiveHacking #YesWeRHackers #HackMeImFamous
Following #bugbounty findings, I started focusing my research on time-based secrets. This research began for me a year ago, and enabled me to take the time to implement my open source tool: Reset Tolkien.🚀
I've written an article detailing my research :
- https://t.co/JE8tQKhk0c
@ajxchapman@Karel_Origin@hakluke Two tricks actually:
1. I use \u2028 instead of \n just to mess with the view-source
2. --> at the start of a line in JS comment the whole line
You also need the meta tag for this to work proprely