Dear son,
A horny man can lose everything in a day.
1 minute of lust can ruin your whole life.
Success requires sexual discipline.
Control your sexual urges to win in life.
One of the SSRF's :
Server only fetch URL's with :
-https protocol
-AWS S3 bucket suffix (.s3.amazonaws.com)
- CSV extension
Payload : https://myserver\.com/ssrf.php?.s3.amazonaws.com/random.csv
ssrf.php redirects to http://169.254.169.254
I did it—$1 million on @Bugcrowd
For a lot of people this might be a small achievement, but for me, I’ve been waiting for this!
Do you know the most important tip in bug bounty? Choose one favorite program and spend years working on it. That’s my way. I’ve been working on the same program for about 3–4 years—every day on the same program. When I get bored or can’t find anything, I switch to another program until I find a bug, then I go back to my favorite program again.
After 3–4 years of hunting the same program, this helped me understand the team’s weak points. For example, they often ship ASMX/SVC endpoints without securing them, and they sometimes leave backup files in the web app, etc. With this approach, I made more than $750K from that one program alone!
Another tip—my personal rule—is: when I hunt a new program, I never leave or give up until I find a P1 or P2. If you make that deal with yourself, you’ll be unstoppable!
Believe me, these two tips are the keys to success in bug bounty that few people talk about.
Finally, huge thanks to the @Bugcrowd team for their support—I really love that team. Thanks to @RelentlessT7,
Timmy_Bugcrowd, @Masonhck3571, and all the triagers! Also thanks to FIS Global and their lovely security team!
Your turn now to make $1M—you can do it!
#ItTakesACrowd #CyberSecurity #infosec #redteam #BlueTeam #BugBounty #bugbountytips #bugbountytip #HackerCommunity #Bugcrowd
Thank you so much for all the love💙
I turned 25 last month and was feeling low for not having a regular job. It’s not that I don’t want one, but I’ve always been scared of rejection. Bug bounty has been the easiest way for me to earn and feel confident.
Found a cool bug at Meta.
From misconfigured Grafana instance to R/W access on 507 private Meta repositories.
Wrote up the full chain here:
https://t.co/LYQ0prc68d
$157k bounty awarded by @metabugbounty
This is my current stack:
Terminal: cmux
Coding model: GPT-5.5(codex)
Open source model: Deepseek V4 Pro(Max)
Harness for open source models: Droid
Terminal editor: Fresh editor
What's your pick?
What is the most efficient and easy way to setup a solution today for Claud code segmentation/sandboxing, without loosing to much performance?
What I want :
- a secure way to run Claud code + tools with full access to a shell on laptop (independent of the os) I want it to be able to install apps, dependencies you name it on the fly inside its ”home”.
- egress over network, so it can send / route traffic through a proxy like burp/caido for logging purposes, passive audits and manual evaluations. But no other host / access, findings will be sent back into the workflow for validation.
- files / memory / context dumps synced over git, rsync or similar,
- a easy snapshot functionality so I’m able to roll back and get em back up running fast when it eats itself.
Any ideas? I could easily ask the llm, but I want some human input around it.
Are there some truth to the sentences:
”Bounties is dead, pentest is dying, sast is dead”?
I personally think so, but there are a lot of nuances to it. It’s not going to disappear overnight, but roles and jobs will change, natural language code will become more secure, security will move closer to the devs and time to fix had to be close to 0.
We are now with almost insane lightning speed entering an new era of security. Either we want it or not, and the landscape of security is changing before our eyes.
It makes me wonder ”what is the shape of security to come”