Finally, here is the blog for the prototype pollution research we did.
"A tale of making internet pollution free"
- Exploiting Client-Side Prototype Pollution in the wild
https://t.co/jsShZGlgKB
🥳🥳 WE ARE GOING FULL-TIME. We just secured $1.7mn of funding in our seed round from some amazing people from the security community. Here is the blog —https://t.co/vJPPtHza1V
#opensource#community#security#announcement
I and @rootxharsh found and exploited a 0Day RCE in Apple's Travel Portal and were rewarded with $50K. Here's the write-up for that:
https://t.co/zMpw2QOEvP
Finally, the Most awaited write-up is here , SSRF (Server Side Request Forgery) worth $4,913 | My Highest Bounty Ever!
Kudos to @TechFenixSec Red team for helping me throughout the research
Retweet if you like it.����
#bugbounty
https://t.co/qfLCiAo0sg
Inspired from all the awesome creators, Here's our try-on video content. Here's the first installment of the Javascript Prototype Pollution series.
https://t.co/1eBQGHhjoX
by @iamnoooob & me.
Remembering and typing all those long commands was never convenient for me so I made this : LazyHunter https://t.co/DbOs9FEBWg
It helps me save some time during Bug Hunting.
#bugbounty
The most important part of recon is to find the internal domains, you can also find them in dotfiles or Bash profiles (dev commits)
Recon on internal domains = more juicy endpoints = more bounties 😋 #bugbountytips
Hackers from Indore and nearby location, there is an IBH regional meet coming up.
Organizers:
@rootxharsh - Appsec @Vimeo & bug bounty hunter @Hacker0x01@ahm3dsec - Penetration tester and bug bounty hunter @cobalt_io & @synack
Signup - https://t.co/50KIolcpTh
#infosec
Here is my writeup for Facebook's BountyCon 2020 CTF. Was not able to give much time but enjoyed solving a couple of challenges.🧑💻
#bugbounty#ctf
https://t.co/kCnUyvF4rw
Opensourcing another project from team @pdiscoveryio#Nabbu, Simple and Fast port scanner with handy features to use with another tool in your recon pipeline.
Link to project:- https://t.co/4R2ToEgsRq
#naabu#bugbounty#infosec#pentesting