๐จ NEW TOOL: RegistryGuard Pro is live! ๐ก๏ธ
Stop OCI/Docker supply-chain attacks before they start. ๐ Full Inventory Mapping ๐ท๏ธ Deep Tag Enumeration ๐ Image Poisoning PoC ๐ Pro JSON Reports
For the #BugBounty family. ๐ โญ https://t.co/n6n0Rdwz9h
#Infosec#Recon#Docker
900+ WordPress plugins just casually leak their presence.
No bruteforce, no guessing, just a simple request. Wild.
Haven't seen anyone using this for recon yet. ๐ค
Soon.
cc: @leak_ix
@Bugcrowd@Hacker0x01
Why not hire people like who have seen the struggle of real hunting? Why not hire people who are working day/night for years, These people are Gems, They know what are the real problems and how to overcome them.
Hire bug hunters instead of Pentesters,
Hire talent instead of certs,
Hire those who would love to build the platform.
90% reports goes to N/A because Triagers (Pentesters) couldn't understand it.
5% goes to invalid priorities.
4% goes to no response.
1% goes to accepted because ur lucky that time.
There were times when triagers (Bug hunters) help hunters to exploit their submissions to escalate the priority (Bug hunters).
vs
We don't have time to check your report, Kindly create a video because it takes time to create a new user (Pentesters).
We launched the Full-Time Hunters' Guild this week via the @ctbbpodcast community.
Accountability, collaboration, data, and support staff for full-time hunters (or part-time w/ 100k+/year).
Very excited to see how this boosts my BB performance in 2025.
https://t.co/pJbqatY1NB
In the past few months, I've been making a subdomains database containing 1.6 billion subdomains scrapped from multiple public (and private) sources.
This database is now public and FREE and can be queried on the following website.
https://t.co/C2cXn3sUOD
Enjoy!