url/?f=etc/passwd ==> 403
encode etc/passwd as base64
url/?f=L2V0Yy9wYXNzd2Q= ==> 200
#note
you can use this trick in SQL , SSTI , XSS , LFI , Etc...
#bugbountytips#bugbountytip
I just published a blog post for the people that want to get into bug bounties. I hope it helps people that are thinking about doing bug bounties, but haven't started yet. It explains what to expect and how to deal with common problems / situations: https://t.co/V9CKTpJzPT
Tomorrow I’ll begin my 10th year in prison.
I don’t know what to say. I screwed up. I ruined my life and caused a lot of pain. When I look back and see my many mistakes, I feel immense regret.
I decided to make a homage-post to @homakov and @Nirgoldshlager about different OAuth-token leakage methods I've been researching – ten years after their blog posts that inspired me to start hunt for bugs ♥️ thank you.
https://t.co/pODPvDUOU9
I have created a lot of useful little hacking tools over the last few years, sometimes I tweet about them, sometimes I don't.
Here's a list of some of the most useful ones, and a brief explanation of what they do! 🧵👇
I found a vulnerability in #Azure allowing me to access Azure accounts of companies worth billions
We all know vulnerabilities exist. This isn't an injection, XSS, or RCE.
But the crazy thing about it?
It took 2 hours to discover. 🤯
Here's the story of #AutoWarp👇 (1/10)
Our province in the PH needs help due to super typhoon Rai. I've raised around $400. As small as $1 can help for food. We need at least basic needs, food and water. Thank you very much, especially my bug hunter friends.
Some basic regex knowledge can save you a lot of time and supercharge your hacking process. 💻
This article by @hakluke aims to teach regular expressions from a hacker’s perspective, by providing real-world examples, starting from basics and going deep! https://t.co/c9hB6cXMPK