A week ago I said that bug hunters could write novels about “the dark side of bug bounty”.
I mostly meant how shitty programs can be.
Little did I know:
https://t.co/7oWk5XcgSC
The report of a platform triager, an h1 employee, who stole bugs from bug hunters to profit.
Registration is now LIVE for the PNPT Training Live stream class.
Over 50 hours of ethical hacking training, including OSINT, Active Directory exploitation, web exploitation, privilege escalation, exploit development, and so much more. FREE.
Enroll here: https://t.co/pyMidHpivz
🐚 Did you know? Posix shell input/output redirection doesn't need to be at the end of the command. You can put it at the start or in the middle of the command too:
$ echo >file hello world
✨
Oy vey. We give candidates a blank GCP project for our interview project with Owner access. Just saw that a candidate committed his credentials to Github, which got picked up by a bot and racked up $78k in charges in 3 days. 😬
I was reviewing Cryptocurrency services I was using and I found a private Github token in a Blockfolio app from two years ago! Writeup:
https://t.co/giDulNFhu5