People should learn to live like this. Theres not a single thing here that is inaccurate, and i truly believe it would make a lot of people more happy than they currently are.
“Bug bounty is dying” is noise.
Lock in. Make money. Use AI to 10x your output. If it eventually dries up, you’ll have enough capital to start that biz or enough experience to land a job.
Simple as that.
Vulnerability research with AI: straight highways & cable cars instead of foggy climbs. We lost the grit of conquest. Perhaps the "intellectual joy" was forced into a higher dimension. Keep thinking. That familiar shiver of discovery will come back, wearing a new mask.
CSRF PoC Generator v1.0.5 is released for @CaidoIO.
Thanks to @weeshter for reporting an issue with generating PoCs from HTTP History rows. This update fixes that workflow.
As an addition, I refreshed the UI with a cleaner Caido-style layout.
https://t.co/b7sZTtbUP7
Super excited to release our latest Broken Access Control (BAC) Masterclass on @hackinghub_io with 2 hours of content and almost 20 labs. I'm giving away 3 free seats to anyone who comments, reposts, and replies to this post. Drop a 🔥 below!
More info 👉🏼 https://t.co/g8gwo5vYGN
I created a challenge based on one of my Google bugs worth $12,000. It is an OAuth misconf. I will drop a writeup for it soon, before that, give it a try & practice, it doesn't matter if u r capable of solving it or not, just click and start poking 🙂
https://t.co/lAW53dVyk5
Found a 1-click account takeover via postMessage. No phishing, no fake login page, just one click and a full-access token.
Wrote up the full breakdown and also gave the whole site a little revamp while I was at it.
https://t.co/piH3rZg9LN
I wrote this story in a blog post, starting with my old challenge and leading up to this point. Chromium has since patched this attack vector. The full post is linked below, hope you enjoy reading it ;)
https://t.co/cRm6YTGAND
If the admin panel you targeted has a username enumeration , you can brute-force using a wordlist. This has worked many times for me in this case, the username was "admin"
My password wordlists:
Basic: https://t.co/dwZXsZISiJ
Advance: https://t.co/2AvuC5qTqz
Usernames wordlist:
https://t.co/cKCjZbmS39
#bugbountytips #bugbounty
AI is creating more attack surface instead of reducing it , just check the VRT & search for LLM issues.
everyone keeps predicting the future, but the reality is that non technical people r now pushing code, security teams are struggling to keep up with rapid reports , and new easy 0days are coming. Meanwhile, AI keeps advancing without slowing down 💯
so instead of overthinking , focus on present day problems & hunt for all bugs 🐞
🚨
As of tomorrow I am permanently reducing my course cost by 50% to $100 so more people have access to it and can get those bounties while they are still hot. And yes, they are still hot. The internet is still full of stupid problems waiting to be found for those looking, at least for now...
https://t.co/ZQDJvWYVZb
I suspect we have about 2 years of decent #bugbounty hunting left before most companies have access to and properly leverage the tools like Mythos that effectively replace "most" hackers.
Using the EXACT methods in this course, I found 20+ critical bugs on a target in a matter of hours the other day. Nothing fancy. The internet is just too dang big to fix and patch in a small amount of time, even if AI is finding the bugs. Internal legacy human processes with 500 steps are still bottle-necking remediation.
What the bug bounty world becomes next is anyone's guess. My suspicions, hackers will be paid flat rates for hacking and/or patching targets any way they can (be it AI, manually, or both). So, here's to the next evolution of hacking, which is hopefully round-table LHE's where we all work together on targets to harden them as best as possible, instead of working against each other to try to "be the best hacker".
Re-post for a chance to win 1 of 5 course coupons for a give away on May 14th. I'll have Grok pick the winners.