@S1r1u5_ Sure, competition is there, but fun is gone. I don’t like to use ai to solve CTF tasks (partially or not, doesn’t matter), and I don’t like to stay behind(on leaderboard) someone who just uses ai. That’s just not the game I like playing.
@LehmannLorenz@code People saying in comments that Linux is a solution, are you making a joke? How the heck it’s saving you from code execution after you’ve clicked “install” on malicious extension?!?
@Hacker0x01, your support team has been unresponsive for 9 days regarding ticket #532796. I have dedicated considerable time to a program, discovered multiple bugs, and have been unable to withdraw my bounties since December. Please address this issue immediately. #hackerone#bb
Is there a way to find out if application is running PHP version < 8?
- phpinfo is NOT available
- Errors are suppressed
#php#bugbounty#hackers#hunters#cve
The easiest way to find a max-impact desync vulnerability in 2024:
1. Create a novel desync technique
2. Add it to a tool like HTTP Request Smuggler
3. Scan a bunch of systems and see what sticks.
The only tricky step is #1 and there's a new tool to help with this 1/2
A writeup analysis of a simple logical vulnerability at @googlechrome for which @GoogleVRP paid me $16,000.
Link: https://t.co/YMpxGVQCSo
P.S. I have very few subscribers, so I am grateful for every repost
#0day#Chrome#GoogleVRP#CVE
🚨 Explore the CVE jungle with ProjectDiscovery's cvemap! 🌐🛡️
A powerful tool integrating KEV, EPSS, POCs, and more data, for a comprehensive threat analysis. Stay on top of cybersecurity challenges with #cvemap! #CyberSecurity#HackWithAutomation
https://t.co/XpTJXxZ4im
We found two 0-day vulnerabilities in @Ubuntu kernel and it all started by reading descriptions of old CVEs 📖
Thread about the discovery of #GameOverlay 🧵👇🏼
Universal MXSS. Works in all browsers and is likely to bypass lots of filters because title is both an SVG and HTML tag. Briefly checked DOM Purify and it looked okay.