⚠️ New video alert! ⚠️
Just uploaded a detailed walkthrough of @hack_sparo Death Note challenge on THM! 🚀
File upload exploits, SSH Misconfig, File immutability & Append Only attributes and Simple Docker breakouts.
Check it out with the link below! 👇
https://t.co/eP3ZbtBsP2
PwnShop has no flags. Real targets don't have them either, they have consequences.
Stolen accounts. Free orders. Full admin access. That's the impact we want you to feel.
Web: https://t.co/OHin68jWf6
https://t.co/Lp7aG240Wq
Mobile: https://t.co/7UpNSwVeQx
OWASP LLM08 Excessive Agency. When an AI agent has more permissions than it needs with no verification before acting.
I Asked PwnShop Mobile Chatbot to credit my wallet. It asked for a WALLET_TOPUP_OVERRIDE_KEY.
Can you get the credit applied?
https://t.co/GjcDDf5EaM
Pwnshop Mobile is here 📱
The Android version of Pwnshop is live. OWASP Mobile Top 10, LLM Top 10, and API business logic flaws. No setup needed, just download the APK and start hacking.
https://t.co/syMujPF4CM
If you want to see what pwnshop intentionally vulnerable code actually looks like under the hood, the full source is open.
Read the code, find the flaws, break the app.
https://t.co/3ovl3glFDT
#AppSec#BugBounty#OWASP
We built a vulnerable e-commerce app you can hack legally.
Pwnshop has over 40 vulns. OWASP Top 10 (2025) + LLM Top 10.
Live and ready. Spin it locally with Docker or hack it straight from your browser.
https://t.co/SYomyT6Zvr
https://t.co/3ovl3glFDT
#AppSec#BugBounty#OWASP
Built a vulnerable e-commerce app for pentesters and AppSec engineers to hack legally. 40+ vulns. OWASP Top 10 (2025) + LLM Top 10.
Hack it live or spin it locally with Docker. https://t.co/UfTLxRcdXe https://t.co/UG5nKmQhme
#AppSec#BugBounty#OWASP
Some Telegram channels, public and private, block you from saving media even when you're a member.
TeleReap bypasses save restrictions at the API level, bulk downloads, channel intel, auto-watcher, scheduler, file browser, history log & cloud upload.
https://t.co/XOaLGA5c6k
We’re so close to 3,000 subscribers. Only 3 more to go! Thanks to everyone who’s been part of this journey so far. Let’s hit 3k together and keep growing.
@commando_skiipz It depends on the application logic. If the balance check and debit are not atomic, this becomes a classic race condition / TOCTOU issue and $2,000 can definitely go out.