Alhamdulillah, biidznillah, just passed OSCP Exam on my 5th try. Finally, after 2 years of chasing this cert, Allah has willed it to me to passed.
"Fail then try again, fail then do it again, until you reach your goals."
Thanks @offsectraining for the "Try Harder"
Alhamdulillah, second time in my life, got paid for a won't fix bug.
Reported -> Triaged -> Bounty -> After internal assess they consider this as intended feature
Asked the Program Owner about the bounty, they said the bounty still stands. Haha thankyou !
You can try the Suggest Attack Vectors feature in rep+. Add your Anthropic key and get quick ideas (IDOR, SQLi, weird params) right in the browser.
I also used Bulk Replay to test without leaving DevTools.
PS: Always understand what you’re doing. Never trust the LLM blindly.
Pick a niche, become an expert, find bugs maybe even 0days or reverse n-days, and write blogs. Even if you don’t hit those $100k bounties, it’ll be a stepping stone toward a $100k job.
What niche? How to pick? Examples?
infosec being so vast from web3 sec to web2, mobile, desktop, recon, client-side, server-side, cryptography and so on. These are umbrella terms, but if we zoom in, there are specific areas where spending a lot of focused time will make you a top 20 expert -- 100% sure.
The key thing is, that the current top 20 experts in any niche will eventually be replaced as they get bored or burned out. This leaves room for you, and the easiest way to pick a niche is to learn from an existing expert in the niche, take inspiration, and grind to build on top of it.
1. For instance, I got into the client-side JS niche by following @terjanq’s work. From there, I went down even further to focus specifically on ElectronJS.
2. Another example: @rootxharsh and @iamnoooob their niche is in reversing n-days and finding new ones based on that knowledge. I don’t think anyone in India can compete with them on reversing n-days, writing blogs, and submitting findings to bounty programs.
3. And off the top of my head, @ajxchapman, from his tweets, seems to have a specific niche in V8 n-day exploits. I don’t think there’s anyone else in the web security scene who can write V8 exploits 😅.
4. Like @orange_8361 , pick a complex target and grind on it for months eventually uncovering mind-blowing findings.
5. Or, like @albinowax, choose a complex specification, such as HTTP, and find bugs from every aspect of it from top to bottom
(Sorry for tags xD)
I could list so many more people, but my point is this: if you look at the top bug bounty hunters or experts, there’s a pattern. Their blogs or tweets consistently focus on a specific niche (or two) for years and years. No one ever becomes a pro in a night.
How to Become an Expert in a Specific Niche?
Spend a lot of time. There’s no shortcut. Follow the work of the expert you picked for inspiration, read their blogs, dive into the blogs they learned from, and explore everyone else in that specific niche. Solve CTFs and write about them.
For example, not to make it all about myself, but just as an example. I’ve read every blog from the people I listed as inspirations(https://t.co/5MCSPeoygf) while learning client-side security.
If it’s taking time to understand, you’re likely on the right path. That’s where most people give up, so keep pushing. Just dedicating days to it will put you ahead of at least 100 others. It’s that simple.
Expert = Spent Time × IQ
Find Bugs or 0days, Reverse n-days, and "Write Blogs
Once you’re an expert, finding bugs will start to feel natural. But let’s be real, sometimes you might not get lucky. When that happens, reverse other n-days and write about it. I mean write about anything. Nothing gives you as much exposure as writing blogs: you’re helping others, plus you’re building a network that will eventually help you land a $100k job or $100k bounties.
Alhamdulillah, I just published a new story, about a bug that I found several months ago. Here it is,
Purchasing Golden Number at a Lower Price: A $800 Bounty Story https://t.co/6BGThp7Kf4
How I configure Autorize in Burp Suite 90% of the time, to identify IDOR/BOLA:
- Uncheck Ignore 304/204 (they can often uncover issues)
- Check unauthenticated
- (the first 2 filters are default)
- Filter: Scope items only
- Filter: Ignore OPTIONS requests
#pentesting#appsec #cybersecurity #bugbounty
Recently decided to start note-taking on whatever I read - blogs, courses etc. Since everything I read is already public, I don't see any point in keeping those notes to myself. Now that I'm consistent with it, here's where everything will be:
https://t.co/aLNjrfe3xk
#bugbounty
📢 14K #Giveaway🔥
rules to enter:
👉 must follow @OSINTindustries & @0xtechrock
👉 Like & Repost!
🌟 100 OI credits to 3 humans.
🌟winners announcement on Sept 10.
#OSINT
My friends and I had sucessfully escalating Time-Based SQLi to RCE utilizing xp_cmdshell, biidznillah. Here is the details writeup, hope you enjoy!
https://t.co/RqL9TRjkxu
This horrific live video footage vividly illustrates the reality of Israel's mass slaughter in #Gaza. This is what our MPs across the political divide are supporting.
#FreePalestine
Hello folks! I am testing a web app, and found a PDF renderer with user-controlled input. when i insert simple HTML <h1>YES</h1>, it executed in the PDF, but not with the <iframe>. Any idea to leverage this ?
Alhamdulillah, biidznillah, just passed OSCP Exam on my 5th try. Finally, after 2 years of chasing this cert, Allah has willed it to me to passed.
"Fail then try again, fail then do it again, until you reach your goals."
Thanks @offsectraining for the "Try Harder"