On July 25, we hacked OpenAI.
Two bugs let us take over ChatGPT/Codex accounts of OpenAI employees (+some unaffiliated users) and reach connected services: Outlook, Slack, GitHub, etc.
We proved it with a PR in OpenAI’s internal codebase . It took us <72h. 🧵
With only 48 hours remaining in a bug bounty event, I used @HacktronAI CLI to perform large-scale analysis of several JDBC drivers. Netting $85,000 in total rewards.
This write-up shows how AI-assisted vulnerability research is speeding up the work of researchers and leading to high-impact findings.
Read here - https://t.co/voMin9l8Dx
Andrej Karpathy says you should learn AI depthwise, not breadthwise.
Most education is breadthwise: watch lectures, memorize formulas, and trust you'll need it later.
Karpathy flips this by learning "depthwise, on demand."
What this means:
Pick a project, start building, and learn exactly when you hit a wall.
When he created a tutorial on transformers (the architecture behind ChatGPT), he didn't start by explaining attention mechanisms or complex architectures.
Instead, he started with the simplest possible thing: a lookup table that predicts the next word.
You build that first. Then you try to make it handle more complex patterns.
And it breaks.
Only then, when you've felt the limitation, does he introduce the next concept. Each piece solves a problem you've actually encountered.
As he puts it:
"It's a dick move to present the solution before I give you a shot to try it yourself."
When you attempt the problem first, the solution actually makes sense.
Teaching forces you to learn. "If I don't really understand something, I can't explain it."
When you try to explain and stumble, you've found the gaps in your understanding.
...
Build a project that gives you a reward.
Hit a wall. Learn just enough to solve it. Then explain it to someone else.
Don't consume content. Build the code.
That's how you actually learn.
Pick a niche, become an expert, find bugs maybe even 0days or reverse n-days, and write blogs. Even if you don’t hit those $100k bounties, it’ll be a stepping stone toward a $100k job.
What niche? How to pick? Examples?
infosec being so vast from web3 sec to web2, mobile, desktop, recon, client-side, server-side, cryptography and so on. These are umbrella terms, but if we zoom in, there are specific areas where spending a lot of focused time will make you a top 20 expert -- 100% sure.
The key thing is, that the current top 20 experts in any niche will eventually be replaced as they get bored or burned out. This leaves room for you, and the easiest way to pick a niche is to learn from an existing expert in the niche, take inspiration, and grind to build on top of it.
1. For instance, I got into the client-side JS niche by following @terjanq’s work. From there, I went down even further to focus specifically on ElectronJS.
2. Another example: @rootxharsh and @iamnoooob their niche is in reversing n-days and finding new ones based on that knowledge. I don’t think anyone in India can compete with them on reversing n-days, writing blogs, and submitting findings to bounty programs.
3. And off the top of my head, @ajxchapman, from his tweets, seems to have a specific niche in V8 n-day exploits. I don’t think there’s anyone else in the web security scene who can write V8 exploits 😅.
4. Like @orange_8361 , pick a complex target and grind on it for months eventually uncovering mind-blowing findings.
5. Or, like @albinowax, choose a complex specification, such as HTTP, and find bugs from every aspect of it from top to bottom
(Sorry for tags xD)
I could list so many more people, but my point is this: if you look at the top bug bounty hunters or experts, there’s a pattern. Their blogs or tweets consistently focus on a specific niche (or two) for years and years. No one ever becomes a pro in a night.
How to Become an Expert in a Specific Niche?
Spend a lot of time. There’s no shortcut. Follow the work of the expert you picked for inspiration, read their blogs, dive into the blogs they learned from, and explore everyone else in that specific niche. Solve CTFs and write about them.
For example, not to make it all about myself, but just as an example. I’ve read every blog from the people I listed as inspirations(https://t.co/5MCSPeoygf) while learning client-side security.
If it’s taking time to understand, you’re likely on the right path. That’s where most people give up, so keep pushing. Just dedicating days to it will put you ahead of at least 100 others. It’s that simple.
Expert = Spent Time × IQ
Find Bugs or 0days, Reverse n-days, and "Write Blogs
Once you’re an expert, finding bugs will start to feel natural. But let’s be real, sometimes you might not get lucky. When that happens, reverse other n-days and write about it. I mean write about anything. Nothing gives you as much exposure as writing blogs: you’re helping others, plus you’re building a network that will eventually help you land a $100k job or $100k bounties.
Nuclei v3 is finally out; it includes multiple new additions that enable us to write a versatile set of templates, including complex and multi-protocol workflows in the form of repeatable @pdnuclei templates.
More details in the release blog - https://t.co/GSGUeO8grB
GitHub Release - https://t.co/nc54hU0ixk
#hackwithautomation #vulnscan #recon #opensource
https://t.co/JbBnEMwVuu
Sorry for the delay, but it's here now!
Give it a read a let me know how you like it!
cc: @RathiArpeet#infosec#hacking#wordpress
Chandrayaan-3 Mission:
'India🇮🇳,
I reached my destination
and you too!'
: Chandrayaan-3
Chandrayaan-3 has successfully
soft-landed on the moon 🌖!.
Congratulations, India🇮🇳!
#Chandrayaan_3#Ch3
I've made over 100k on SSRF vulnerabilities.
They aren't always as simple as pointing it at localhost or AWS Metadata service.
Here are some tricks I've picked up over the past 5 years of web app testing:
New blogpost! In this post we analyse CVE-2023-29300, a pre-auth RCE in Adobe ColdFusion via unsafe Java Reflection invocation.
https://t.co/6av1adAYRP
I hacked into a @Bing CMS that allowed me to alter search results and take over millions of @Office365 accounts.
How did I do it? Well, it all started with a simple click in @Azure… 👀
This is the story of #BingBang 🧵⬇️
Announcing Nuclei Cloud - SaaS platform built on the top of @pdnuclei open-source project to ease the automation experience at scale for everyone.
We've also raised $25M in Series A round led by @CRV 🙏
More details in the blog –– https://t.co/mz2Bg3IieX
#hackwithautomation
ATO of FB/OC accounts after stealing access_tokens ($44,250)
https://t.co/79z5LwgN2n
DOM-XSS in Instant Games due to improper verifications ($62,500?)
https://t.co/Hf63ib7g4x
ATO in Canvas Games due to weak cross window message Origin validations ($62,500)
https://t.co/BUziBmRbjj
New blog post from our side at @pdiscoveryio. In this blog we analyze a bug in php development server. How a slight mistake in logic led to source code disclosure.