Alhamdulillah.
My first bug after about 7 months of grind and confusion
Thanks to all who I benefited from their knowledge in this field
#bugbounty#NASA#cyberscurity
Bug bounty talks that are 5+ years old
and still produce bugs nobody else is
finding.
Most hunters watch the latest recon
tool demo and skip the talks that built
the methodology they're using without
knowing it.
Here are 10 forgotten talks 🧵 that still pay
First bounty!
After spending around 1,700 hours of strugling and doubting my abilities, I got my first bounty.
I thank everyone who has helped me reached this milestone.
#Firstbounty#Bugcrowd
Very helpful video on how to attack complex/hardened systems by @alisaesage, if you didn't see it yet 🧠
This applies to web bug bounty hunting as well!
https://t.co/93V8pvLKHR
كل فتره من فحصك المتواصل لازم تخلي كذا فيه توقف تتعلم شي جديد تقراء شي جديد تسمع شي جديد حتى لو مو لغرض التعلم بقد ما تنمي عقلك على التفكير وتشوف الافكار الجديده
Hackers Vs Triage
https://t.co/oKPlYb8Qp5
An absolute goldmine for bug bounty hunters 👀💥
A massive collection of real, disclosed HackerOne reports — organized by vulnerability type, impact, and target 🎯
If you want to go beyond theory and actually understand how real-world exploits work… this is it.
Study patterns. Learn impact. Hack smarter. 🚀
🔗 Source: https://t.co/yMey4fzDbn
#BugBounty #InfoSec #CyberSecurity #EthicalHackin
Nigerians, Wake Up!
Over the last 2 years, a dangerous and divisive narrative has spread across Nigeria, a narrative of religious persecution, of Nigerian Christians being massacred by “Islamic jihadists” and “ISIS terrorists” for their faith in a “Christian genocide”, a narrative which did not originate in Nigeria, but in Washington DC. For the last 2 years, and in recent months most especially, the administration of US President Donald Trump has been relentlessly pushing this narrative.
Why is it doing this, and why should every Nigerian be very concerned?
The answer lies in the history of geopolitics over the last 8 decades, and in this video, YouTubers Sonny Faz and Bek Lover shed light on this answer.
I published one of the techniques that I've been using against OAuth providers, honetly, it's led me to discover many flaws, and recently I used it to find a 1-click ATO on one of the most widely visited websites,I hope you find it useful :-)
https://t.co/o7OO8Y7e3K
Most JWT content is stuck in 2015.
alg=none, weak secrets, basic misconfig screenshots.
That’s not where the interesting bugs are.
I usually keep this stuff private.
This time I’m dropping it publicly ↓
https://t.co/Sm0oiwjyxV
This is why reading specs beats reading recycled bug bounty writeups.
I published a real-world auth bug where trusting one OIDC claim the wrong way could let a different user inherit someone else’s account.
Read: https://t.co/wxCZsVmRQM
Stop reading recycled Medium writeups. They’re surface-level marketing trash for script kiddies.
If you want actual protocol-level bugs and critical auth bypasses, you read the primary sources. Here’s the reading list that separates actual engineers from scanner monkeys. 🧵👇
The more time you spend on a target, the higher your chances of finding bugs.
However, very few people are willing to spend weeks or even months just to understand how an application truly works.