I completely forgot to share the tools I used in my previous video: https://t.co/l8dYOvxQ8A
you can now grab them here and start hunting for exposed Gemini API keys:
https://t.co/XCZiXaa6sC
https://t.co/5EbQOlqSvY
please use them responsibly and focus on self-hosted bug bounty programs. Happy hunting!
I earned $10,000 for my submission on @bugcrowd https://t.co/CA89MKVB8T #ItTakesACrowd#BugBounty
Bug: Weak JWT sign key + mass assignment in the JWT -> read arbitrary customer sensitive/PII data
Fully found by Claude using @profundisio MCP
⚙️ @profundisio New Unified Search allows users to search across hosts, DNS, certificates, and WHOIS, with all results ranked together in a single query.
Very useful for recon during bug hunting! 🔥
https://t.co/vyvLWOJpYO
#bugbounty#bugbountytip#bugbountytips #ethicalhacking #hacking #infosec #pentesting #PenetrationTesting
Found an interesting ORDER BY SQLi during a pentest protected by a Baffin Bay WAF.
Used RAG MCP by @0xrudra + Claude CLI (deepseek-v4-pro) to explore PostgreSQL WAF bypass techniques.
Write-up: https://t.co/bKLEl2pD1d
#CyberSecurity#AppSec#SQLInjection#WAFBypass#PostgreSQL
Jangan pernah remehin "useless" bug. Self-XSS yang biasanya diketawain (karena butuh interaksi user) aja bisa berubah jadi bounty $15.000 (Zoom).
Kuncinya adalah, chaining.
Gue nemu case di mana attacker gabungin Self-XSS sama OAuth. Gini skenarionya:
1. Korban klik link malicious (XSS jalan di domain A).
2. XSS ini kirim postMessage ke domain B (trusted domain).
3. Domain B nerima message, terus trigger OAuth login ke Zoom.
4. Pas korban login, Authorization Code-nya malah dibajak sama XSS di domain B.
5. Attacker dapet Access Token.
Hasilnya? Attacker ambil alih total, curi data, sampe bisa nyalain kamera & mic korban.
Satu bug remeh kalo digabung sama celah lain bisa jadi exploit yang mematikan.
I’ve been hacking on for quite some months now, and it’s been a rewarding journey. Huge shoutout to their security team! 🙌
There are still some bugs pending for payout. The grind continues! 🚀 #BugBounty
@robj3d3 Awesome man!!! Please install Tailscale immediately, then set up a Cloudflare Tunnel if you wanna host any websites
Then go to Hetzner, add Firewall, make new one, empty it (!), then it will block all inbound ports