3 months ago, I took the challenge to take over one of the most hardened bug bounty programs ever. 30 days later, ranked top 1 within the rules and exited. Since then, I still have the crown. Sharing a couple mental tips ⏬️
I found a vulnerability that allowed me to unlock any @Google Pixel phone without knowing the passcode. This may be my most impactful bug so far.
Google fixed the issue in the November 5, 2022 security patch. Update your devices!
https://t.co/LUwSvEMF3w
📢#infosec AMA v2.0 #61
Our next guest for v2.0 is :-
✨✨ @hunter0x7 ✨✨
Ask him about #bugbounty#cybersec or anything else.
RT, Like, ask question to win (guest selects the winner) a voucher by
@PentesterLab
Date :- Oct 7
I’ve never done a similar giveaway but got 2 professional passes to @bsidesahmedabad 🇮🇳 that I’d love to donate should you be interested in attending and haven’t purchased one yet.
Just FOLLOW me and RETWEET this post to participate 🤍
Thread - Confluence Blind OGNL Injection analysis from our limited java knowledge. From vulnerable sink to becoming admin of the confluence instance. #CVE-2022-26134. Tested on latest vulnerable version 7.18.0.
Whitehat satya0x reported a critical vulnerability in @wormholecrypto on Feb 24 via Immunefi.
The bug was quickly patched, no user funds were affected, and satya0x received a $10 million payout from Wormhole, the largest bounty payout on record.
https://t.co/xKDGxfFLjA
If you haven't yet seen, this is how we hacked a BIG bank 😱 . With @infosec_au , We were able to gain RCE on more than 100 different subdomains by exploiting a 0day we discovered. Reported through their #bugbounty program. Enjoy the read!
https://t.co/TlG6e5DINs
Finally, my first blog post on an interesting advanced sqlmap use case I found recently through a code audit. Shows how to combine sqlmap options to automate a complex scenario involving a mid-parameter SQLi on an error page. Enjoy! https://t.co/FzXM4BalOb
I have finally finished one of my many writeups due to the community. In celebration, I will be giving out 3 1-month subscriptions to @PrettyRecon. Comment, RT and follow to be considered for the giveaway! #bugbountytips#bugbounty#cybersecurity
https://t.co/GVVk8MOScU
A few months ago, I collaborated with @HusseiN98D to find critical vulnerabilities in a bank. It involved finding a 0day in dotCMS. You can read about the discovery and exploitation process here: https://t.co/prFg60QieF
🍾🪩🪅🎉🥳Giveaway time! 🥳🎉🪅🪩🍾
We are going to send a t-shirt and few goodies to one person who follows
@PentesterLab
and likes this tweet !!
And we are going to give a 1-year voucher to someone who RT this tweet!