After a month hunting (+50 hours) on NASA’s VDP, I finally showed impact. Still aiming for that first P1 on bugcrowd.
Back to my BSCP journey…
Thanks to @4osp3l, @NahamSec, and @bhaveshdewasii .....they inspire me a lot.
#BugBounty
I finally made a couple months ago........It has been one of the toughest experiences in the field of cybersecurity.
I wrote a detailed review for those who have found it very difficult or have failed more than once.
#OSCP
https://t.co/opbLAe94DI
https://t.co/Aek8HqiHUf
After a couple of months away from social media, I focused on bug bounty, but it became too stressful. Now I’m preparing OSCP, happy studying and solving machines, and I’m turning this account into a log of my journey to the certification to support others on the same path.
@ant0sec No del todo, en mi caso, el sindrome del impostor es lo que puede conmigo. Por otro lado, los bugs que más alto han sido categorizados por triagers llevan casi 1 año esperando respuesta de la empresa (6) y los bugs más simples y rápidos son los que me han dado dinero (5).
After a couple of months away from social media, I focused on bug bounty, but it became too stressful. Now I’m preparing OSCP, happy studying and solving machines, and I’m turning this account into a log of my journey to the certification to support others on the same path.
I came back from my cave just to check if my write-up had been good enough, and it looks like it was.
SSRF --> Gopher --> File upload bypass --> RCE
https://t.co/9TWN1fsiF8
Our second winner is s1x! 🎊
s1x came forward with another excellent write-up outlining his exact methodology for solving October CTF challenge with an unintended solution! The detailed breakdown of the Gopher protocol technique and how it can be used to capture the flag is truly well-written.
Read it here 👇
https://t.co/ipJNzc16v1
I've subscribed to @theXSSrat content, I'm going to stay away from social media and lock in bug bounty, I'll be back in 2026, we'll see if it's been effective🫡
BSCP Prep Vol. 18:
• Completed HTTP request smuggling practicioner labs.
• Reached the 70%
• I hope they don't put this on my exam, it's fun to exploit but I fail at some details in the recon.
#BugBounty
@ks7X01 One is more focused on web, and the other on enterprise pentesting. Both are really good,if you want to focus on web, go for BSCP, and if you want to be a pentester, choose CPTS.
BSCP is free and that's a plues ;)
@4osp3l Not everyone want to share their real stats, many just show how good they are at finding bugs, making us feel we’ll never reach their pro level. What you show is that consistency is the real key. Thank you for that 💪
@Walid8766166735 I'm preparing a huge cheatsheet to pass BSCP, I'll share it if I pass the exam.
I only have 300$ on earnings, but I recommend you to check content from:
@theXSSrat@NahamSec@4osp3l (medium or X) @coffinxp7 and rs0n_live on youtube.
And of course @PortSwigger Labs ;)
Having too much fun studying HTTP Request Smuggling
I mean is so interesting, I´ve been doing pentest 2 years and never though on this.
Is worth it to find for them on BB programs?👀
BTW this youtube channel is a goldmine: https://t.co/FuKDYG6Jht
After 1 week of vacations I came back with a BAC on hackerone, found with a friend in a conference.
Unfortunately it was dup, but I'm on the right track, going back to BSCP.
I'll be starting my own BB challenge soon 👀