@Thezinnekalu My expectation is that, as bug bounty shifts toward automation with tools like Claude Code (API/cloud-based), the need for high local RAM should decrease since most of the heavy lifting is offloaded to the cloud... 🫤
Thinking about grabbing a MacBook Air M4 (16GB) — question for bug bounty hunters: does this make sense if I haven’t used macOS in 12+ years?
Be honest: is it enough for the job, or am I about to pay premium money just to relearn shortcuts like it’s 2012 again? 😂
@thedawgyg This looks cool! I’m curious about your workflow—what type of AI are you using and how are you handling the orchestration? Good luck with that RCE! 🤞
@singe This would work if rules could be triggered based on a regex match: you’d send one request to Repeater with a dummy value, and it would know to run all rules and resend every matching request with the value substituted.
@singe It helps identify auth issues like BAC by comparing responses between requests.
It also enables fuzzing by sending multiple requests with random characters (' " ? % & > [ $) in URL/JSON params or headers to check whether any context breaks when those values are used as input.
Happy Arcanum-versary!
@arcanuminfosec 's 1st giveaway for the week is FOUR seats to our EPIC Advanced Client-Side Hacking course by myself and @xssdoctor !
👍 1 Like = 1 Entry!
♻️ 1 Share = 2 Entries!
Winners announced 1/21!
Syllabus for the course below 👇
🤯 Jumping into Bug Bounty? Stop manually sifting through minified JS!
It's a known fact: Javascript files are a GOLD MINE for security bugs. This extension turns minified chaos into readable code instantly. 🚀
https://t.co/9pk1qWhCk1
#BugBounty#WebSecurity#infosec
My Twitter algorithm is convinced I need more low-quality content and questionable influencers. 🤦 I'm fighting back!
Send me your best recommendations for top-tier #Cybersecurity and #BugBounty accounts to follow. Help me fix my feed before it's too late! 😟
Great writeup — concise + well-explained. A fantastic primer for new bug bounty hunters just getting started, perfect for learning how small issues chain into account takeover👉 https://t.co/SwUfwCKJ04
by @j_zere#bugbounty#appsec#infosec
@_jensec For something more advanced that might involve reverse engineering, you have this channel. It's helped me a lot in the past...
https://t.co/6vHxlg7dzt
By @SecFatal
@_jensec Sometimes ssl unpining is not trivial and a quick and easy solution for analyzing requests is to use Frida scripts directly and log everything that is http...
@HusseiN98D@Bugcrowd Well done. Without going into the details of the methodology, using a purely manual approach what categories have you found to be the most prevalent?
Resolutions for 2025:
❌ read the books I bought
❌ finish the udemy courses
❌ finish all the @PortSwigger labs
❌ read bookmarked articles
❌ view all YouTube "watch later" videos
✅