alex_vec's profile picture. Penetration Tester | OSCP | Previously founded: @Carnagebot | https://hackerone.com/alexvec | https://bugcrowd.com/alexvec

Alex

@alex_vec

Penetration Tester | OSCP | Previously founded: @Carnagebot | https://hackerone.com/alexvec | https://bugcrowd.com/alexvec

Pinned

Legit check on me 🤝


Alex reposted

Easy $400K+ success by Minter Suite with Zereborn We cleared 20% + of this drop ALONE 💎 Like & RT for a free 1 SOL giveaway. Ends in 24 hours ⏰

MinterSuite's tweet image. Easy $400K+ success by Minter Suite with Zereborn

We cleared 20% + of this drop ALONE 💎

Like & RT for a free 1 SOL giveaway. Ends in 24 hours ⏰

Highly recommended for beginners and experienced hunters! This podcast is a gem 💎

Been really overwhelmed by the love for CTBBPodcast from the @spotify 2023 Wrapped. Love y'all <3

ctbbpodcast's tweet image. Been really overwhelmed by the love for CTBBPodcast from the @spotify 2023 Wrapped. 

Love y&apos;all &amp;lt;3


It's official, my team, trick or hack me, has placed between the first top 8 teams in the HackerCup 2023 by @Bugcrowd ! With 40 teams participating, this is a huge achievement and I'm stoked to give the best I can in this Round 2 🥳 #bugbounty

alex_vec's tweet image. It&apos;s official, my team, trick or hack me, has placed between the first top 8 teams in the HackerCup 2023 by @Bugcrowd !

With 40 teams participating, this is a huge achievement and I&apos;m stoked to give the best I can in this Round 2 🥳

#bugbounty

November has been my best month in Bug Bounty hunting. $4200+ in rewards and many lessons! I changed my strategy to two key points: - Collaborating really helps - Stick to ONE or TWO programs and go deep on them. Read more about it here: alexvec.github.io/posts/november… #bugbountytip


Hackean la web de CCOO con write-up incluido. El nivel de seguridad es de una HackTheBox easy, les faltó incluir la flag de root.txt y se llevan el premio 😂

El atacante de la web de @CCOO, aka 'farlopa'...ha publicado una guia con los pasos que realizó para aprovechar las vulnerabilidades en el diseño e implementación de su web.... Veremos que pasa con los datos de los afiliados.. farlopa.noblogs.org/mariscada-virt… #defaced #cibercrimen #hackeo

CarloSeisdedos's tweet image. El atacante de la web de @CCOO, aka &apos;farlopa&apos;...ha publicado una guia con los pasos que realizó para aprovechar las vulnerabilidades en el diseño e implementación de su web....
Veremos que pasa con los datos de los afiliados..
farlopa.noblogs.org/mariscada-virt…
#defaced #cibercrimen #hackeo


I earned $1,300 for my submission on @bugcrowd bugcrowd.com/alexvec #ItTakesACrowd IDOR -> High /P2 impact bounty Yet another record as single bounty payment! 🐞 #BugBounty

alex_vec's tweet image. I earned $1,300 for my submission on @bugcrowd bugcrowd.com/alexvec #ItTakesACrowd 

IDOR -&amp;gt; High /P2 impact bounty
Yet another record as single bounty payment! 🐞

#BugBounty

I earned $200 for my submission on @bugcrowd bugcrowd.com/alexvec #ItTakesACrowd


My first High/P2 vulnerability found! After some days receiving over 10+ dupes on P3s and some other P3s being assesed, I finally found a high impact vulnerability on a target. s/o @Bugcrowd triaging team for being so smooth. #bugbounty #CyberSecurity

alex_vec's tweet image. My first High/P2 vulnerability found!

After some days receiving over 10+ dupes on P3s and some other P3s being assesed, I finally found a high impact vulnerability on a target.  

s/o @Bugcrowd triaging team for being so smooth.
#bugbounty #CyberSecurity

Burp Suite

🚨 Giveaway day 2: 👉 Follow us @bugcrowd 💟 Like this post 🔂 Retweet with your all-time favorite tool



Alex reposted

Ok fam. I’m giving away TWO free tickets to my course which takes place in two/three weeks. All you have to do to win is like, retweet this tweet, and reply with “tbhmlive.com!” I’ll pick winners next week! If you haven’t seen my course, check out the link!


Happy to announce I am participating at @Bugcrowd's HackerCup! This is my first hacking event so it's very exciting and I will try my best

alex_vec's tweet image. Happy to announce I am participating at @Bugcrowd&apos;s HackerCup!

This is my first hacking event so it&apos;s very exciting and I will try my best

Alex reposted

thanks! i use my own tool for JS monitoring :-) check out @alex_vec blog post about monitoring JS files alexvec.github.io/posts/monitori…


I earned $50 for my submission on @bugcrowd bugcrowd.com/alexvec #ItTakesACrowd First time searching for bugs in BugCrowd! #bugbounty #cybersecurity #appsec


Monitoring JS files for Bug Hunting! 🐞 Today I want to share an interesting method of finding potential bugs, leaked secrets or sensitive information from websites, by monitoring its client-side JavaScript files. alexvec.github.io/posts/monitori… #BugBounty #pentesting #appsec


Passing the Offensive Security Certified Professional (OSCP) with 110/100 points, here's how I did it! I wrote a detailed post on my blog explaining my journey through the OSCP! alexvec.github.io/posts/perfecti…

alexvec.github.io

Perfecting the OSCP with 110/100 score: Here’s my journey

Beginning with the Basics


Alex reposted

Answering my web #AppSec interview question from the other day! Question 55: What is formula injection and how might it be exploited? Formula injection, also known as "CSV Injection" occurs when an attacker can insert Excel-like formula (e.g. =1+1) into an application's CSV…


First couple of weeks bug bounty hacking and received $1200 in bounties! Three Medium reports crushed 🥳🐞 @Hacker0x01 #bugbounty #bugbountyhunter

alex_vec's tweet image. First couple of weeks bug bounty hacking and received $1200 in bounties! 
Three Medium reports crushed 🥳🐞

@Hacker0x01  #bugbounty #bugbountyhunter

Loading...

Something went wrong.


Something went wrong.