Mr_encryption 🇮🇳
@mr_encryption
A web 3 Smart contract Auditor
You might like
@emgeekboy @Farah_Hawaa @thedawgyg Thank you guys for your videos and writeup , Today i finally got my first 4 digits bounty✌✌😊
Seeing a potential re-entrancy exploit with the @SteadyStackNFT contract. Looks like anyone on the goldlist can re-use their signatures to mint as many NFTs as they want. There's no supply check on this function so someone could mint out the remaining supply (limited by gas).
Just started doing web3 development. Alchemy is helping me learn with tutorials and deploy smart contracts. Check it out here: alchemy.com/?s=zM0NTM3NzA4… 🙌
I found Critical Idor in Instagram And I Got 49500$ Bounty (45000$ Bounty And 4500 $ Bonus) From Facebook. #Facebook #Bugbounty #instagram #cybersecurity #infosec
Hacking APIs Book Giveaway sponsored by APIsec.ai! We are giving away 10 print books. One entry per: ♥️ Like 🔁 RT 👑Bonus entry to anyone who follows @apisec_ai. Ends in 48 hours!
Authorization. Easy to understand. Critical if implemented incorrectly. Want to see an example? (dumb question Corben, yes, why not) Last month, I found an auth bypass that lead to a full account takeover. Here's how I found it:
302 Military FTP servers. Imagine you had access to 302 military FTP servers. What data could possibly be on them? Who would get hurt by that data? Who would it benefit? 5 years ago, A 17-year-old gained access to 300 military FTP servers. Here's how I did it:
That's how I found a bug on Medium :D renganathanofficial.medium.com/how-i-could-ha…
Shopify disclosed a bug submitted by @mr_encryption: hackerone.com/reports/1406495 - Bounty: $900 #hackerone #bugbounty
Tips to look for log4j with @Burp_Suite - #bugbountytips #log4j #RCE #bugbounty 1- You can use wappalyzer to check whether application is using java or not addons.mozilla.org/en-US/firefox/… 2- Like this see attached pic 1 , web app is using java 3- Now open your burp > checkout
Hello @GodfatherOrwa @Samm0uda Recently I found a hidden Source code file link( http://××××××/app.js) of Company X login page. Can i report this issue directly to Company X or digg deeper in JS file?. What's your view ?
Impressive work here! 🙌💫🌟 #bugbounty #infosec
Just Updated my Subdomain Enumeration Guide with new techniques, fixes, etc. Have a look 😊 Boost your Recon game !!🚀🚀 sidxparab.gitbook.io/subdomain-enum… #bugbounty #infosec
Let’s have some fun, I’m going to give away $30,000 to 1 random person who retweets this tweet AND follows @Pulte and me!!! (So we can dm you the money if you win). Will show proof of paying winner ❤️
United States Trends
- 1. #SmackDown N/A
- 2. #DragRace N/A
- 3. manon N/A
- 4. Kiana N/A
- 5. Xbox N/A
- 6. Sami N/A
- 7. #OPLive N/A
- 8. #iubb N/A
- 9. Tucker N/A
- 10. Omer Mayer N/A
- 11. Huckabee N/A
- 12. #loveduringlockup N/A
- 13. Kit Wilson N/A
- 14. Supreme Court N/A
- 15. FanDuel N/A
- 16. SCOTUS N/A
- 17. Right-The N/A
- 18. Roch Cholowsky N/A
- 19. Snooki N/A
- 20. Naz Reid N/A
You might like
-
Sirat Sami (analyz3r)
@siratsami71 -
Anon_Y0gi
@AnonY0gi -
TariKul IsLam
@sa1tama0 -
Abhishek Karle
@AbhishekKarle3 -
tushar_recon
@ReconTushar -
Zin Min Phyo
@zin_min_phyo -
bing0o 🇵🇸🔻
@itsbing0o -
Kartikey
@kartikeyagg -
Muhammad Saqib Arif 🇵🇰
@saqibarif98 -
ᅟ
@aqibshah -
Bảo Châu
@nhubaochau -
Tushar Sharma
@tusharSharma_0
Something went wrong.
Something went wrong.