nerdByt's profile picture. ๏ผจ๏ฝ๏ฝƒ๏ฝ‹๏ฝ…๏ฝ’ โ–ซ Bug Bounty Hunter โ–ซ C|EHv12 โ–ซ

๐•Š๐Ÿœ๐•ž๐Ÿœ๐Ÿ›๐• ๐Ÿ˜๐•ฉ๐Ÿœ โ˜ 

@nerdByt

๏ผจ๏ฝ๏ฝƒ๏ฝ‹๏ฝ…๏ฝ’ โ–ซ Bug Bounty Hunter โ–ซ C|EHv12 โ–ซ

Fijado

Found a CORS misconfiguration that Expose User PII & session Token. ๐Ÿ”โžก๏ธ๐Ÿšจ Off to triage โ€” letโ€™s hope for the best. โšก๐Ÿ™โœ… #cors #misconfiguration

nerdByt's tweet image. Found a CORS misconfiguration that Expose User PII & session Token. ๐Ÿ”โžก๏ธ๐Ÿšจ
Off to triage โ€” letโ€™s hope for the best. โšก๐Ÿ™โœ…

#cors #misconfiguration

โ€œInstagramโ€™s โ€˜View-Onceโ€™ isnโ€™t as private as you thinkโ€ฆ Watch before they patch it โš ๏ธ๐Ÿ“ธโ€ youtu.be/CU6RYM57os4

nerdByt's tweet card. Instagram โ€œView-Once-Imageโ€ Exploit โ€” Privacy Warning 2025

youtube.com

YouTube

Instagram โ€œView-Once-Imageโ€ Exploit โ€” Privacy Warning 2025


Hey @grok based on my tweet history - What is my physical age? What is my mental age? What is my IQ? What is my EQ? What is my ideal profession? What is my worst nightmare?


๐Ÿ”ฅโœ๏ธ All in One JS Leak Hunting โš ๏ธ Read โ€œHunting Sensitive Data Leaks in JavaScriptโ€Šโ€”โ€ŠAn Advanced Recon Guideโ€œ by Farhan Alam on Medium: samael0x4.medium.com/hunting-sensitโ€ฆ


"Reconnaissance is not just about finding what's there; it's about discovering what shouldn't be there."* - samael_0x4


๐•Š๐Ÿœ๐•ž๐Ÿœ๐Ÿ›๐• ๐Ÿ˜๐•ฉ๐Ÿœ โ˜  reposteรณ

From Image Upload to Account Takeoverโ€Šโ€”โ€ŠChaining Upload, Storage, and CORS Issues in a Real Pentest medium.com/@shazilrao620/โ€ฆ #bugbounty #bugbountytips #bugbountytip


๐Ÿซก๐Ÿง  Enumeration is ๐Ÿ”‘ | dnsx -silent (combine with dnsx)

Me: I canโ€™t find subdomains ๐Ÿ˜ฉ ffuf: Hold my wordlist... well you can Combine with dnsx for validation!!!

Freyxfi's tweet image. Me: I canโ€™t find subdomains ๐Ÿ˜ฉ
ffuf: Hold my wordlist...
well you can Combine with dnsx for validation!!!


๐•Š๐Ÿœ๐•ž๐Ÿœ๐Ÿ›๐• ๐Ÿ˜๐•ฉ๐Ÿœ โ˜  reposteรณ

๐Ÿ”ฅ XSS Filter Bypass Cheatsheet ๐Ÿ”ฅ ๐Ÿš€ Basic Payloads: ๐ŸŸข <script>prompt(1)</script> ๐ŸŸข "><script>prompt(1)</script> ๐ŸŸข <img src=x onerror=prompt(1)> ๐ŸŸข <svg/onload=prompt(1)> ๐ŸŸข <body onload=prompt(1)> ๐ŸŸข <iframe src="javascript:prompt(1)"></iframe> ๐ŸŸข <aโ€ฆ


"Leveling Up! Just received my first THREE private invites for bug bounty hunting!" @BugBase Time to dig deep, hack smart, and hun7 those bugs #BugBounty #bugbase #hackerone #bugcrowd #private #invite #Hunting

nerdByt's tweet image. &quot;Leveling Up! 
Just received my first THREE  private invites for bug bounty hunting!&quot;  @BugBase
Time to dig deep, hack smart, and hun7 those bugs

#BugBounty #bugbase #hackerone #bugcrowd #private #invite #Hunting
nerdByt's tweet image. &quot;Leveling Up! 
Just received my first THREE  private invites for bug bounty hunting!&quot;  @BugBase
Time to dig deep, hack smart, and hun7 those bugs

#BugBounty #bugbase #hackerone #bugcrowd #private #invite #Hunting
nerdByt's tweet image. &quot;Leveling Up! 
Just received my first THREE  private invites for bug bounty hunting!&quot;  @BugBase
Time to dig deep, hack smart, and hun7 those bugs

#BugBounty #bugbase #hackerone #bugcrowd #private #invite #Hunting

๐•Š๐Ÿœ๐•ž๐Ÿœ๐Ÿ›๐• ๐Ÿ˜๐•ฉ๐Ÿœ โ˜  reposteรณ

A Russian hacker recently posted 20 million OpenAI ChatGPT user login credentials on the hacking platform "BreachForums," raising concerns over security breaches in services like DeepSeek and Kimi. #CyberSecurity #DataBreach ift.tt/S7mHyNO


๐•Š๐Ÿœ๐•ž๐Ÿœ๐Ÿ›๐• ๐Ÿ˜๐•ฉ๐Ÿœ โ˜  reposteรณ

Authentication method - Brute Force โœ…

bountywriteups's tweet image. Authentication method - Brute Force โœ…

๐•Š๐Ÿœ๐•ž๐Ÿœ๐Ÿ›๐• ๐Ÿ˜๐•ฉ๐Ÿœ โ˜  reposteรณ

Deepseek isnโ€™t a US company, so it must be evil and stealing dataโ€ฆ maybe even out to get your mom, lol. Anyway, this video doesnโ€™t prove anything. These requests could just be pings or fetching static files since the servers are in China.

Is DeepSeek lying to you? Let's find out using Wireshark ... #deepseek #ai #privacy #cybersecurity #wireshark #data #openai #chatgpt



United States Tendencias

Loading...

Something went wrong.


Something went wrong.