tommyboyhacking's profile picture. Hack/Planets 🪐

TommyBoy

@tommyboyhacking

Hack/Planets 🪐

Pinned

While the time in bug bounty has been fun, I think it's time to re-evaluate my opportunities a bit. I enjoy finding critical vulnerabilities in websites but really I'll attack anything you got. H1 profile in my bio as a resume if your org could use a test or full timer.


TommyBoy reposted

Let's talk manual testing for IDORs. I have pasted a payload from a redacted T-Mobile API below. It does not have a bug (that I am aware of) on it, I want to use this for educational purposes because its a great teaching opportunity. A: This is a URI path parameter representing…

the_IDORminator's tweet image. Let's talk manual testing for IDORs. I have pasted a payload from a redacted T-Mobile API below. It does not have a bug (that I am aware of) on it, I want to use this for educational purposes because its a great teaching opportunity.

A: This is a URI path parameter representing…

Bro is solo carrying Bug Bounty twitter rn

Classic IDOR, but lets talk SSRF: /pdfEngine/v2/prepaidStatement?consNo={consumer}&month=April&year=2025 One of the things I've been seeing more (not less) of, is developers passing parameter values like this {consumer} into back end paths. So lets assume this, on the back…



TommyBoy reposted

Scariest thing I could think of. Happy Halloween!

alxbrsn's tweet image. Scariest thing I could think of. Happy Halloween!

Just had a crit downgraded and paid out as high due to the employee "accidentally" triggering the blind xss payload. Idk about y'all but generally speaking employees don't purposely go around triggering XSS payloads so I'm not sure what that has to do with anything.


Manifesting LHE's and MVH's in near future


The state of bug bounty summed up in an image:

tommyboyhacking's tweet image. The state of bug bounty summed up in an image:

TommyBoy reposted

Man do some fuck shit bingo bango bongo bish bash bosh


can't focus on shit


Doth all the critical vulns be fixed but doth all the bounties be unpaid


peach tea / hacker koozies

tommyboyhacking's tweet image. peach tea / hacker koozies

TommyBoy reposted

i’ve started rejecting all cookies instead of accepting them. idek what it means but i’ve had enough


United States Trends

Loading...

Something went wrong.


Something went wrong.