toxicsolution's profile picture. OSCE3 | OSED | OSEP | OSWE | OSWA | OSCP | BSCP | CCNA | Bug Bounty Hunter | Security Researcher

/home/toxicat0r

@toxicsolution

OSCE3 | OSED | OSEP | OSWE | OSWA | OSCP | BSCP | CCNA | Bug Bounty Hunter | Security Researcher

I earned $1800 for my submission on @bugcrowd bugcrowd.com/toxicat0r #ItTakesACrowd API takeover (customer data exposed). Several small bugs resulted in one big final payment :)


I earned $600 for my submission on @bugcrowd bugcrowd.com/toxicat0r #ItTakesACrowd Administrator privileges to their API :)


I earned $450 for my submission on @bugcrowd bugcrowd.com/toxicat0r #ItTakesACrowd IDOR exposed customer data. Changed the HTTP method from PUT to GET, shortened down the URL, and finally changed the user ID :)


I earned $300 for my submission on @bugcrowd bugcrowd.com/toxicat0r #ItTakesACrowd IDOR in a private program ;) Got another $150 for no rate limiting as well 🥳


Shoutout to @evildaemond, Ulas, and Viper at @Bugcrowd. Triaging at the speed of light 💯


Just bought myself a couple of new IoT cameras. Not sure if I should laugh or cry :)

toxicsolution's tweet image. Just bought myself a couple of new IoT cameras. Not sure if I should laugh or cry :)

/home/toxicat0r reposted

BendyBear: Novel Chinese Shellcode Linked With Cyber Espionage Group BlackTech unit42.paloaltonetworks.com/bendybear-shel…


/home/toxicat0r reposted

Important Update

CDPROJEKTRED's tweet image. Important Update
CDPROJEKTRED's tweet image. Important Update

/home/toxicat0r reposted

Accessed the computer system of a facility that treats water for about 15,000 people and sought to add a dangerous level of additive to the water supply reuters.com/article/us-usa…


9 exploits published today with my name on them. Super happy about that, but also worrying that some WP plugin developers really don’t care about security. They ignored my requests until I contacted the WP plugin security team directly.

[webapps] WordPress Plugin Supsystic Backup 2.3.9 - Local File Inclusion dlvr.it/RsFRB4



/home/toxicat0r reposted

CVE-2021-3156: Heap-Based Buffer Overflow in Sudo (Baron Samedit) blog.qualys.com/vulnerabilitie… via @qualys


/home/toxicat0r reposted

New campaign targeting security researchers @google blog.google/threat-analysi…


/home/toxicat0r reposted

Don't forget to add "Password2021" to your wordlists.


/home/toxicat0r reposted

I have report from Microsoft about SolarWinds hack, including IoCs. Excerpts in this thread: "Microsoft security researchers recently discovered a sophisticated attack where an adversary inserted malicious code into a supply chain development process.... 1/


Hey @rushisec - I had loads of fun. Thanks! Check it out here: tryhackme.com/jr/watcher

toxicsolution's tweet image. Hey @rushisec - I had loads of fun. Thanks!
Check it out here: tryhackme.com/jr/watcher

Hey @S1lky_1337 - fun machine :) Good find regarding the authentication bypass. Interesting case.

toxicsolution's tweet image. Hey @S1lky_1337 - fun machine :) Good find regarding the authentication bypass. Interesting case.

Stumbled across this awesome tool yesterday. Perfect for OSINT, bug bounty hunting, and so on. Search across a half million git repos 💯 grep.app


/home/toxicat0r reposted

"Sent torsdag kveld fikk VG inn en rekke tips fra lesere som hadde blitt logget inn på andres profiler når de forsøkte å logge seg inn via ID-porten, en felles innloggingsløsning til offentlige tjenester." direkte.vg.no/nyhetsdognet/n…


Loading...

Something went wrong.


Something went wrong.