rabbit hole (@0xbeven) 's Twitter Profile
rabbit hole

@0xbeven

hacker | hackerone.com/0xbeven |bugcrowd.com/0xbeven | ctf tryhackme.com/p/0xbeven | webdev | +5 CVEs

ID: 63067026

calendar_today05-08-2009 07:46:38

2,2K Tweet

618 Takipçi

2,2K Takip Edilen

rabbit hole (@0xbeven) 's Twitter Profile Photo

Past week been intense dive into API, learnt postman,burp,wfuzz,setting crApi, this has been pending for almost a year i started it, kudos to myself APIsec University. credly.com/badges/481e10c… via Credly

Adam Langley (@buildhacksecure) 's Twitter Profile Photo

I released a YouTube video for the first time in nearly 4 years! Watch it if you want some hints and tips for fuzzing and navigating APIs youtu.be/lQEpsrT6O0w?si…

André Baptista (@0xacb) 's Twitter Profile Photo

Once you’ve found a source of user input, the next question is: Where does that input land? That’s your sink. And WordPress plugins expose a ton of them.  Here are 9 to look for 👇 1. update_option() - Stores global config like default roles, site settings, API keys. - Set

Once you’ve found a source of user input, the next question is:

Where does that input land?

That’s your sink. And WordPress plugins expose a ton of them. 

Here are 9 to look for 👇

1. update_option()

- Stores global config like default roles, site settings, API keys.
- Set
Matt Langston (@mattlangston) 's Twitter Profile Photo

banteg That's Sarah Davis. She gave a really nice TEDx Talk last year: "If Code Can Make Music, What Will You Make?" youtube.com/watch?v=ehLb1p…

Jorian (@j0r1an) 's Twitter Profile Photo

Just found an interesting way to bypass some nonce-based CSPs and made a small XSS challenge with an exploitable scenario. See if you can find it before I tell! Source JS: gist.github.com/JorianWoltjer/… URL: greeting-chall.jorianwoltjer.com Found a solution? Please DM to avoid spoilers, thanks!

Just found an interesting way to bypass some nonce-based CSPs and made a small XSS challenge with an exploitable scenario. See if you can find it before I tell!
Source JS:
gist.github.com/JorianWoltjer/…
URL:
greeting-chall.jorianwoltjer.com
Found a solution? Please DM to avoid spoilers, thanks!
Magna (@magn4_) 's Twitter Profile Photo

I have just received this DM from Tim Hackfort and it made my day 😁😁. Seeing that a Bug Hunter faaar better than me was able to find a bug because of my Video is something that i wasn't expecting. Thanks a lot for your DM 🙌🙌

I have just received this DM from <a href="/0xbeven/">Tim Hackfort</a> and it made my day 😁😁.

Seeing that a Bug Hunter faaar better than me was able to find a bug because of my Video is something that i wasn't expecting. 

Thanks a lot for your DM 🙌🙌