0xn3va (@0xn3va) 's Twitter Profile
0xn3va

@0xn3va

github.com/0xn3va | hackerone.com/0xn3va

ID: 1090853017644085248

calendar_today31-01-2019 06:03:21

33 Tweet

160 Followers

99 Following

xchg justin,justin (@justinsteven) 's Twitter Profile Photo

I've published some work regarding Git security 🥳 It discusses the burying of repos within repos, exploiting IDEs (by opening a directory), shell prompts (by cd'ing into a directory) and Git pillaging tools (pwn the attacker who tries to steal your .git) github.com/justinsteven/a…

0xn3va (@0xn3va) 's Twitter Profile Photo

Hey Facebook Security how do you suppose that the researchers will report vulnerabilities to BB if the submit requires an fb account, that you suspend during creation? Don't you think in case of any critical vulnerabilities, the time of communication with support will be expensive?

Ron Chan (@ngalongc) 's Twitter Profile Photo

It has been a while since my last blog post. Today I'm starting a new blog series about smart contracts security. It's going to be fun! This is my first blog of the series, Price manipulation in EVM chains. ngailong.com/smart-contract…

0xn3va (@0xn3va) 's Twitter Profile Photo

For the last six months I have been researching Github Actions and not only, here you can find my notes✌️github.com/0xn3va/cheat-s… 0xn3va.gitbook.io/cheat-sheets/

Intigriti (@intigriti) 's Twitter Profile Photo

[3️⃣] JWT Cheatsheet by @0x_n3va This cheatsheet is so incredibly complete 🤯 It covers EVERYTHING there is to know about JWT tokens! Reading through this will help you master the topic for sure! 💪 👇 0xn3va.gitbook.io/cheat-sheets/w…

Uranium238 (@uraniumhacker) 's Twitter Profile Photo

We found a way to disclose organization's secrets in GitHub and got access to part of GitHub itself. Checkout the blog: ophionsecurity.com/blog/access-or… #BugBounty #Vulnerability

0xn3va (@0xn3va) 's Twitter Profile Photo

I've updated my GitHub Actions security cheat sheets and added new cases that could lead to serious vulnerabilities, enjoy! 0xn3va.gitbook.io/cheat-sheets/c… github.com/0xn3va/cheat-s…

I've updated my GitHub Actions security cheat sheets and added new cases that could lead to serious vulnerabilities, enjoy!

0xn3va.gitbook.io/cheat-sheets/c…

github.com/0xn3va/cheat-s…
GitHub Security Lab (@ghsecuritylab) 's Twitter Profile Photo

How do static analysis tools detect vulnerabilities in software? Learn more about the fundamentals of static analysis and security research, and challenge yourself with exercises in the first part of CodeQL Zero to Hero series by /* BlazingWind */ github.blog/2023-03-31-cod…

RyotaK (@ryotkak) 's Twitter Profile Photo

Published a write-up about the vulnerability which could expose the access token of GitHub Staff. blog.ryotak.net/post/github-ac…

0xn3va (@0xn3va) 's Twitter Profile Photo

I completely updated Content Security Policy (CSP) Cheat Sheet, check it out 0xn3va.gitbook.io/cheat-sheets/w… Subscribe to releases at GitHub to track all updates in my Application Security Cheat Sheets github.com/0xn3va/cheat-s…

Christophe Tafani-Dereeper (@christophetd) 's Twitter Profile Photo

Using AWS IAM roles from GitHub Actions with OpenID Connect? Make sure you set a condition on the JWT subject in your trust policy! Read how we found vulnerable roles in the wild, including from the UK government! securitylabs.datadoghq.com/articles/explo…

Using AWS IAM roles from GitHub Actions with OpenID Connect? Make sure you set a condition on the JWT subject in your trust policy!

Read how we found vulnerable roles in the wild, including from the UK government!

securitylabs.datadoghq.com/articles/explo…
0xn3va (@0xn3va) 's Twitter Profile Photo

If you were looking for secure coding best practices in the form of specific requirements, take a look at my project Application Security Handbook which I released recently. Cheers ✌️ GitHub: github.com/0xn3va/applica… GitBook: 0xn3va.gitbook.io/application-se…

🦊 GitLab (@gitlab) 's Twitter Profile Photo

❓Have you ever wanted to get in the mind of a hacker? Well, here's your chance during our Ask a Hacker AMA next week on September 8th. ✏️ Sign up and drop your questions here. bit.ly/3qNOChj

❓Have you ever wanted to get in the mind of a hacker? Well, here's your chance during our Ask a Hacker AMA next week on September 8th. 

✏️ Sign up and drop your questions here. bit.ly/3qNOChj
0xn3va (@0xn3va) 's Twitter Profile Photo

Special thanks to the 🦊 GitLab security team for having me on the GitLab Ask a Hacker AMA! It was great! youtube.com/watch?v=aJagtR…

🦊 GitLab (@gitlab) 's Twitter Profile Photo

ICYMI: #bugbounty hunter 0xn3va joined our AMA and shared insights on why he hacks, his process for identifying bugs and advice for new hackers. bit.ly/3LIivXq