πŸ‡·πŸ‡΄ cristi(@CristiVlad25) 's Twitter Profileg
πŸ‡·πŸ‡΄ cristi

@CristiVlad25

ID:2188880010

calendar_today11-11-2013 19:12:27

10,9K Tweets

38,2K Followers

151 Following

πŸ‡·πŸ‡΄ cristi(@CristiVlad25) 's Twitter Profile Photo

What type of bug bounty program is the one you like most? Tell me why you made that choice.

Me: I used to prefer * scopes and would do lots of recon. But it's been a year since I started focusing on single targets (apps).

Instead of going wide and shallow, I prefer going…

account_circle
πŸ‡·πŸ‡΄ cristi(@CristiVlad25) 's Twitter Profile Photo

Let's test this out :)

Also, did anyone find out the hard limit of replies per hour, is it unlimited since they've removed the 30 replies per 3 hours?

Let's test this out :) #chatgpt4 Also, did anyone find out the hard limit of replies per hour, is it unlimited since they've removed the 30 replies per 3 hours?
account_circle
πŸ‡·πŸ‡΄ cristi(@CristiVlad25) 's Twitter Profile Photo

Common places to find SQLi:

- login forms, search bars, URL params, cookies, HTTP headers, and other inputs. These are just a few.

In what other places have you found SQLi?

account_circle
πŸ‡·πŸ‡΄ cristi(@CristiVlad25) 's Twitter Profile Photo

I can see this often in cybersec fellows. A good amount of privacy concerns is healthy, but some people take it to the next level.

account_circle
πŸ‡·πŸ‡΄ cristi(@CristiVlad25) 's Twitter Profile Photo

Here are some of the most important flags I use with feroxbuster. You can probably do something similar with your favorite buster:

1. I filter out status codes: 301,302,404,500. Sometimes 300s and 500s can lead to something, but for me, most often than not, haven't.

2. I have…

account_circle
πŸ‡·πŸ‡΄ cristi(@CristiVlad25) 's Twitter Profile Photo

Here's my Autorize configuration, as some of you asked for it. It's quite simple:

1. I uncheck 'Ignore 304/204' because these often leverage good results.

2. Alongside the default interception filters, I add 2 more to minimize noise:

- Scope items only
- Ignore…

Here's my Autorize configuration, as some of you asked for it. It's quite simple: 1. I uncheck 'Ignore 304/204' because these often leverage good results. 2. Alongside the default interception filters, I add 2 more to minimize noise: - Scope items only - Ignore…
account_circle
πŸ‡·πŸ‡΄ cristi(@CristiVlad25) 's Twitter Profile Photo

What are your top tools for web app pentesting?

Mine are:
1. Burp Suite (couldn't imagine life without it).
2. Feroxbuster (my buster of choice).
3. Gau (I use it infrequently).

account_circle
πŸ‡·πŸ‡΄ cristi(@CristiVlad25) 's Twitter Profile Photo

The best ideas I ever had came into my mind while walking, brushing my teeth, taking a shower, or taking a dump.

I'm not sure why but there's probably a neuroscience explanation.

account_circle
πŸ‡·πŸ‡΄ cristi(@CristiVlad25) 's Twitter Profile Photo

What's your experience with Burp for helping you find SQLi?

I always found SQLi manually, but I think that some sort of automation/extension could help me cover more ground.

Please share so that others and myself can learn.

account_circle
πŸ‡·πŸ‡΄ cristi(@CristiVlad25) 's Twitter Profile Photo

If you were to switch careers from cybersecurity, what would you go for and why?

Me: I would dive deep into AI systems and alignment. I do this to a very small extent currently.

account_circle