πŸ‡·πŸ‡΄ cristi(@CristiVlad25) 's Twitter Profileg
πŸ‡·πŸ‡΄ cristi

@CristiVlad25

ID:2188880010

calendar_today11-11-2013 19:12:27

10,9K Tweets

38,4K Followers

151 Following

πŸ‡·πŸ‡΄ cristi(@CristiVlad25) 's Twitter Profile Photo

Where do you see yourself as you progress through your cybersecurity journey?

Me: I see myself reaching a management position, with the caveat that I will never take my hands off pentesting or cyber-engineering. I couldn't live without the technical.

…

account_circle
πŸ‡·πŸ‡΄ cristi(@CristiVlad25) 's Twitter Profile Photo

From recent experiments, knowing how to talk to chatgpt4 in its own language (prompt engineering) can leverage so much good stuff, not only technically but also in all aspects of life.

For example, I often use it to find patterns that I could only find by reading 10 different…

account_circle
πŸ‡·πŸ‡΄ cristi(@CristiVlad25) 's Twitter Profile Photo

In my experience, web app scanners can't match manual testing (i.e. looking at requests and responses using Burp Suite or ZAP or the like).

While they may offer some value, their high cost often doesn't justify their performance.

Curious to hear other perspectives of real-world…

account_circle
πŸ‡·πŸ‡΄ cristi(@CristiVlad25) 's Twitter Profile Photo

How do you use dev tools in your pentests?

Me:

- for client-side code analysis (it's convenient because it's beautified)
- for DOM inspection
- for storage analysis
- for dynamic testing (I'm still trying to learn this)

account_circle
πŸ‡·πŸ‡΄ cristi(@CristiVlad25) 's Twitter Profile Photo

What type of bug bounty program is the one you like most? Tell me why you made that choice.

Me: I used to prefer * scopes and would do lots of recon. But it's been a year since I started focusing on single targets (apps).

Instead of going wide and shallow, I prefer going…

account_circle
πŸ‡·πŸ‡΄ cristi(@CristiVlad25) 's Twitter Profile Photo

Let's test this out :)

Also, did anyone find out the hard limit of replies per hour, is it unlimited since they've removed the 30 replies per 3 hours?

Let's test this out :) #chatgpt4 Also, did anyone find out the hard limit of replies per hour, is it unlimited since they've removed the 30 replies per 3 hours?
account_circle
πŸ‡·πŸ‡΄ cristi(@CristiVlad25) 's Twitter Profile Photo

Common places to find SQLi:

- login forms, search bars, URL params, cookies, HTTP headers, and other inputs. These are just a few.

In what other places have you found SQLi?

account_circle
πŸ‡·πŸ‡΄ cristi(@CristiVlad25) 's Twitter Profile Photo

I can see this often in cybersec fellows. A good amount of privacy concerns is healthy, but some people take it to the next level.

account_circle
πŸ‡·πŸ‡΄ cristi(@CristiVlad25) 's Twitter Profile Photo

Here are some of the most important flags I use with feroxbuster. You can probably do something similar with your favorite buster:

1. I filter out status codes: 301,302,404,500. Sometimes 300s and 500s can lead to something, but for me, most often than not, haven't.

2. I have…

account_circle