Sicarius
@els1carius
Pentester, Web specialized 🪲 Top 30 YesWeHack yeswehack.com/hunters/sicari…
Check my website if you're bored secarius.fr :)
ID: 1045601524230041600
28-09-2018 09:10:04
1,1K Tweet
1,1K Followers
250 Following
Just found a very interesting asset by poking around on Profundis.io 👀 Turned out it belonged to a bug bounty program… And it had an exposed internal Jenkins instance, fully open via a public dashboard 😳 💥 profundis.io #bugbountytips #bugbounty
Hey James Kettle If you have some free time, I pinged you on discord regarding your last (awesome) research paper, I've tried the techniques you've described, and found some weird specificity that you might want to see (and might already know as well) :) thanks !
Another Critical Vulnerability got triaged today a Collaboration with mhmd berro (badcracker) all thanks to Profundis.io alerting system💯🫡
We’ve just landed a $12,000 bounty with Lilian Fellice on a public program at bugcrowd with a nice admin panel access bypass (and few other things :D) ! The asset where this was discovered was, of course, found using Profundis.io 😇
I wrote a (very) short article on how I found a Remote Code Execution, seconds after it got mistakenly deployed by the developers and earned a $$$ bounty for it :D Enjoy! #BugBounty Profundis.io secarius.fr/bugbounty/how_…
Just got a reward for a critical vulnerability submitted on YesWeHack ⠵ with Lilian Fellice -- Improper Access Control - Generic (CWE-284). yeswehack.com/hunters/sicari… #YesWeRHackers
I earned $12,000 for my submission on @bugcrowd bugcrowd.com/ElSicarius #ItTakesACrowd This time with very little help from Profundis.io 😅 -Found a hidden PHP resource using my wordlist generation tool -Found the required param in the error response ->SQLi boolean based on it🔥
Another 4-digit reward with 🇸🇦 Murtada Bin Abdullah (Rood) ! ❤️ 1) Got a new asset alert from Profundis.io 2) Found an “authorized users only” panel 3) Checked JS files and discovered an API key 4) Mapped API endpoints and confirmed the key worked 5) Was able to read, upload, and delete files +