MrB0LTv2 (@mrb0ltv2) 's Twitter Profile
MrB0LTv2

@mrb0ltv2

OSCP | CEH | Synack Red Team | Hall_Of_Fame - Evernote, Blinksale, Block port, Ford, HackTheBox 🤗

ID: 232594722

linkhttp://mrbolt.github.io calendar_today31-12-2010 16:29:57

410 Tweet

372 Followers

1,1K Following

The Hacker News (@thehackersnews) 's Twitter Profile Photo

ApkUrlGrep: A simple open-source tool to quickly extract endpoints from APK files. Github: github.com/ndelphit/apkur… via @delphit33 and Gerben Javado #pentesting #hackerone #infosec

ApkUrlGrep: A simple open-source tool to quickly extract endpoints from APK files.

Github: github.com/ndelphit/apkur…

via @delphit33 and <a href="/gerben_javado/">Gerben Javado</a>

#pentesting #hackerone #infosec
Hack3rScr0lls (@hackerscrolls) 's Twitter Profile Photo

You asked for something about OAuth — we did. Here is a mindmap about hacking OAuth 2.0. We tried to cover all possible ways even with low impact. Our inspiration was homakov.blogspot.com/search?q=oauth Thanks to Egor Homakov for outstanding articles. #BugBountyTip #CyberSecurity #BugBounty

You asked for something about OAuth — we did.
 
Here is a mindmap about hacking OAuth 2.0. We tried to cover all possible ways even with low impact.

Our inspiration was homakov.blogspot.com/search?q=oauth
Thanks to <a href="/homakov/">Egor Homakov</a> for outstanding articles.

#BugBountyTip #CyberSecurity #BugBounty
Serena (@serenamourey) 's Twitter Profile Photo

Hey InfoSec friends! What was the resource (blog, book, etc.) that had the biggest impact on your skill development? Was there anyone who inspired you to learn a particular topic?

Luan Herrera (@lbherrera_) 's Twitter Profile Photo

A tricky URL spoofing bug that I reported two years ago to Mozilla and it is still working: spoof.lbherrera.me (reproducible only on Firefox).

Abhishek Karle (@abhishekkarle3) 's Twitter Profile Photo

I just published How I was able to change victim’s password using IDN Homograph Attack link.medium.com/zSmBpWKg27 Thanks to @musiclouderlml for sharing #bugbountytips

Chirag Gupta (@chiraggupta8769) 's Twitter Profile Photo

SQL Injection in Email Address (username) - by Dimaz Arno Tips: "injection_here"[at]email[dot]com Bypassing Email Filter which leads to SQL Injection: medium.com/@dimazarno/byp…

SQL Injection in Email Address (username) - by <a href="/dimazarno/">Dimaz Arno</a>

Tips: "injection_here"[at]email[dot]com

Bypassing Email Filter which leads to SQL Injection:

medium.com/@dimazarno/byp…
Harsh Bothra (@harshbothra_) 's Twitter Profile Photo

Burp Extensions that I use: (1/n) 1. Autorize - To Test BACs 2. Burp Bounty - Profile-based Scanner 3. Active Scan++ - Add more power to Burp's Active Scanner 4. AuthMatrix - Authorization/PrivEsc Checks 5. Broken Link Hijacking - For BLH #bugbountytips #bugbounty

👑 OFJAAAH 👑 (@ofjaaah) 's Twitter Profile Photo

👑 How did I find a critical today? well as i said it was very simple, using shodan and jaeles. 🔥shodan domain domain| awk '{print $3}'| httpx -silent | anew | xargs -I@ jaeles scan -c 100 -s /jaeles-signatures/ -u @ 🔥 @zeroc00I j3ssie (Ai Ho) #bugbountytip #KingOfBugBountyTips

👑 How did I find a critical today? well as i said it was very simple, using shodan and jaeles.

🔥shodan domain domain| awk '{print $3}'|  httpx -silent | anew | xargs -I@ jaeles scan -c 100 -s /jaeles-signatures/ -u @ 🔥

@zeroc00I <a href="/j3ssiejjj/">j3ssie (Ai Ho)</a> 
#bugbountytip #KingOfBugBountyTips
HolyBugx (@holybugx) 's Twitter Profile Photo

My File Upload Checklist, detailed version of Ahsan Khan checklist, and also some extra methods I personally use and gathered during the time. #BugBounty #BugBountyTip #BugBountyTips #TogetherWeHitHarder #InfoSec

My File Upload Checklist, detailed version of <a href="/hunter0x7/">Ahsan Khan</a> checklist, and also some extra methods I personally use and gathered during the time.

#BugBounty #BugBountyTip #BugBountyTips #TogetherWeHitHarder #InfoSec
Vidya (@journovidya) 's Twitter Profile Photo

What amazing talent in माझी Mumbai, आपली BMC run Tamil school at Aarey Aaditya Thackeray #tamilrappers #tamil #talent #rapper #sound #beatbox #rapping #groupsingers #singers #kids #beatboxing #lockdown #talent #Surviving #Covid_19 #school #students

Nikhil Mittal (@nikhil_mitt) 's Twitter Profile Photo

Month of Azure Red Teaming Giveaway! I am giving away two seats of Altered Security Attacking and Defending Azure (CARTP). Please Repost, Like and Reply to participate. I will announce two random winners tomorrow. alteredsecurity.com/online-labs #RedTeam #Pentesting #Azure

Month of Azure Red Teaming Giveaway!

I am giving away two seats of <a href="/AlteredSecurity/">Altered Security</a>  Attacking and Defending Azure (CARTP).  Please Repost, Like and Reply to participate. I will announce two random winners tomorrow. 

alteredsecurity.com/online-labs

#RedTeam #Pentesting #Azure
Muqsit 𝕏 (@mqst_) 's Twitter Profile Photo

⚡ Mastering GraphQL Exploitation: How to exploit GraphQL endpoints for bug bounty & profit. 1. yeswehack.com/learn-bug-boun… 2. book.hacktricks.xyz/network-servic… #infosec

⚡ Mastering GraphQL Exploitation: How to exploit GraphQL endpoints for bug bounty &amp; profit.

1. yeswehack.com/learn-bug-boun…
2. book.hacktricks.xyz/network-servic…

#infosec