Reconless (@0xreconless) 's Twitter Profile
Reconless

@0xreconless

Security research, blogs, and videos by @filedescriptor, @ngalongc & @EdOverflow

YouTube: youtube.com/channel/UCCp25…

ID: 1219917042070904832

linkhttps://blog.reconless.com calendar_today22-01-2020 09:37:50

41 Tweet

5,5K Followers

3 Following

FD (@filedescriptor) 's Twitter Profile Photo

New Reconless video! I will talk about how you can abuse IDN and Unicode tricks to make short domains for XSS that has a length limitation, bypass URL/SSRF validation, and many more! youtube.com/watch?v=f1XCvD…

New <a href="/0xReconless/">Reconless</a> video! I will talk about how you can abuse IDN and Unicode tricks to make short domains for XSS that has a length limitation, bypass URL/SSRF validation, and many more!

youtube.com/watch?v=f1XCvD…
Reconless (@0xreconless) 's Twitter Profile Photo

Hacking without Humans - Check out our latest video! Ron Chan & FD talk about how OpenAI's GPT-3 can be applied in cybersecurity. From writing bug bounty reports, identifying spam reports to looking for security logic flaws from the docs. youtube.com/watch?v=n7WOn8…

Reconless (@0xreconless) 's Twitter Profile Photo

As a frequent request, we have made a video covering how to find DOMXSS with DevTools! FD walks through how to use Untrusted Types to turn a manual process into semi-automated. youtube.com/watch?v=CNNCCg…

Reconless (@0xreconless) 's Twitter Profile Photo

Check out our latest video in the 1Password Hacking series, where how Ron Chan found simple API bugs that nobody had looked at after decrypting the protocol!

Reconless (@0xreconless) 's Twitter Profile Photo

Ever wondered how an exploitation and the impact of a JWT bug look like? Check out our latest video, where we exploit a critical JWT without a signature to take over any account without user interaction on Microsoft Outlook! youtube.com/watch?v=t54N4x…

Reconless (@0xreconless) 's Twitter Profile Photo

Don't assume XSS in out-of-scope/sandboxed domains is not worth reporting! Check out how you can escalate it for a bigger impact in this video. youtube.com/watch?v=tl6JCL…

Ron Chan (@ngalongc) 's Twitter Profile Photo

I wrote a tool to help to make the tedious process of authorization testing in GraphQL more enjoyable. Give it a try! You can find it at graphql-dashboard.herokuapp.com How to use guide at youtube.com/watch?v=JJmufW…

The Daily Swig (@dailyswig) 's Twitter Profile Photo

‘Soft skills are the most under-researched area of the bug bounty industry’ – ‘Reconless’ YouTubers (Reconless ) on filling a gap in infosec education portswigger.net/daily-swig/sof…