McG (@cybermcg) 's Twitter Profile
McG

@cybermcg

Cyber Security, Pen Tester & Bug Bounty Hunter. 🇬🇧

ID: 1454522335118168070

linkhttps://hackerone.com/mcgregor2023 calendar_today30-10-2021 18:55:36

218 Tweet

188 Followers

1,1K Following

McG (@cybermcg) 's Twitter Profile Photo

Had 4 critical vulnerabilities get resolved today for NHS England NHS England Transformation HackerOne resolved within 1 week. Nice to be able to help and ensure that client data doesn’t get exposed

McG (@cybermcg) 's Twitter Profile Photo

Still can’t believe the company who produces ozempic who had exposed admin credentials (which worked) refused to payout or publish acknowledge it… company is worth 500 billion 😂 elite as ever, patch and say thanks moving on

Rt Hon Sir Grant Shapps (@grantshapps) 's Twitter Profile Photo

It might sound impossible but the UK will very soon have lasers that shoot down missiles & drones at the speed of light. How? Because we’ve reformed military procurement to speed up projects that could’ve taken decades, to urgently get the new weapons we need to defend Britain.

McG (@cybermcg) 's Twitter Profile Photo

Anyone have any reading recommendations on OS / PHP command injections, believe I found in a crypto exchange with a BBP program but can’t yet verify if I’m correct

McG (@cybermcg) 's Twitter Profile Photo

Found an error in a smart contract, here’s hoping they respond swiftly (official program). First time I’ve tried on blockchain bug bounties

Gi7w0rm (@gi7w0rm) 's Twitter Profile Photo

⚠️Please take a moment to look at #CVE-2024-38036. An unauthenticated remote code execution in the Windows #TCPIP stack. Seems to be a buffer related problem handling IPv6 packets. Affecting Win10, Win11, Server 2008 - 2022. No details yet, but likely bad! msrc.microsoft.com/update-guide/v…

pyn3rd (@pyn3rd) 's Twitter Profile Photo

#CVE-2024-21733, a Tomcat HTTP Request Smuggling vulnerability, reminds me of the HeartBleed vulnerability, which had a profound impact 10 years ago. In both cases, buffer over-reading is the root cause. Attacker is overwhelmingly likely to skim sensitive data from buffer cache.

McG (@cybermcg) 's Twitter Profile Photo

Found a old CVE in one of the largest cookie processing companies, CVE-2020-17519 (PoC) github.com/murataydemir/C… they are charging people to reject cookies… blows my mind, pay to not be tracked. Feels like that should be illegal 😂 Anyway reported & let’s see how they respond.

Found a old CVE in one of the largest cookie processing companies, CVE-2020-17519 (PoC) github.com/murataydemir/C… they are charging people to reject cookies… blows my mind, pay to not be tracked. Feels like that should be illegal 😂 Anyway reported & let’s see how they respond.
McG (@cybermcg) 's Twitter Profile Photo

Proud achievement! Listed in the gov.uk acknowledgments page. …ity-reporting.service.security.gov.uk/acknowledgemen…