Peter M (@pmnh_) 's Twitter Profile
Peter M

@pmnh_

aka pmnh / ex-Security researcher / Synack #1 SRT 2022-2023 / Synack, HackerOne, BC / Deep recon / source code analysis. Opinions my own, not employer.

ID: 1400463711232397327

linkhttps://www.pmnh.site calendar_today03-06-2021 14:45:49

621 Tweet

2,2K Followers

569 Following

Peter M (@pmnh_) 's Twitter Profile Photo

If I'm doing deep research/recon it seems like 20 hours is the magic number where "this target is impossible" changes to "this target kind of makes sense" and then I start finding vulnerabilities. Don't give up and don't shy away from things that look hard on the surface!

huli (@aszx87410) 's Twitter Profile Photo

I haven't played CTF for a while cause I am busy with other stuff like new job and moving to a new place(I am in Tokyo now!). But I still see some interesting challenges on twitter from time to time and really want to take a note, so here is it blog.huli.tw/2023/12/03/en/…

Peter M (@pmnh_) 's Twitter Profile Photo

Encountered another Java RCE yesterday requiring a reflection-based payload to bypass WAF and server-side filtering. In both .NET and JVM-based languages, learn how to build one-liners with reflection, guaranteed it will pay off when you encounter a tough WAF.

Mustafa Can İPEKÇİ (@mcipekci) 's Twitter Profile Photo

While exploiting SQL injection issues, knowing the capabilities of the target DBMS is key which is what I'm always saying. I will try to explain how to find tables with valid data on IBM DB2 targets .#bugbountytip 1/n

Peter M (@pmnh_) 's Twitter Profile Photo

During bug hunting, what error message gives you an adrenaline rush? Mine is "you have an error in your SQL syntax" 🔥

Peter M (@pmnh_) 's Twitter Profile Photo

Starting my next full-time job tomorrow. It's been a great almost 1.75 year run in full-time BB. Thanks to everyone who hit me up for collabs, supported me, and the amazing friends around the world I've met. This community is full of great people and kindness. Y'all are awesome!

Nagli (@galnagli) 's Twitter Profile Photo

The damage of VDP programs and their Incentivization is far greater than giving some hunters "points" for farming none-bugs that they can later boast on their CV's, I believe it might actually ruin Bug Bounty platforms in the near future, Let's explore the facts 📜 So VDP's, as

The damage of VDP programs and their Incentivization is far greater than giving some hunters "points" for farming none-bugs that they can later boast on their CV's, I believe it might actually ruin Bug Bounty platforms in the near future, Let's explore the facts 📜

So VDP's, as