manuel valdez⛩️ (@saur1n) 's Twitter Profile
manuel valdez⛩️

@saur1n

learning, breaking🔁

ID: 125066770

calendar_today21-03-2010 15:29:19

32,32K Tweet

1,1K Followers

1,1K Following

RogueSMG (@roguesmg) 's Twitter Profile Photo

I spent 3 days on trying to exploit an SSRF. And still FAILED. The Payloads were getting blocked. Started digging a bit and realised there's a TON of bypasses and workarounds out there than I thought: - Simple Headers can sometimes do wonders: X-Forwarded-For, etc. - URL

I spent 3 days on trying to exploit an SSRF. 
And still FAILED.

The Payloads were getting blocked. Started digging a bit and realised there's a TON of bypasses and workarounds out there than I thought:

- Simple Headers can sometimes do wonders: X-Forwarded-For, etc. 
- URL
manuel valdez⛩️ (@saur1n) 's Twitter Profile Photo

Just scored a reward Intigriti, check my profile: app.intigriti.com/profile/saurinn Bug: Out-of-Band XXE injection via importing a file leading to system file read. #HackWithIntigriti

manuel valdez⛩️ (@saur1n) 's Twitter Profile Photo

Swag's here! As part of an active campaign from 12build program run by Intigriti, I managed to find a few cool bugs. Great program, good quality💯 t-shirts #bugbountytips

Swag's here! As part of an active campaign from 12build program run by <a href="/intigriti/">Intigriti</a>, I managed to find a few cool bugs. Great program, good quality💯 t-shirts
#bugbountytips
manuel valdez⛩️ (@saur1n) 's Twitter Profile Photo

Because I haven't had enough time to bug hunting this month I'll invest my time learning PentesterLab. The AuthN/authz and API labs look particularly interesting to me

Because I haven't had enough time to bug hunting this month I'll invest my time learning <a href="/PentesterLab/">PentesterLab</a>. The AuthN/authz and API labs look particularly interesting to me
RogueSMG (@roguesmg) 's Twitter Profile Photo

SSRF *almost* working? Getting the blind callbacks, maybe even control the path, but the target app just doesn't parse or reflect the *content* from your exfil server? The assumption usually is: "It's a WAF, blocking SSRF. I'll tear it apart." Rather, the Reality is: Nope, not

manuel valdez⛩️ (@saur1n) 's Twitter Profile Photo

Have you had multiple bugs on the backlog but can submit them because the program has been suspended for a few days? Anxiety 🚀

manuel valdez⛩️ (@saur1n) 's Twitter Profile Photo

Now we're moving! I'm learning a ton PentesterLab. I subscribed for the Pro just to get my hands on SAML attacks and so far it's been really insightful

Now we're moving! I'm learning a ton <a href="/PentesterLab/">PentesterLab</a>. I subscribed for the Pro just to get my hands on SAML attacks and so far it's been really insightful
manuel valdez⛩️ (@saur1n) 's Twitter Profile Photo

Program's closing 😀😃😄😁😆😅🔫 I'm left with two crits on draft... I guess this is one of those "First time?" meme moments