Nagli (@galnagli) 's Twitter Profile
Nagli

@galnagli

Hacker; Bug Bounty Hunter - Top 10 All Time @Hacker0x01, Top 20 @BugCrowd; Live Hacking Events Winner; Cloud Security at @wiz_io

ID: 1205537370331918336

linkhttps://www.shockwave.cloud calendar_today13-12-2019 17:18:09

1,1K Tweet

34,34K Followers

554 Following

Nagli (@galnagli) 's Twitter Profile Photo

Officially Top 5 All-Time on HackerOne's Leaderboard following a 10G💰 bounty from a public program 🤠 hackerone.com/leaderboard/al… #BugBounty

Officially Top 5 All-Time on <a href="/Hacker0x01/">HackerOne</a>'s Leaderboard following a 10G💰 bounty from a public program 🤠 

hackerone.com/leaderboard/al…

#BugBounty
Nagli (@galnagli) 's Twitter Profile Photo

Enjoying a champagne at Grand Hyatt 🇭🇰 lounge and getting collaboration invite from Frans Rosén on Sunday? That’s what dreams are made of 😅 Looking forward to catching up with folks next week in Poland ✈️ #BugBounty

Enjoying a champagne at Grand Hyatt 🇭🇰 lounge and getting collaboration invite from <a href="/fransrosen/">Frans Rosén</a> on Sunday?

That’s what dreams are made of 😅

Looking forward to catching up with folks next week in Poland ✈️

#BugBounty
Nagli (@galnagli) 's Twitter Profile Photo

The new HackerOne policy around CVE reports is concerning, especially for High & Critical ones, as it potentially keeps hundreds of their customers vulnerable to critical ransomware-leading risks by withholding information as they are automatically being set as "Informative."

The new <a href="/Hacker0x01/">HackerOne</a> policy around CVE reports is concerning, especially for High &amp; Critical ones, as it potentially keeps hundreds of their customers vulnerable to critical ransomware-leading risks by withholding information as they are automatically being set as "Informative."
Chris Evans (@scarybeasts) 's Twitter Profile Photo

Thanks Nagli for the feedback. There is no new policy but there was a documentation error, which is now fixed. Keep the feedback coming!

Nagli (@galnagli) 's Twitter Profile Photo

Just got awarded the prestigious P1 Warrior Belt by bugcrowd for submitting over 100 valid critical submissions to companies on their platform, manually and using shockwave.cloud automation engine. Among the companies that I worked with to remediate critical,

Just got awarded the prestigious P1 Warrior Belt by <a href="/Bugcrowd/">bugcrowd</a> for submitting over 100 valid critical submissions to companies on their platform, manually and using shockwave.cloud automation engine.

Among the companies that I worked with to remediate critical,
Nagli (@galnagli) 's Twitter Profile Photo

The Polyfill[.]io backdoor is wild! from what I read all over on Twitter the person who was in charge of the domain sold it to rogue actors back in February and ever since it served as backdoor to hundreds of thousands major websites that had it referenced within a script tag,

The Polyfill[.]io backdoor is wild! from what I read all over on Twitter the person who was in charge of the domain sold it to rogue actors back in February and ever since it served as backdoor to hundreds of thousands major websites that had it referenced within a script tag,
Nagli (@galnagli) 's Twitter Profile Photo

Excited to share some big personal news today, I have joined Wiz to enhance their Risk & Threat Exposure Management and build a new disruptive Risk MDR offering. It's been quite a ride working on Shockwave - External Attack Surface Management. for the past couple of years as a solopreneur and as a

Nagli (@galnagli) 's Twitter Profile Photo

Spent some quality time doing Europe 🚂 hacking and business trip with Joel Margolis (teknogeek) to recharge from Vegas 🎰 shenenigans. Lufthansa First Class Limo 🛫 Prague 💺Vienna 💺 Budapest. We earned 2-3x the trip cost on the 3rd day thanks to #BugBounty

Nagli (@galnagli) 's Twitter Profile Photo

Had the opportunity to share a bit about myself and my Bug Bounty journey during an interview at Louis Vuitton Vuitton's Live Hacking Event, hosted at their main HQ in Paris - big shout-out to YesWeHack ⠵ for hosting a great experience 💎

Nagli (@galnagli) 's Twitter Profile Photo

What a shame by Detectify when they force out the equity of one of their co-founders who pretty much invented the concept of recon 10 years ago. I don’t worry for Frans as he still destroy any high-paying Bug Bounty program and one of the best ever to collab with 🤝

Nagli (@galnagli) 's Twitter Profile Photo

Yay, I was awarded a $20,000 bounty on HackerOne! Honestly, It's been a while since I had a good experience with #BugBounty program and twitter is usually full of rants. I want to thank Zoom BBP Team for their co-operation on the report 💎

Yay, I was awarded a $20,000 bounty on <a href="/Hacker0x01/">HackerOne</a>! 

Honestly, It's been a while since I had a good experience with #BugBounty program and twitter is usually full of rants.

I want to thank <a href="/Zoom/">Zoom</a> BBP Team for their co-operation on the report 💎
Nagli (@galnagli) 's Twitter Profile Photo

Look's like HackerOne reputation points system is officially dead. Create a Self-Serve VDP Bulk submit 5000 reports Bulk resolve Enjoy 35,000 reputation points. With 100% self-serve VDP's, creating separate leaderboards isn't enough - points have to be removed.

Look's like <a href="/Hacker0x01/">HackerOne</a> reputation points system is officially dead. 

Create a Self-Serve VDP
Bulk submit 5000 reports
Bulk resolve
Enjoy 35,000 reputation points.

With 100% self-serve VDP's, creating separate leaderboards isn't enough - points have to be removed.