tavi (@0xtavi) 's Twitter Profile
tavi

@0xtavi

Pentesting machine running on coffee, ice-cream and spring water

app.intigriti.com/researcher/pro…

ID: 1254209164458557443

linkhttp://h3k.ro calendar_today26-04-2020 00:42:29

707 Tweet

790 Takipçi

318 Takip Edilen

🇷🇴 cristi (@cristivlad25) 's Twitter Profile Photo

It's likely that soon ChatGPT will have unlimited memory and it will be truly personalized to you. (just a hunch) Until then, upon finishing a conversation you can simply ask it to summarize the conversation in one paragraph highlighting the key points and storing that in

tavi (@0xtavi) 's Twitter Profile Photo

Is there any fuzzing/content discovery tool/option which "auto-calibrates" the discovery response? For example, I want a fuzzing option which will "magically" exclude 20W response after it determines that there are multiple 20W responses received (noise/WAF etc.)

Blaklis (@blaklis_) 's Twitter Profile Photo

The record of my talk at DEFCON is finally out! Go check media.defcon.org/DEF%20CON%2032… to see a few surprising bugs I found in my bug bounty career :p #bugbounty

tavi (@0xtavi) 's Twitter Profile Photo

I finally discovered (after 3 yrs) how to open multiple instances of Burp on MacOs (without using java cli which was horrible btw) Create an automator script with the following `open -n /Applications/Burp\ Suite\ Professional.app` Drag it to the dock and there you go!🎉

Pomme (@pxmme1337) 's Twitter Profile Photo

so last week i had an idea it's a recon competition kind of game new round every 24hrs check the FAQ section! hope you'll like it ❤️ recon-royale.com

so last week i had an idea

it's a recon competition kind of game

new round every 24hrs

check the FAQ section!

hope you'll like it ❤️

recon-royale.com
Gareth Heyes \u2028 (@garethheyes) 's Twitter Profile Photo

The DEF CON video of my talk 'Splitting the Email Atom' is finally here! 🚀 Watch me demonstrate how to turn an email address into RCE on Joomla, bypass Zero Trust defences, and exploit parser discrepancies for misrouted emails. Don’t miss it: portswigger.net/research/split…

Gareth Heyes \u2028 (@garethheyes) 's Twitter Profile Photo

Want to discover advanced XSS vectors like this? I'll be presenting "Digging for XSS Gold: Unearthing Browser Quirks with Shazzer" live online at 16:00 UTC November 7th portswigger.net/research/talks

Want to discover advanced XSS vectors like this? I'll be presenting "Digging for XSS Gold: Unearthing Browser Quirks with Shazzer" live online at 16:00 UTC November 7th

portswigger.net/research/talks
Inti De Ceukelaire (@intidc) 's Twitter Profile Photo

‼️TAMRI/AGADIR - CALL FOR HELP: My nephew Dries went missing near Tamri (Agadir) in Morocco since Nov 19th. If you know anyone that is currently near Taghazout or the Sous-Massa National Park, please share this with them. Someone must have seen him and time is ticking to get him

‼️TAMRI/AGADIR - CALL FOR HELP: My nephew Dries went missing near Tamri (Agadir) in Morocco since Nov 19th. If you know anyone that is currently near Taghazout or the Sous-Massa National Park, please share this with them. Someone must have seen him and time is ticking to get him
tavi (@0xtavi) 's Twitter Profile Photo

feels so fcking powerful to run a LLM locally on a personal laptop lol although my m1 mac burns after 2 questions sent to 14b deepseek, it's still mindblowing

tavi (@0xtavi) 's Twitter Profile Photo

It looks like humanity is finally recovering. We got 4o image generation and everyone is spamming ghibli stuff. 🤣🤣

sw33tLie (@sw33tlie) 's Twitter Profile Photo

I've recently put more work into my ffuf fork, uff, and I think every ffuf user should at least give it a try - and maybe even switch to it. Here's why, in a #bugbounty 🧵

I've recently put more work into my ffuf fork, uff, and I think every ffuf user should at least give it a try - and maybe even switch to it.

Here's why, in a #bugbounty 🧵
tavi (@0xtavi) 's Twitter Profile Photo

All you need to find bugs is watching HTTP requests and playing with match and replace Burp Suite rules. KISS! (keep it super simple)