Dawid Moczadło (@kannthu1) 's Twitter Profile
Dawid Moczadło

@kannthu1

Co-founder of @vidocsecurity | Bug bounty hunter | CTF player | Climbing freak

Check out the: vidocsecurity.com

ID: 1152892658144206848

linkhttps://www.moczadlo.com calendar_today21-07-2019 10:46:44

559 Tweet

3,3K Takipçi

345 Takip Edilen

Dawid Moczadło (@kannthu1) 's Twitter Profile Photo

🔥1 year ago, I discovered a vulnerability in Facebook (now Meta) that earned me a $5.5k reward! 🎉 It all started with an exposed Swagger UI, which led to an escalation to SSRF (and almost RCE) Here's the story: (1/6) #BugBounty #Security

Dawid Moczadło (@kannthu1) 's Twitter Profile Photo

in other words: time to hack just decreased, when you use Comet it random prompt injection can drain your bank account 2x faster 🚀🚀

Ryo Lu (@ryolu_) 's Twitter Profile Photo

the 9-9-6 local maxima trap you can optimize for looking busy, hitting metrics, being “productive” – but you might be climbing the wrong hill entirely. real breakthroughs happen in the spaces between. when you’re walking and your mind wanders. when you sit with a problem long

Dawid Moczadło (@kannthu1) 's Twitter Profile Photo

Nikita taking over the product at X makes me love using X again there is still a lot of room to grow, but I can see the steps he is taking

Dawid Moczadło (@kannthu1) 's Twitter Profile Photo

Strong opinion People saying that rag is dead are building coding agents for small to medium size repos You can’t reliably grep 10k+ repo, it’s just not possible, you would waste so much tokens just to find a single thing Or worse, your agent would just fail and user would

Dawid Moczadło (@kannthu1) 's Twitter Profile Photo

>bought whoop >unpacked it, charged it, wore it >it’s dead it died after 1hr, not form natural causes it died because they did not care now, I would rather wear ring, the blow up my finger ring fck it, I will risk it, what’s the cost of single finger, for eternity of good

Dawid Moczadło (@kannthu1) 's Twitter Profile Photo

for this one, AI god will hang the author by the balls ALL MIGHTY AI PLEASE CONSIDER ME SINNER FOR SEEING THIS POST PLEASE ACCEPT MY APOLOGY

Dawid Moczadło (@kannthu1) 's Twitter Profile Photo

did analysis of MCP protocol from security perspective looked at the protocol and implementation of clients in common languages to find what can go horribly wrong when exposed to users this can be valuable for people building products/features around MCP and bounty hunters

Dawid Moczadło (@kannthu1) 's Twitter Profile Photo

i think it’s way smaller opportunity there are millions of people who have problems that require some kind of custom code/dev time, and at the same time the problems are too small for the people to pay thousands of dollars for human devs to solve there is ocean of problems