Nicolas Verdier (@n1nj4sec) 's Twitter Profile
Nicolas Verdier

@n1nj4sec

Hacker | Bug Bounty Hunter

ID: 2567353628

linkhttps://github.com/n1nj4sec/pupy calendar_today14-06-2014 16:04:38

137 Tweet

2,2K Takipçi

519 Takip Edilen

YesWeHack ⠵ (@yeswehack) 's Twitter Profile Photo

📣 It’s a wrap for #HMIF, the first live #BugBounty dedicated to French scale-ups and unicorns! Congrats to all hunters for reporting 109 bugs and special kudos to smaury, AMEL Bigouden, myst404, Linus Särud, クロマタエ, Blaklis, Nicolas Verdier, Brumens, Hansluz 👏🏼 #YesWeRHackers

📣 It’s a wrap for #HMIF, the first live #BugBounty dedicated to French scale-ups and unicorns!

Congrats to all hunters for reporting 109 bugs and special kudos to <a href="/smaury92/">smaury</a>, <a href="/amellb/">AMEL Bigouden</a>, <a href="/myst404_/">myst404</a>, <a href="/_zulln/">Linus Särud</a>, <a href="/Kuromatae666/">クロマタエ</a>, <a href="/Blaklis_/">Blaklis</a>, <a href="/n1nj4sec/">Nicolas Verdier</a>, <a href="/Brumens2/">Brumens</a>, Hansluz 👏🏼

#YesWeRHackers
Boschko (@olivier_boschko) 's Twitter Profile Photo

Just published a writeup containing 10 CVEs for Tenda's W15Ev2 AC1200 SOHO router. If you like bug-bounty blogs with meat on the bone you'll enjoy the read ❤️ boschko.ca/tenda_ac1200_r…

Nicolas Verdier (@n1nj4sec) 's Twitter Profile Photo

#CVE-2022-23529 ... wtf ? with an article from palo alto #unit42 :') there is still plenty of 0days like that to report look

#CVE-2022-23529 ... wtf ? with an article from palo alto #unit42 :') there is still plenty of 0days like that to report look
HackerOne (@hacker0x01) 's Twitter Profile Photo

The time is finally here….👀 🥁 Drumroll, please 🥁 Join us in celebrating the Elite Eight teams moving on to Round 3 of the #AmbasssorWorldCup! The next round kicks off in just three short weeks. Which team will you be cheering on?

The time is finally here….👀

🥁 Drumroll, please 🥁

Join us in celebrating the Elite Eight teams moving on to Round 3 of the #AmbasssorWorldCup! 

The next round kicks off in just three short weeks. Which team will you be cheering on?
PortSwigger Research (@portswiggerres) 's Twitter Profile Photo

Turns out you don't need semi-colons to batch queries in MSSQL! SELECT * FROM test WHERE id = 1 WAITFOR DELAY '0:0:5' Great writeup by GoSecure, we'll update the Web Security Academy SQLi cheat sheet shortly. gosecure.net/blog/2023/06/2…

HackerOne (@hacker0x01) 's Twitter Profile Photo

The results are in! 📊 The four teams moving on to Round 4 of the #AmbassadorWorldCup are #TeamParis🇫🇷, #TeamIsrael 🇮🇱, #TeamNepal🇳🇵, and #TeamSpain!🇪🇸 Congratulations to all AWC teams for the incredible teamwork and effort put into protecting our AWC partners. 🙌

The results are in! 📊

The four teams moving on to Round 4 of the #AmbassadorWorldCup are #TeamParis🇫🇷, #TeamIsrael 🇮🇱, #TeamNepal🇳🇵, and #TeamSpain!🇪🇸

Congratulations to all AWC teams for the incredible teamwork and effort put into protecting our AWC partners. 🙌
Blaklis (@blaklis_) 's Twitter Profile Photo

The #ambassadorworldcup finally come to an end! Congratz #teamspain for your deserved world champion title! We were fighting with the team against the #teamnepal, which was a close fight. We did our best and we don't know yet the result, but whatever, I'm super proud of the road

The #ambassadorworldcup finally come to an end! Congratz #teamspain for your deserved world champion title!

We were fighting with the team against the #teamnepal, which was a close fight. We did our best and we don't know yet the result, but whatever, I'm super proud of the road
Nicolas Verdier (@n1nj4sec) 's Twitter Profile Photo

just came back home from HackerOne #ambassadorworldcup at Buenos aires ! Amazing time there ! Special thanks to all my teammates from #teamparis 🇫🇷 for all the collabs, skills and good hacking vibes. 😁🏴‍☠️. GG everyone and in particular #teamspain for the well deserved 🏆

just came back home from <a href="/Hacker0x01/">HackerOne</a> 
 #ambassadorworldcup at Buenos aires ! Amazing time there ! Special thanks to all my teammates from #teamparis 🇫🇷 for all the collabs, skills and good hacking vibes. 😁🏴‍☠️. GG everyone and in particular #teamspain for the well deserved 🏆
Nicolas Verdier (@n1nj4sec) 's Twitter Profile Photo

The first round of HackerOne's #AWC just ended and the 🇫🇷 finished 1st of the qualifiers. I'm also very proud to finish 1st on the individual leaderboard for this round 🙃 GG everyone 🔥!

Blaklis (@blaklis_) 's Twitter Profile Photo

As it is a good moment to celebrate our success a bit : France not only finished 1st in that qualification round, they finished 1st by a massive amount of points! (668 vs 296). On a more personal note, Nicolas Verdier and I are the top 2 scorers in bounties during that round. What a

As it is a good moment to celebrate our success a bit : France not only finished 1st in that qualification round, they finished 1st by a massive amount of points! (668 vs 296).

On a more personal note, <a href="/n1nj4sec/">Nicolas Verdier</a> and I are the top 2 scorers in bounties during that round. What a
Nicolas Verdier (@n1nj4sec) 's Twitter Profile Photo

I recently found a blind FreeMarker SSTI on a bbp. It was not possible to RCE but I found some nice gadgets to enumerate accessible variables, read data blindly or perform some DoS. I documented that here if someone is interested gist.github.com/n1nj4sec/5e3ff…

rez0 (@rez0__) 's Twitter Profile Photo

I'm a hacker and AI researcher who has reported vulnerabilities to OpenAI, Google, and others. I wrote this guide as a reference of all of the ways that you can hack AI. It has saved me hours. Bookmark this if you need a reference for what all to try (AND includes mitigations).

I'm a hacker and AI researcher who has reported vulnerabilities to OpenAI, Google, and others. I wrote this guide as a reference of all of the ways that you can hack AI. 

It has saved me hours. Bookmark this if you need a reference for what all to try (AND includes mitigations).
Blaklis (@blaklis_) 's Twitter Profile Photo

My french team, for the world cup, and in collaboration with my wife, printed me a hoodie with a redacted payload on it. That bug was super fun, but quite hard to exploit! If encoded words, RFC2047 and so on are strange words to you, Gareth Heyes \u2028 presented at the same time their

My french team, for the world cup, and in collaboration with my wife, printed me a hoodie with a redacted payload on it. That bug was super fun, but quite hard to exploit!

If encoded words, RFC2047 and so on are strange words to you, <a href="/garethheyes/">Gareth Heyes \u2028</a> presented at the same time their
Geluchat (@geluchat) 's Twitter Profile Photo

Today was my last day as a pentester at Bsecure, and it feels a bit surreal. After a three-year journey of hunting on the side, I’m finally ready to go all-in as a full-time bug bounty hunter. To celebrate this milestone, I've written an article sharing the full story. It’s a

Today was my last day as a pentester at Bsecure, and it feels a bit surreal. After a three-year journey of hunting on the side, I’m finally ready to go all-in as a full-time bug bounty hunter.
To celebrate this milestone, I've written an article sharing the full story. It’s a
Kévin GERVOT (Mizu) (@kevin_mizu) 's Twitter Profile Photo

I'm happy to release a script gadgets wiki inspired by the work of Sebastian Lekies, koto, and Eduardo Vela in their Black Hat USA 2017 talk! 🔥 The goal is to provide quick access to gadgets that help bypass HTML sanitizers and CSPs 👇 gmsgadget.com 1/4

I'm happy to release a script gadgets wiki inspired by the work of <a href="/slekies/">Sebastian Lekies</a>, <a href="/kkotowicz/">koto</a>, and <a href="/sirdarckcat/">Eduardo Vela</a> in their Black Hat USA 2017 talk! 🔥

The goal is to provide quick access to gadgets that help bypass HTML sanitizers and CSPs 👇

gmsgadget.com

1/4