☠Labda☠ (@thelabda) 's Twitter Profile
☠Labda☠

@thelabda

Geek, IT security, OSCP
bugcrowd.com/labda
Synack RedTeam member
@Bugcrowd Ambassador #BugBountyTips

ID: 2545698342

linkhttps://thelabda.com calendar_today04-06-2014 10:12:59

1,1K Tweet

718 Takipçi

377 Takip Edilen

/ XNL -н4cĸ3r (and @xnl-h4ck3r in the new Sky) (@xnl_h4ck3r) 's Twitter Profile Photo

gau and waybackurls are great tools, BUT... Below are more or less equivalent, just getting links from wayback machine, and also not filtering (so returning images, css, etc. as gau does by default)... Yes they are faster than waymore, but waymore gets... well... more! 🤘😉

gau and waybackurls are great tools, BUT...

Below are more or less equivalent, just getting links from wayback machine, and also not filtering (so returning images, css, etc. as gau does by default)...

Yes they are faster than waymore, but waymore gets... well... more! 🤘😉
☠Labda☠ (@thelabda) 's Twitter Profile Photo

My latest cve has been published!💣 nvd.nist.gov/vuln/detail/cv… It was a nasty directory traversal. Keep in mind: always try to escape from your current directory! #bugbounty #bugbountytips #cve #hacking

neeraj (@knight0x07) 's Twitter Profile Photo

PoC showcases how TA captured & exfiltrated creds (b64 encoded) to the C2 for users logging in the ICS Web SSL VPN by modifying legit component of ICS via exploiting #0day vulns (unauth #RCE) in #Ivanti Connect Secure #VPN #cyber #infosec #cybersecurity #malware #redteam #dfir

Brute Logic (@brutelogic) 's Twitter Profile Photo

You probably know that <Img Src=javascript:alert(1)> Doesn't work anymore (although several lists out there have it) But if you add OnError=location=src It does! brutelogic.com.br/gym.php?p05=%3… Not so useful but who knows your next inline injection scenario? #XSS 😎

/ XNL -н4cĸ3r (and @xnl-h4ck3r in the new Sky) (@xnl_h4ck3r) 's Twitter Profile Photo

GAP is now the Burp Suite BApp store 🤘 Go give it a go, give some feedback, give it a rating, and go get all those links, parameters and custom wordlists! #BugBounty

GAP is now the <a href="/Burp_Suite/">Burp Suite</a> BApp store 🤘
Go give it a go, give some feedback, give it a rating, and go get all those links, parameters and custom wordlists!
#BugBounty
☠Labda☠ (@thelabda) 's Twitter Profile Photo

How do you log your penetration-test activity? Do you use your custom tool, or some sort of third party solution? #questionoftheday #hacking #pentest #bugbounty

Hack The Box (@hackthebox_eu) 's Twitter Profile Photo

One does not simply walk to the Vault ✋ But every quest is easier with the support of our allies! Thank you bugcrowd for being the Diamond Sponsor of #BusinessCTF24. Register now for the biggest #CTF competition for corporate teams: okt.to/IxcdSO

One does not simply walk to the Vault ✋
But every quest is easier with the support of our allies! Thank you <a href="/Bugcrowd/">bugcrowd</a> for being the Diamond Sponsor of #BusinessCTF24. Register now for the biggest #CTF competition for corporate teams: okt.to/IxcdSO
Gareth Heyes \u2028 (@garethheyes) 's Twitter Profile Photo

We've just released Shadow Repeater, for AI-enhanced manual testing. Simply use Burp Repeater as you normally would, and behind the scenes Shadow Repeater will learn from your attacks, try payload permutations, and report any discoveries via Organizer.

m4t (@szilak44) 's Twitter Profile Photo

Call any number (even premium-rate ones) from a locked iPhone and confirm whether a number/email is saved in the contact list: szilak.com/2025-09-18-loc… #iphone #apple #privacy