manuel valdez
@saur1n.bsky.social
📤 124
📥 164
📝 55
▪️Hacking my way through life ▪️Part time Bug Bounty hunter ▪️Engineer ▪️Teacher ▪️x.com/saur1n
reposted by
manuel valdez
Baklava Monster, CISSP
5 months ago
Spotted a reverse engineering boutique at Zurich main station
0
6
2
It's amusing to me the amount of apps that implement pretty decent anti-SSRF measures: - Private IP addresses✅ - Normalization of diff. IPv4/IPv6 representations✅ - TOCTOU DNS rebinding✅ - HTTP Redirects✅ But still this little😈 slips through the cracks: - 0.0.0.0❌
#bugbountytips
6 months ago
0
0
0
It's just like that sometimes
6 months ago
0
0
0
6 months ago
0
0
0
Swag's here! As part of an active campaign from 12build program run by
@intigriti.com
, I managed to find a few cool bugs. Great program, good quality💯 t-shirts
#bugbountytips
6 months ago
0
1
0
Os Inception
7 months ago
1
1
0
I'm starting a new series called: Weird SSRF outputs
7 months ago
1
2
1
Hacking is just a weird thing that many discover because it's just something that we inherent (at birth?) and then develop over the years. It just feels right to be around computers and entangled stuff that most of the time, u cannot wrap your head around it, but guess what? That's the beauty of it
8 months ago
0
1
0
reposted by
manuel valdez
0xacb
8 months ago
Sometimes all it takes is one weird byte. REcollapse aims to find it! Just give it a URL and it will generate a fuzzing list for all regex pivot positions with all possible bytes %00 to %ff! Check it 👇
loading . . .
1
1
1
This is the bad thing about sharing testing environments. This guy has been hammering an HTMLi on a invitation email request for three days now, which I'm 99.9% sure has been reported before **several times**.
8 months ago
1
0
0
I feel sorry for triagers seeing this type of... Thing on bug bounty reports
9 months ago
0
2
0
reposted by
manuel valdez
Physgal ⚛️
9 months ago
Antimatter is cool and it's a real thing. I used to work on an experiment where we collided protons with antiprotons to make top-antitop quark pairs (among other things). ⚛️
add a skeleton here at some point
3
252
31
📷
9 months ago
0
1
0
Decompressing
9 months ago
0
0
0
I hate providing reproduction steps with (a) missed step(s). I guess writing reports late at night can take a toll on us sometimes. It can happen but it sucks, especially for the triager assessing the ticket
9 months ago
0
0
0
It's all about that tiny request, that picky little one that gets lost in a sea of junk from your history tab, the one which gives you the keys to the juicy treasure. Bug Bounty poem :)
9 months ago
0
1
0
reposted by
manuel valdez
David Leavitt
10 months ago
It’s the same picture
264
7255
1822
reposted by
manuel valdez
Jwst Feed
10 months ago
Arp 321. a compact group of five galaxies located in the constellation Hydra. It's a fascinating object for astronomers because these galaxies are in close proximity and interacting with each other. Processed Hubble data by Dr. Mehmet Hakan Özsaraç.
www.flickr.com/photos/mhozs...
🔭 🧪
24
2383
342
reposted by
manuel valdez
Ryan T. Brown 🎮🩷
10 months ago
Even physical games are bricked without PSN access if you need to pair a disc drive. This is why real physical media and disc drive access is vital. Welcome to the future - nobody owns anything, and all art and entertainment is disposable, temporary, and lost forever.
82
2681
1272
I guess this is well known by experienced WebApp pentesters/bug hunters/Burp Suite power-users, so this is targeting beginner users. While loading the Burp Suite extension Autorize, it has by default this box checked: 1/n
10 months ago
1
0
0
Stored XSS is cewl but have you heard about a store full of XSS's? 🙄
10 months ago
0
0
0
reposted by
manuel valdez
d4d
10 months ago
We've updated our URL validation bypass cheat sheet with this shiny Domain allow list bypass payload contributed by dyak0xdb!
1
28
9
By testing for SSRF be on the lookout of any Axios http clients, these instances follow redirects by default which devs sometimes don't know it. Therefore, there is a high chance defenses could be bypassed by entering the evil host after the redirection. Don't forget 301,308 redir codes ;)
10 months ago
0
1
0
reposted by
manuel valdez
Katie Mack
11 months ago
"The best possible knowledge of a whole does _not_ include the best possible knowledge of its parts -- and this is what keeps coming back to haunt us." -Erwin Schrödinger, on quantum entanglement, 1935
17
704
91
Spotting bugs left and right just to sit back thinking about bb reports... That right there *is* the struggle!
11 months ago
0
0
0
Tip toeing into the app, It doesn't seen to have a Bookmark kinda thing, am I missing something?
11 months ago
0
0
0
reposted by
manuel valdez
Katie Mack
11 months ago
Anyway if you'd like a lightweight primer on all things quantum, you can check out the series of short intro videos I made with the Perimeter Institute, Quantum 101:
perimeterinstitute.ca/quantum-101-...
Just because quantum mechanics isn't spooky doesn't mean it's not really, really cool. 🧵🔚
loading . . .
Quantum 101 – Quantum Science Explained | Perimeter Institute
Welcome to the quantum realm! Join Katie Mack, Perimeter Institute’s Hawking Chair in Cosmology and Science Communication, over 10 short forays into the weird, wonderful world of quantum science.
https://perimeterinstitute.ca/quantum-101-quantum-science-explained
28
711
98
reposted by
manuel valdez
Katie Mack
11 months ago
Today I was asked in an interview about folks who use the weirdness of ✨quantum✨ to hawk pseudoscience junk. I think that kind of grift proliferates because of a big misunderstanding a lot of folks have about quantum mechanics, which is not really their fault! 🧵
49
1768
389
test
11 months ago
0
0
0
you reached the end!!
feeds!
log in