Opens profile photo
Follow
Click to Follow Jhaddix
Jason Haddix
@Jhaddix
CISO/Hacker in Charge , 18 years hacking, 10 years leadership. exCitrix, exRedspin, exFortify, exHP, exBugcrowd, exUbisoft
Coloradoexecutiveoffense.beehiiv.com/subscribeBorn July 27Joined February 2009

Jason Haddix’s posts

🧵A hackers guide to FINDING cybersecurity jobs🧵 Many people know of the normal ways to look for jobs like LinkedIn & Indeed... but we're hackers! Today I'm going to share with you my top places/tips for finding your next gig. 🚨Retweet, follow, & like for more! 🚨 1/
73
2,633
👮 Hacking into several Prisons 👮 Here's how I did it (legally), and what I learned along the way! A thread for security testers and cyber security pros 🧵👇
Image
59
2,425
Another long (hacker) story thread 🧵 = Stealing checks worth millions & pwning a bank = Here’s how I did it, so you can learn. I was once contracted to do a penetration test on a bank… Like, retweet, and follow for more hacker stories! (1/x)
58
2,071
I have a real problem with hacker elitism. I dislike the term script kiddie. This job does not make you better than anyone. Taking pride in a thing you do for a career, that also happens to be fun , is a privilege. please, participate positively in the community. <3
Image
90
1,576
Friday will be my last day . It's been a wonderful ride the past 4 years. I'm so thankful for the opportunity and the epic people there. Next up, I'll be taking the Head of Security and Risk Management role & marrying my passion for games and security!🕹️🤓
Image
209
1,298
A thread🧵 💸Secrets of automation-kings in bug bounty💸 Finding 1day (or 1month) web exploits that haven't made their into scanners yet can make you big money. Read more to understand where and how to get an edge in this area! 🚨Retweet, follow, & like for more! 🚨 1/x
70
1,382
(a LONG thread) 🧵 Inspired by & here's one of my fun hacker stories: = The complete compromise of a password manager company = Here's how I did it (so you can learn): I was given the project to pentest a password manager company: *.redacted.com (1/16)
55
1,329
Excited to announce that and I are currently working on “The Bug Hunter’s Methodology” book. The book will focus on cutting edge web red team, pentester, and bug bounty topics. Tools, methods, automation, and no BS.
72
1,171
4/8/22 #bugbountydiary #bugbountytips Everyone is sick in the house but I had some running scans I needed to check up on. I found a SQL injection bug on a blog. Here's how I did it, so you can learn... 👇 🚨Like, retweet, & follow for more hacker tips!🚨 1/x
70
1,096
- Run all your subdomain tools - uniq them - Pass that list to: "amass enum -nf domains.txt" to insert them into the amass database. Then track new findings each day via: amass track -d domain.com | grep "Found" #bugbountytips #bugbountytip thanks
7
960
== Trademark and Copyright Recon == How to find assets no other bug hunters have found. One of my simple "secrets" for years. Little automation exists for it. 💸💸💸 a thread🧵 🚨follow, retweet, & like for more hacker tips!🚨 1/x
50
974
Just so people know, I'm not crazy... On the left, Burp 1.7 after spidering JUST tesla.com and setting a scope rule for "tesla" On the right Burp 2023, with Incy Wincy crawler ON (via fastest config) Same configs. * 2023 Burp took 1.5 hours for the crawl *… Show more
Image
52
939
🧵Another hacker story thread! 🧵 == The Medical Alert Hack == Not too long ago I put a whole city on high alert during a security assessment. A tale of caution. 💀 Read along to learn my approach & mistakes! 🚨Retweet, follow, & like for more hacker stories! 🚨 1/x 👇🏼
28
881
🧵A Practice Target SUPER Thread🧵 Offensive Security People! Want to take your theory to live targets? Need some resume filler? Just want to keep fresh and practice? Here's a thread of my favorite practice targets to recommend. 🚨Retweet, follow, & like for more! 🚨 1/
55
872
🥽 The Anti-Recon Recon Thread 🥽 Recon is important, but some people hate it. I get it. When you're in the zone & ready to pounce on a target, you just want to start hacking. Want the best of both worlds? Quick/complete recon, WITH great coverage? (a long thread) 🧵⬇️
Image
56
904
When you look up your target's ASN you'll find their ipv4 & ipv6 ranges. Here's a one-liner to request all the webserver's SSL certificates and parse them for NEW TLD's, domains, and subdomains. #bugbountytips
Image
36
829
I started in helpdesk with very little comsci background, then *heard* pentesting was a thing you could make a career. I begged, borrowed, ++ to learn everything I could about it. You can do it too. I promise. Happy holidays hackers. Especially newbies out there. Keep grinding.
20
716
My #nahamcon2022 Keynote recording is out! The Bug Hunter's Methodology: Application Analysis v1 youtube.com/watch?v=HmDY7w Learn my tips, tricks, & tools for web pentesting or bug bounty. Thanks Ben ( ) & NahamCon! 🚨Retweet, follow, & like for more hacker content! 🚨
50
763
Information security is one of those scenes where you can go from nothing to a lifelong happy career without a degree or pedigree. I love it.
12
713
🤖 WebSecGPT - Your AI security buddy Hacking an API or JS framework? Don't have a swagger file or struggling to understand the app? Wanna quickly identify all js sinks? Meet WebSecGPT (a thread ) 👇
20
763
🔍 My ultimate workflow for simple and easy JavaScript Analysis ⚡️ Comprehensive JavaScript analysis in offensive security, appsec testing, and red teaming wins. Often you can find juicy hidden endpoints, parameters, & domains buried JS! A thread 🧵 1/x 👇
45
753
🧵Another new hacker story thread! 🧵 == The 100 Million Person Data Disclosure == That time I hacked a whole country by accident! 🚨Retweet, follow, & like for more hacker stories! 🚨 1/x 👇
21
698
🧵Another hacker story thread!🧵 === Penetrating a Porn Site === How I hacked access to the most sensitive areas of a porn site using only low severity vulnerabilities. Here's how I did it... 👇 🚨follow, retweet, & like for more hacker stories!🚨 1/x
sexy lips GIF
GIF
41
662
Want a one-liner that notifies you of any fresh domains (if they come up) to you each hour? #3 ⬇️ > screen > subfinder -silent -d {target}.com -o {target} > while true; do subfinder -silent -dL {target} -all -nW | anew {target} | notify; sleep 3600; done
Image
16
681
A thread/tip for hackers/defenders/organizations. 🧵 ⚠️A commonly found vulnerability for organizations is credentials leaked on Github.⚠️ Sometimes this can be from the organization's OWN code repositories on GitHub, but... 🚨follow, retweet, & like for more tips!🚨 1/x 👇
35
649
💪 Code Literacy is a Super Power for Hackers 💪 (and Security Literacy is a super power for devs) Knowing how vulnerabilities are mitigated makes you a 10x engineer (sec or dev) Check out this thread for some of my fav 🔥FREE🔥 resources. ⬇️ (Also send me more!)
31
668
Jeez, there were a lot of hacker Twitter peeps throwing hate at each other, and the weekend is not even over. You know what’s really cool? Being kind, supportive, and not gatekeeping. That’s fucking RAD.
576
On last night's stream we did an overview of all the great "targets" and resources newbies can learn hacking on. It was super fun! Most of it came from my appsec bootcamp which I mentioned briefly. Will upload the video to YouTube tomorrow =)
Image
16
574
🐻 Hacking a Search / Cloud Company 🐻 I once took over a MAJOR foreign search/cloud company. I had full access to every employees email & full source code for all their apps. Here's how it did it (legally)… ⬇️🧵
21
618
🧵Full-Time Bug Bounty Hunter thread 🧵 I'm looking for people to jump in and give me their perspectives. This is all speculative and in US hyper inflated markets. A Sr/Principle Security Tester in the US can command $150-200k salary in big markets (SFO, LA, NY). 👇1/x
43
582
I know it's common sense but remember when parsing JS for endpoints/files: / = Root directory . = This location .. = Up a directory ./ = Current directory ../ = Parent of current directory ../../ = Two directories backwards #bugbountytips ?
2
554
If you didn't know or just missed it maintains a configurable XSS cheatsheet for web security testers here: portswigger.net/web-security/c It includes features to build payloads with exactly what you need, and has written context around injections! I use it often. Enjoy!
7
560
Being a hacker has little to with your job. It's in your blood, your soul— it's a way of thinking. It's curiosity, creativity, and challenging norms. It's a relentless pursuit of knowledge, it's embracing the unconventional. Whatever you do today, bring the hacker mindset.
19
539
I’ve been leading Ubisoft’s security team for the last 4 years. It has been an epic adventure & I have learned so much along the way. I have truly worked with some great people. It is, however, time for me to move on. I will depart Jan 2. Stay tuned for what’s next 🫡
35
538
Taking a break from bounty and social media for a while. Prob a month or two. Been pretty dark since defcon, I think I burned myself out 🥱 Stay safe everyone ❤️
34
518
Hey friends. Sorry I’ve been so incognito recently. Julia (my wife) had some serious health issues the last few months that culminated in emergency surgery last week. Looks like we are out of the woods now but in recovery mode for a few more weeks. Love you all.
64
508
OWASP LLM Top Ten v.1: 🚀 Prompt Injections 💧 Data Leakage 🏖️ Inadequate Sandboxing 📜 Unauthorized Code Execution 🌐 SSRF Vulnerabilities ⚖️ Overreliance on LLM-generated Content 🧭 Inadequate AI Alignment 🚫 Insufficient Access Controls ⚠️ Improper Error Handling 💀 Training… Show more
12
514
#bugbountytips 🧵 1/x Starting from almost scratch. Testing Environment: DO Ubuntu VPS, 2 vCPUs. 4GB mem / 60GB Disk, ($20/mo) This works for most general tasks. In most VPS intensive tasks (content discovery, fuzzing, etc) memory is your bottleneck.
22
460
🎯 Red Team/Bug Bounty recon method 📋 2nd level subdomain brute forcing: > cat knownsubs | rev | cut -d . -f 1-3 | rev | sort -u | tee sub.subdomains 🔨 Brute force those. Any that had * from SSL certs (wildcards) are ideal candidates. (learned from & )
Image
13
470
So… I just finished my 1st Live Hacking event & I’m heading into another with As a program owner, hacker, & security leader… I have thoughts! Read along for some spicy bounty takes. 🚨 Like, follow, & retweet for more security content 🚨 a 🧵 1/x
Image
7
465
Dropped some previews of "The Bug Hunters Methodology v4 - App Hacking" the stream today. No ETA on release yet, WiP:
Image
Image
Image
8
442
I'll be doing the full 2hr version, a walkthrough of some of the tools, and my mind-mapping process of the The Bug Hunter's Methodology workshops this year! =)
Quote
🔥FREE TRAINING🔥 Bug Bounty Hunter Methodology Another great presentation by @Jhaddix ! Jason is doing a briefing and this 2-hour training! @VillageRedTeam Website: redteamvillage.io YouTube: youtube.com/redteamvillage Twitch: twitch.tv/redteamvillage #DEFCON
Image
11
427
The lost art of LINKED target discovery w/ Burp Suite: 1) Turn off passive scanning 2) Set forms auto to submit 3) Set scope to advanced control and use string of target name (not a normal FQDN) 4) Walk+browse, then spider all hosts recursively! 5) Profit (more targets)!
14
411
SO you're a bounty hunter with a gaming rig? 🧵 If you don't want to use a VPS or run native (dual-boot Linux) you can install Ubuntu and WSL 2. (+) You'll (probably) benefit from more memory, cores, and a fast broadband connection.
32
424
I just realized… today I hacked a fortune 50, had a call with the Gov, and spoke to a movie producer 😂🫠🚀 What a day lol
24
435
I was bullied for being brown, being overweight, being a nerd, having a birthmark on my face, being poor, & having glasses. Every harsh word and bruise/scar fueled me to work hard harder and become good at what I do. I learned compassion & empathy is a super power. Solidarity ✊🏽 t.co/9Y2WetKRqh
This Tweet is unavailable.
11
377
I unsubscribed from twitter blue. I condemn the ceo of this site. I’m deeply saddened I ever supported him. The problem is MY brand was built here. Before him. My brand feeds my family. Two of which are gay and non-binary. I sat down with them to talk about it. They’d… Show more
14
396