Will Liu

@hnz010

Collage student Bug bounty hunter

China
Vrijeme pridruživanja: svibanj 2019.

Tweetovi

Blokirali ste korisnika/cu @hnz010

Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @hnz010

  1. Prikvačeni tweet
    29. pro 2019.

    1. Make $20k bounty. 2. More Hacking than Reading. 3. Get swag from Hackerone.

    Poništi
  2. proslijedio/la je Tweet
    12. sij

    Just posted Remote Code Execution in Three Acts: Chaining Exposed Actuators and H2 Database Aliases in Spring Boot 2. Using a payload containing three different programming languages :)

    Poništi
  3. proslijedio/la je Tweet
    28. pro 2019.

    ▓▓▓▓▓▓▓▓▓▓▓▓▓▓▓ 99%

    Poništi
  4. proslijedio/la je Tweet
    23. pro 2019.

    I need to beg my hacker fam for a signal boost and some help. Please. I need to find where this picture was taken. There is a missing 8-year-old girl and schizophrenic mother. She was traveling through IAH when she left the airport and cut off communication with everyone. 1/x

    Prikaži ovu nit
    Poništi
  5. proslijedio/la je Tweet
    18. pro 2019.

    If you look into the right place, even Google can make some easy mistakes 👀👀 Check it out

    Poništi
  6. proslijedio/la je Tweet
    15. pro 2019.

    My tool found 4k subdomains. Your tool found 64k subdomains - you have clearly the better tool! Just reported two criticals while you are still screenshotting all your "legit 64k subdomains". People, especially beginners, fail because they trust tools.

    Poništi
  7. proslijedio/la je Tweet
    16. pro 2019.

    Finally got the approval, Here are multiple Linode's access token stealing/account takeover bugs, I like the second one. Retweet if you like it.

    Poništi
  8. proslijedio/la je Tweet
    15. pro 2019.

    Rare Payment Bypass Cases : Case 1: Submit=Payment ( Just Remove Payment & submit the request ) Example : Submit = Case 2: Amount=100$ ( Give space b/w = & 100$ and submit the request ) Example : Amount= 100$

    Poništi
  9. proslijedio/la je Tweet
    15. pro 2019.

    Are you ready to takeover subdomains? ;) I have developed a tool to scan subdomain takeover vulnerabilities. Found 300+ vulnerable subdomains on Twitter,Yahoo,Pinterest,Periscope,Spotify,HarvardUni,StanfordUni,BerkeleyUni,YaleUni,PrincetonUni... Its free!

    Prikaži ovu nit
    Poništi
  10. proslijedio/la je Tweet
    12. pro 2019.
    Poništi
  11. proslijedio/la je Tweet
    12. pro 2019.

    [] Found staging application that give you access to a privilege account with default credz, make sure to reuse this domain cookies to the main domain (prod), you can easily access as privileged user. & Get ready for next monday !

    Poništi
  12. proslijedio/la je Tweet
    30. stu 2019.
    Poništi
  13. proslijedio/la je Tweet

    If you've got an infosec question you want answered - throw them in here and I'll get them answered.

    Poništi
  14. proslijedio/la je Tweet

    Once you have a list of subdomains your next steps are literally >nmap >content discovery >more content discovery based on that content >googling for specific CVE's based on identifiers >more content discovery >more content discovery >find a bug >repeat

    Poništi
  15. proslijedio/la je Tweet
    1. stu 2019.
    Odgovor korisnicima i sljedećem broju korisnika:
    Poništi
  16. proslijedio/la je Tweet
    29. lis 2019.

    Mohamed Sayed - Blog: [Leak] Can I take the user information, please?!!

    Poništi
  17. proslijedio/la je Tweet
    15. lis 2019.

    I just published How I was able to bypass the OTP code requirement in Razer [The story of a critical bug]. Make sure to check my first writeup and feedback is appreciated.

    Prikaži ovu nit
    Poništi
  18. proslijedio/la je Tweet
    25. lis 2019.

    I'm publishing my work on the practical testing and breaking of JWT authentication. The scripts that can make your JWT testing easier: Feedback are always welcome!

    Poništi
  19. proslijedio/la je Tweet
    24. lis 2019.

    We’ve just published a new article about typical security issues in JSON Web Tokens (JWT). Learn about the eleven thorns right here:

    Poništi
  20. proslijedio/la je Tweet
    20. lis 2019.

    I just published How PayPal helped me to generate XSS. RT if you like :)

    Poništi

Čini se da učitavanje traje već neko vrijeme.

Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.

    Možda bi vam se svidjelo i ovo:

    ·