Tweets
- Tweets, current page.
- Tweets & replies
- Media
You blocked @pry0cc
Are you sure you want to view these Tweets? Viewing Tweets won't unblock @pry0cc
-
pry0cc Retweeted
I forked meg an added support for using burp collaborator links in payloads. You can add {tracker} to URL's and that'll get replaced by the hostname of the target + a collaborator link.http://github.com/Cgboal/meg
Thanks. Twitter will use this to make your timeline better. UndoUndo -
pry0cc Retweeted
Also wrote this blog which details how you can use collaborator outside of burpsuite, which is useful for long running tasks where you don't want to keep burp open.https://calumboal.com/posts/persistent-collaborator/ …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
This is so underrated.https://twitter.com/CalumBoal/status/1239175075158536197 …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
pry0cc Retweeted
- getallurls is a tool made by
@hacker_ - anti-burl is a tool made by@TomNomNom -#ffuf is a tool made by@joohoi - Burp & Burp collaborator by@PortSwigger@PortSwiggerRes of courseShow this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
pry0cc Retweeted
Sometimes you got to keep it simple in
#bugbounty. Just got an#SSRF, steps (credits below): 1 Run getallurls for all assets & merge results 2 `cat results | grep "url="| anti-burl | tee ssrf.txt` 3 Review & cleanup list 4 Fuzz all "url-like" params w/ Burp collab &#ffufShow this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
pry0cc Retweeted
Hey! Do you want some of the best pentesting training about for a killer price? DM me for special rates for
@ShellAffect for 20 licences and up. Negotiation is open. https://0x00sec.org/t/shell-affect-release/12685/ … Please retweet for this killer one-time offer!Thanks. Twitter will use this to make your timeline better. UndoUndo -
pry0cc Retweeted
Also works for open redirects. You can also use `grep "=http"` or `grep "=/"` to grab endpoints, regardless of the parameter's name
#BugBounty#bugbountytipshttps://twitter.com/ngkogkos/status/1226186160432611329 …Thanks. Twitter will use this to make your timeline better. UndoUndo -
Hey! Do you want some of the best pentesting training about for a killer price? DM me for special rates for
@ShellAffect for 20 licences and up. Negotiation is open. https://0x00sec.org/t/shell-affect-release/12685/ … Please retweet for this killer one-time offer!Thanks. Twitter will use this to make your timeline better. UndoUndo -
pry0cc Retweeted
Found weird bug 1. While registering with username , got error username already taken, so I use another username. 2. Go to edit profile , change username to already registered username , success! 3. Existing users account with that username deleted.
#bugbountyShow this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Ok - Serious question. Anonymous poll, only for those who have gotten domain admin in an engagement before. What feels better?
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Got a badass night of hacking, pies and laughs with my boys
@ImpetuousDanny &@CalumBoal I'm excited!Thanks. Twitter will use this to make your timeline better. UndoUndo -
pry0cc Retweeted
Searching the entirety of Project Sonar for DNS info in under 1 second, running on shitty old hardware. Just comparing results with Amass/Subfinder etc, blog to follow. Can discover alternative TLDs too. Definitely the fastest subdomain enumeration i've used.
@Jhaddix@rapid7pic.twitter.com/hn153mRFPWShow this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
This is such an underrated project. The possibilities of adding more data sets and indexing those, and building a central database of shared data for instant querying. Imagine indexing all the subdomain data from the same sources as amass & subfinder, for instant query.https://twitter.com/CalumBoal/status/1237689488039727105 …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Project Crobat is really the fastest DNS enumeration method yet https://github.com/pry0cc/crobat-client/ … Being fully opensourced in the near future :) Supports full wildcard on domain index too. Search by {domain}.* and pull all subdomains.pic.twitter.com/VTlmRMfxES
Thanks. Twitter will use this to make your timeline better. UndoUndo -
pry0cc Retweeted
Snark aside. Fuck, I can't believe I'm doing this. It has it's place. Specifically on the DoD 8570 list which .mil leadership must take, and it covers enough that someone can talk about security without sounding like an idiot. So, if they learned hard, they should celebrate.pic.twitter.com/iNrL5eFwcy
Thanks. Twitter will use this to make your timeline better. UndoUndo -
pry0cc RetweetedThanks. Twitter will use this to make your timeline better. UndoUndo
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.