Advertisement · 728 × 90

Posts by Reza Sahaf

Preview
MonkeHacks #48 Codebase Redesign, Celebrations, Climbing

🐵 MonkeHacks #48
Codebase Redesign, Celebrations, Climbing

#bugbountytips #hacktheplanet #bugbounty monke.ie/p/monkehacks...

1 year ago 3 1 0 0
Enjoy the videos and music that you love, upload original content and share it all with friends, family and the world on YouTube.

SSRFs can be tough to make critical without cloud metadata, especially against a target like GitLab that strengthens its infra with every SSRF. Yet @joaxcar.bsky.social broke through with the first critical SSRF on GitLab since 2020. Enjoy our explanation from Sweden! 🇸🇪

1 year ago 11 3 0 1

One of my favorite bugs from last year

1 year ago 20 5 0 0
Post image

Here's what's in the latest issue of BBRE Newsletter 🔥

1 year ago 2 1 0 0

Kids these days don't even know how much opportunity they have to learn hacking from actual pros.

I know there is a lot of content out there, so it can be hard to find the good stuff. But 10 years ago you had to be lucky to find at least something.

Anyway, watch this 👇

1 year ago 61 8 2 0
Flare-On 2024 Solutions and Commentary
Flare-On 2024 Solutions and Commentary YouTube video by BasteG0d69

My videos for Flare-On 2024 are live! Watch me reverse engineer all the challenges from start to end. 🎉🥳

+ Commentary video featuring SuperFashi, where we review the chals together.

* 45 hours of content
* 400+ GB of raw footage

Merry Christmas! Link: www.youtube.com/watch?v=vwW9...

1 year ago 49 11 0 1
Post image

⚠️Challenge time again⚠️

It is based on a real-world situation. Use the HTML injection to leak the flag to an external domain ☃️

This time, send solutions in DM; we don't want to spoil the fun. I also might want to patch any obvious blunder I made creating it

joaxcar.com/xss/outer.ht...

1 year ago 18 5 2 0
Preview
MonkeHacks #43 Year in Review, Technique Drop, Taking Care

🐵 MonkeHacks #43
Year in Review, Technique Drop, Taking Care

📝In this issue, I drop a fun technique for bypassing redirect checks in certain situations. Enjoy :)

#bugbountytips #hacktheplanet #bugbounty monke.ie/p/monkehacks...

1 year ago 6 1 0 0
Post image

A small code-golf web challenge (free research from you, for me), how short can you make a "fetch content and execute it inline".

There is a CSP in a meta tag.
Goal: get the content from the file hack.js and have it inserted in the page. like in the image

joaxcar.com/xss/self.html

1 year ago 36 7 5 3
Post image

Here's what's in the latest issue of BBRE Newsletter 🔥

1 year ago 2 1 0 0
Advertisement

🫡 2024 YTD #BugBounty stats update:

📄 7 issues Reported (4 Crit, 2 High, 1 Medium)
💰 4 issues Paid
⚪ 1 Informational
🔴 1 OOS

1 year ago 2 1 1 1

Will try it, seems to be fun!

1 year ago 0 0 0 0
PortSwigger Advent Calendar

Doing some @portswigger.net advent calendar this year as well. Join me on advent.j15.se

Its not affiliated with Portswigger but it will link you to one of their chapters each day (random for max excitement)

Its created 100% using Cursor so any bugs is AI’s fault

1 year ago 5 3 2 0

Can I ask the reason why a RCE is a low/medium severity bug in this case? Attack complexity or scope is not core asset?

1 year ago 1 0 0 0
Back to the Basics - Web Fundamental to 100k a Year in Bug Bounty (Ep. 99)
Back to the Basics - Web Fundamental to 100k a Year in Bug Bounty (Ep. 99) YouTube video by Critical Thinking - Bug Bounty Podcast

This week we've got a rare episode that is also a bit more beginner friendly!

0xLupin (of Lupin and Holmes) and @rhynorater.bsky.social breakdown some of the hacker mentality that really caused some breakthrough in their hacker growth.

Check it out!
youtu.be/yxc2jVKE-jo

1 year ago 31 9 0 0

Dope!

1 year ago 0 0 0 0
Post image

Alright, new platform so I'm going to start sharing some things that I'm excited about to keep the momentum flowing!

Rn, I think the 403 Bypasser Caido plugin from Bebiks is freaking amazing.

This is a tool to automate the bypassing of walled-off endpoints.

This plugin does 3 things right:

1 year ago 37 8 3 0
Advertisement

Any bug bounty people around? I'm creating a starter pack of people to follow but it's pretty brief currently! Let me know if you'd like to be added: go.bsky.app/GD7hKPX

1 year ago 95 30 45 2

🫡

1 year ago 1 0 1 0
Preview
Bug bounty hunters & content creators Join the conversation

The "bug bounty hunters and content creators" starter pack is now up to 60 users! Follow this to get instantly connected to the bug bounty community & let me know if I've missed you off!

go.bsky.app/GD7hKPX

1 year ago 87 22 19 4

Trying to make a list of programs that have hosted a live event on hackerone
-epic games
-tiktok
-zoom
-salesforce
-uber
-PayPal
-DoD
-shopify
-airbnb
-yahoo
-Starbucks
-Amazon
Which did I miss #Bugbounty

1 year ago 5 1 2 0

I really needed this list! Thanks

1 year ago 1 0 0 0

Hello World!

1 year ago 1 0 1 0