Check out the latest BApp Store release - AI HTTP Analyzer. Use AI to analyze HTTP requests and responses for potential security vulnerabilities like SQLi, XSS, CSRF.
Written by @alpernae, this is our first community-written extension using the new Montoya AI API functionality.
List of recon techniques that almost nobody is trying 🤑
• Running CeWL on product & API docs
• VHost enumeration & Bruteforcing with host header set to "localhost"
• Bruteforcing with different HTTP methods (POST, PUT, PATCH, ...)
• Favicon recon
• Crawling sites with…
🔥 403 turned to 200 🔥
Accessing /admin/settings was answered with 403, but using the "Referrer" HTTP header I was able to access pages that were forbidden!
This is a common method to bypass a server side validation that relying on the user accessing only through the website…
Are you late for web3 security? 🤔🤔🤔
Short answer: Depends
Long answer: Depends on your mindset
If you think you are late, fine give up. I will suggest you doing one thing though.
Come back 2 years later and see how much the space has evolved. How many new superstar…
Hello Twitterverse,
I am planning for an @Hacker0x01 Ambassador meet-up in June in Pune, India region 🇮🇳🚀
More details will be announced soon 😀
I hope you'll love these laptop stickers ♥️
74 Followers 1K Followingdon't expect that someone will come to you who will love you for real because you will only be cheated when it comes to the end
7K Followers 2K FollowingGlobal leader in hands-on learning for enterprise and cloud security education. Join 40000+ infosec professionals from 130+ countries
217K Followers 117 FollowingDriving India’s digital payments innovation with our products like @UPI_Npci, @RuPay_npci, @Npci_Bhim, @BharatConnect_ to keep you Always Forward.
7K Followers 2K FollowingGlobal leader in hands-on learning for enterprise and cloud security education. Join 40000+ infosec professionals from 130+ countries
38K Followers 132 FollowingDetect real, exploitable vulnerabilities. Harness the power of Nuclei for fast and accurate findings without false positives.
8K Followers 85 Followingtech lead @robinhoodapp | ex-@amazonalexa | protected billions in value at @securityOak, @electisec, and more | lackadaisical angel investor
56K Followers 628 FollowingImmunefi — One Platform. Unified Security Operations. Complete Onchain Protection. Over $180B of user funds protected across 650+ protocols.
23K Followers 477 FollowingHead of Trust Security, DM for booking |
Master of hand-to-hand audit combat |
C4/Immunefi/Sherlock VIP |
Hacked Embedded, IoT, iOS in past life
43K Followers 284 FollowingYapping about AI, AppSec, Hacking, & Cybersecurity • Helped secure organizations like Google • Opinions are my cat's • Part-time shitposter
53K Followers 616 FollowingGrzegorz Niedziela - a hacker who documents his hacking journey by creating and curating the best content about bug bounty and offensive security.