Just a random guy, tweeting in front of the world. Sr. Application Security Engineer (API, Mobile, Web, Cloud, AI/ML) 💼. Creator (@vulnbank & xjwt.io)

…in your infra
I built an intentionally vulnerable banking application for security engineers/interns, developers, & QA analysts to learn, practice secure code reviews, and test their application security knowledge in areas such as SQLi, XSS, CSRF, race conditions, API vulnerabilities, & more.
Where are the hackers/code reviewers? How many vulnerabilities can you spot in this code? Apart from the hints, are there other places you can exploit? Can you chain the vulnerabilities?
24
145
794
208,919
Why am I getting incorrect API key error on Codex??? I hope I’m not the only one experiencing this.
5
3
20
1,898
the nastiest goal you will see 😭🪄 #fc27
3
860
> open burp > send to intruder > 1-100 > less than 1mins later > 200 OK
We divided the number to guess among ourselves, and 2 of us got it 🥹🔥😂
4
4
44
5,333
Assuming there are no strict ratelimits & bypass controls🙂
2
8
548
I nearly choked when I finally figured it out 😭😂. I would delete my account if I was stev0.
Throwback to this 😭😭😭
1
4
3,291
Want to get into offensive security but don’t know where to start? 👀 @ExploitforgeLTD @ExFacademy
7
10
104
4,606
If you feel like life is becoming too difficult and you’re close to giving up, read this. There are people going through situations far worse than yours who would give anything for the chance to change their circumstances. If you’re going through a rough patch but still have a roof over your head, food to eat, and a chance to keep going, don’t take those things for granted.
“Make sure you don’t sleep,” one trafficker belted out. “If you sleep, you fall off. And if you fall off, you die!” Part 1 of my latest investigation for @fijnigeria. UNDERCOVER: Europe Through the Sahara Desert and the Mediterranean Sea (I) fij.ng/article/undercover-eu…
2
28
133
10,011
Ghost St Badmus retweeted
We're going live this Saturday. Set your Reminders!! 🚨 Don’t miss it! Date: Sat, 26 Sept · 7PM WAT Here on X: @ExFacademy Host: @PapiJruee Co-Host: @He_is_Legit Speakers: @commando_skiipz, @aligorithm. Come with your curiosities. nitter.net/i/spaces/1RJjpbreYLZKw #cybersecurity
4
12
36
2,657
I’ve just deployed a fix for the annoying stored XSS issue. Learners can still practise exploiting the cross-site scripting vulnerability, but the payload will no longer remain indefinitely. Approximately 15 minutes after an XSS payload is stored, it will be automatically removed from the database. This allows others to access the affected pages and test the vulnerability without repeatedly triggering someone else’s payload. I’ve also added special-character & length validation to usernames during registration. This should make it more difficult for AI agents, bots, and DAST tools to clutter or disrupt the admin interface with malformed usernames. Lastly, I added a critical security misconfiguration involving excessive data exposure, something we’ve encountered several times during real-world pentest of client applications. I’ll leave you all to find it. Happy hunting!
Mr @commando_skiipz Just now, when I was on a practical with the student, testing for Broken Access Control vulnerability with @Vulnbank (vulnbank .org), it appears someone has loaded the server with some kind of unending payload of Stored Cross-Site Scripting (XSS) executing on other users end which is actually disrupting the learning and progression of what we are trying to understand. Here is the video of how the application was reacting when trying to access the Admin page of the application. I have testing and checked this particular one here before and it wasn't like this so please kindly look into it as soon as you can thank you. @Dghost_Ninja
3
11
55
2,678
Ghost St Badmus retweeted
As promised Wrote up a bug class I keep hitting on financial apps: response manipulation. Server makes the decision, ships the wrong verdict in the response, client believes it. 4 variations, same root cause. Built a lab to show the mechanics. dghostninja.github.io/posts/…
There's a silent Broken Access Control bug disturbing even the "big" apps we use and in most cases I've found it, most developers don't know how to go about fixing it. I'll make a write-up about this soon. You'll be shocked about how many "fintech" apps are quietly affected
8
20
104
5,542
Let’s gooooo!!!! 🔥🔥🚀
Offensive security doesn't have to feel out of reach. Next Saturday, we're breaking it down live: what it is, what it takes, and how to get started. 🎙️ X Space · 26 Sept · 7PM WAT Speakers: @commando_skiipz · @_aligorithm · @He_is_Legit · @PapiJruee Come with your curiosities.
2
5
23
1,194
Look at all the tweets from NTA about Obi in 2013 & 2014. If you like, allow renewed hope boys to gaslight you.
3
12
66
2,453
Thank God say I resist the urge to waste money buy ticket
Man City take the points.
2
1
20
1,455
Special ribbon cutting ceremony like our politicians do😂
Replying to @commando_skiipz
I even slept with the hospitality wristband on 😭😭
3
3
58
26,126
Back to cooking @threatmindAI 🚀
19
21
272
9,329
I still never see that bracelet comot o😭🧎🏾
1
2
337
More news to come really soon 🚀🔥
4
488