White hat hacking in Team ROT. Also, hacker-for-hire & bug bounty hunter -- hackerone.com/putsi

Tampere, Finland
Pinned Tweet
Wrote a blog post about how to host private Burp collaborator instance. It also has some scripts to make it a bit easier and faster. teamrot.fi/2019/05/23/self-h…
11
114
272
putsi retweeted
This was a great read, Stellar work @0xLupin
“Security researchers are doomed because of AI.” I kept hearing versions of this, so I went back through 500 years of people saying the same thing every time a machine learned a human skill. Some were idiots. Some were right. Here’s where I landed.
Article

security researchers are doomed.

Let me paint you the picture. Last weekend, Garance and I were walking back from dinner to the @defcon convention center, the biggest hacker conference on earth, to go see Hacker Jeopardy. That's

3
37
284
55,676
Modifying Burp Collaborator config file every time you need to host a new payload takes too much time. If self-hosted Burp collaborator could serve files from a web root directory like Nginx does, would you use it? (I’m gathering votes for a support case)
92% Yes
0% No
8% Don’t care.
12 votes • Final results
4
525
As promised, here's the first sneak peek into our new AI-powered features coming to Burp Suite Professional next month... 👀 🤫 First up, we have Explain This. #BurpAI #BurpSuite
8
26
246
21,513
Spamming "hi" at every LLM: a thread.
318
1,260
14,489
3,507,609
putsi retweeted
I bet a song composed and performed by an AI will be a Top 40 hit during this year.
22
12
139
38,972
This is how tears look like under the microscope. Insane
10
98
999
188,410
The first two weeks of the Vision Pro were absolutely insane. Here are 13 examples that prove the Vision Pro is the best piece of tech ever invented. 1) Real-time 3D surgery nitter.net/Medivis_AR/status/1712…
279
2,491
21,122
9,577,729
Check out our new blog post! We hacked into Apple Travel Portal (yes, again!) using a 0-day Remote Code Execution exploit. Part 1 is live now, stay tuned for the follow-up on another RCE worth a total bounty of $40k! blog.projectdiscovery.io/hel…
4
110
351
44,590
putsi retweeted
The SSRF/auth bypass affecting Ivanti Pulse Connect Secure (CVE-2024-21893), is a great example of what can be achieved with a fully blind SSRF vulnerability (RCE). Read the @assetnote blog here which includes a reliable payload and generation steps: assetnote.io/resources/resea…
3
84
346
32,821
putsi retweeted
I've made $500k+ from SSRF vulnerabilities. Here are my tricks:
84
1,203
4,393
443,614
PortSwigger Web Security disclosed a bug submitted by @mattaustin: hackerone.com/reports/127469… - Bounty: $3,000 #hackerone #bugbounty
19
115
24,212
Hackers, an important one. e.g.: we heard that CVSS "PR" is handled inconsistently (should be PR:None for self-sign-up). We're transparently listing a set of Detailed Platform Standards for consistency across programs. Need your help -- what to cover next? docs.hackerone.com/organizat…
10
27
105
52,647
Web Security vs. Binary Exploitation
97
1,867
10,034
835,369
As promised: Here's the first $10,000 @Intel bug (aka CVE-2022-33942) that allows to bypass the authentication of Intel's DCM by spoofing Kerberos and LDAP responses. Exploit inside, enjoy 🥳 rcesecurity.com/2022/11/from… #BugBounty #security
16
247
803
CVE-2023-21939 - Code Exec - PoC gist.github.com/win3zz/308c6…
3
87
376
35,778