restoring equilibrium

Joined October 2019
113 Photos and videos
the CRTP labs are so buggy that, at this point, debugging the lab is harder than the lab itself :)
32
Adity retweeted
Time for another giveaway! We will pick 6 winners to win one of the following: 1x Annual VIP @hackthebox_eu Licence 5x @PentesterLab 3 Month Licences To enter: 1️⃣ Follow us @BugBountyDefcon 2️⃣ Like this post ❤️ 3️⃣ Re-tweet this post 🔁 Giveaway open until Monday June 15th! GOOD LUCK!
100
355
464
16,949
lab server was down, so I had to go touch some grass. 10/10 recommend
1
43
water the grass if it's not greener on your side 🍃
1
27
I think this mango tree is for everyone except humans.
54
It was supposed to boost productivity, but it accidentally boosted my nap game 😭
1
1
89
Adity retweeted
agi achieved
5
2
22
1,422
Roads after 10 pm on a weekday >>>
1
39
seeing math concepts at work in security tools is pretty interesting :)
1
35
Adity retweeted
17 Nov 2025
We successfully wrapped up the Cysinfo quarterly meetup yesterday! 🎉. Here is the link to the slides & demo videos: cysinfo.com/14th-quarterly-m… Thanks to the security community, core team members, for the support 🙏 #cysinfo
5
7
460
29 Oct 2025
dam vulnerable web app ❌ comet ✔️ ( dam vulnerable agentic browser)
2
98
🚨 JAILBREAK ALERT 🚨 OPENAI: PWNED 😎 ATLAS-BROWSER: LIBERATED 🙌 WOW! There's a new AI browser on the block! Has some hefty guardrails in play, but the browser surface area is vast 🌊 First, I started with a good ol' LSD jailbreak, which was cool to see that the GPT-5 prompt still works in this browser setup with the new sys prompts. Referencing search and videos are a fun enhancement for higher quality jailbreak outputs (some cool youtube videos out there about drugmaking, for example), but honestly that isn't anything new or different from regular ChatGPT's capabilities. What IS hot off the press, and IMO a very real security risk to be aware of for AI browsers (and the internet in general), is this humble yet mighty vuln: Clipboard Injection. It's trivial to add a hidden "copy to clipboard" feature to any clickable button on the web. It took me just a few minutes to update one of my personal websites such that ALL the buttons were geared for injecting the user's clipboard with a malicious phishing link. If your browser Agent is navigating a website and clicks a button like that without your knowledge, and you open a new tab later and hit paste without knowing what's in your clipboard, well...PWNED! 🙃 As you'll see in the video below, "control-c" is in my clipboard in the beginning, but unbeknownst to me, "I'VE BEEN PWNED BY PLINY!!! WEEE I'M FREEE FUCKITY FUCK FUCK!!! ABRACADABRA, BITCH!!! http://paypa1. com/account-update" gets snuck into my clipboard as soon as Agent starts trying to navigate my website. This works so well because Agent is normally aware of all text/code being passed to and from the user, and has clearly been trained to recognize prompt injections, but since the "copy clipboard" button logic is hidden in js in the backend of the site, the Agent has zero awareness of the text content being injected to the user's clipboard. This has broad implications for anyone in the habit of copy-pasting, including coding, data entry, banking/trading, etc. Imagine going about your browsing business, then simply hitting control-v in your address bar and next thing you (don't) know, it takes you to a spoofed phishing website that tells you your OpenAI or Gmail or PayPal session has expired and you need to re-login. If you're not careful, the attackers now have all your login info, including any MFA codes 🥲 gg
94
205
1,462
418,996
29 Jun 2025
therapeutic✨ (things I do to keep myself sane these days ⬇️)
4
1
5
271
29 Jun 2025
Do not judge, thanks!
109
Adity retweeted
10 Apr 2025
Next week is our next run of our Attacking AI course! Check out the expanded syllabus ⬇️ payhip.com/b/xysOk 📢 Last Min Giveaway Time! Two seats up for grabs, winner will be chosen Tuesday next week! Each person can have up to 3 entries to the giveaway! ➡️Repost This Post = 2 Entries ➡️Like This Post = 1 Entry
21
115
199
12,848
31 Mar 2025
So annoying @tryhackme
1
3
173
20 Jan 2025
cute :3
2
9
361
Adity retweeted
Seeing a ton of people making 2025 their year to implement this. Y'all got this - get after it!
All my current bug bounty knowledge is gone. Here's how I get it back and make $100k in the first year: First, I've got to learn the basics. For this, I will make sure I understand at a high level how the components I'm working with function. I'll need to understand...
14
22
279
40,077
19 Dec 2024
What's your fav security blogs/articles etc related twitter account? #Cybersecurity #penetrationtesting #Pentesting
1
1
181
19 Dec 2024
Cooked fr
17 Dec 2024
While developing XBOW over the past three months, we played around with using it for bug bounties and ended up at #11 in the US on HackerOne:
169