Independent Security Researcher | Checkmarx Sales Engineer | lover of all (most) Whiskey

Joined September 2008
4 Photos and videos
27 Sep 2022
I never post on here but here's an update on how today was going and went.
Reminder: Block your calendars for this session with @Checkmarx experts @jossefharush and @ErezYalon at @RSAConference. Explore “The Simple, Yet Lethal, Anatomy of a Software Supply Chain Attack” with us. Details are here: bit.ly/38ntTHK #CheckmarxAtRSA #RSA2022

1
JustinRuth retweeted
More than 280 million people suffer from depression worldwide. Over 700 000 people die due to suicide every year. Suicide is the fourth leading cause of death in 15-29-year-olds. (WHO/2021) If you feel depressed, alone, or lost, there is help to get. You are not alone.
20
65
299
JustinRuth retweeted
This is @codingo_ 's first video and comprehensive written guide. His guide to ffuf is actually more comprehensive than the ffuf readme! I can see his content becoming the ultimate reference guide for hacking/bb stuff. Follow/sub to him everywhere!
I just spent over a month crafting the ultimate guide to Fuff. It is such an incredibly powerful tool, and I bet you're not using all of the features to full advantage! Video: youtube.com/watch?v=iLFkxAmw… Written guide: codingo.io/tools/ffuf/bounty… #bugbountytips
1
8
64
30 Apr 2020
Question for #bugbounty #BugBountyTips would you submit exposed source code (.jsx files) via the browser? Only appears on a certain page and seems like the full app. Not seeing any keys but tons of endpoints as well as custom code and full node_modules folder.
1
2
22 Apr 2020
dang today became such a better day when I realized I could use _ in SED instead of / echo '"google.com"' | sed 's_"__g' is the same thing as echo '"google.com"' | sed 's/"//g' substitute all double quotes with nothing. #linuxnoob

31 Mar 2020
Hit 2 personal goals today on @Bugcrowd 1. Top 1000! 2. Pass 2019 earnings in 2020. set personal goals you can celebrate, the more obtainable the better! #BugBounty
3
22
26 Aug 2019
Thanks for summarizing and sharing!
As per the vote results, here you go! A cool XXE resulting from a SSRF found on local company website during a pentest. DMs are open, retweet and like if you love this style of PoC! 😎 #bugbounty #bugbountytip #bugbountytips #infosec
24 Aug 2019
If javascript: is being filtered try some other payloads that might still work in <a href='payload'> java script: java script: java script: anything others? #bugbounty #bugbountytips
4
11
29 Jul 2019
Over the last couple of weeks I had some down time and got the itch to hit some Bug Bounty programs. Reported a couple of vulnerabilities which ultimately lead to my first payout! Thanks @Bugcrowd ! #bugbounty
1
2
29 Nov 2018
Had an amazing time with the UNT Cyber Security Club talking about buffer overflows! lnkd.in/e54givk

1
whoops... Good to know =) x.com/kalilinux/status/95951…

2 Feb 2018
If you don’t update Kali regularly (*cough*), then your archive-keyring package is outdated, and you’ll get key mismatches when working with our repositories. Sucks for you, but at least you can manually update the new key : wget -q -O - archive.kali.org/archive-key… | apt-key add <3
First accepted bug submission at @Bugcrowd. Hopefully more to come!
1
2
JustinRuth retweeted
#howtohack Our first session of the day! @CompozedLabs @Allstate
2
5
Demoed exploitation of CVE-2017-5638 (Struts2) at learn expo today. Went well but I wonder how others demo vulnerabi…lnkd.in/ep4usa4
Hi all, A friend and colleague is looking to move into a sys admin role in the North Texas area please share or message me if you have any…