OSWP,OSCP,OSWE/RedTeam/Bug Hunter

Joined January 2019
24 Photos and videos
1
56
fubxx retweeted
On non-rooted devices, critical data should never be left openly in the `/shared_prefs` file; it should either be moved to a secure area or kept encrypted in a sandbox. Failure to do so can pose serious risks (especially for financial applications). For Android applications, I strongly recommend learning about Frida or hooking techniques. @intigriti #bugbountytip #bugbountytips #infosec #recon #android
5
20
189
13,158
fubxx retweeted
Bypass CloudFront WAF rule blocking access to Spring Boot # All bypasses return real Actuator data: GET /actuator/health → HTTP 200 (5122B) ← 'a' encoded GET /actuator/health → HTTP 200 (5123B) ← 'c' encoded GET /actuator/health → HTTP 200 (5122B) ← 't' encoded GET /actuator/health → HTTP 200 (5123B) ← 'u' encoded GET /actuator/health → HTTP 200 (5123B) ← 'a' encoded GET /actuator/health → HTTP 200 (5123B) ← 't' encoded GET /actuatoor/health → HTTP 200 (5123B) ← 'o' encoded GET /actuator/health → HTTP 200 (5123B) ← 'r' encoded GET /actuator/health → HTTP 200 (5123B) ← double encoded GET /actuator/health → HTTP 200 (5123B) ← double encoded GET /actuator/health → HTTP 200 (5122B) ← fully encoded
4
71
427
29,512
fubxx retweeted
31 Dec 2025
2025年最后一天了,把博客装修了一下:gh0st.cn/,顺便前几天发了篇文章《黑盒视角下的 WebView 漏洞面探索》:gh0st.cn/archives/2025-12-26…

7
10
50
7,302
18 Dec 2025
A股与A片的9大共同点: 1、都很令人亢奋,过后进入贤者模式 2、上下幅度都很大 3、对大多数人都有害 4、必要时都要用嘴来吹 5、都会做激烈的俯卧撑 6、都到达高潮后一泻千里 7、长阳的时间都很短,一分钟就很不错了 8、搞来搞去其实交战双方都是为了出货 9、多数人都不喜欢带套,但最后还是被套上
332
14 Dec 2025
Orwa always shares extremely practical tips. Excellent.
Big #Bugbountytip / #bugbountytips Google Services Hunting Google services are amazing, and for bug hunters, it's amazing as well. In some cases, you can get some P1-P2-P3 from these services, such as Workspaces / Sheets / Groups / Drives / Etc... In groups: you can access emails / internal data/ credentials In Sheets, you can access PIIs / Edit access In Drive: you can access backups/ PII / Etc... still hard to find and It was an issue how to make good and at the same time fresh dorks for bug bounty programs Then I found out that a lot of links have the same path, and it was like this All Google resources I've found sites.google.com/a/domain.co… docs.google.com/a/domain.com… groups.google.com/a/domain.c… drive.google.com/a/domain.co… mail.google.com/a/domain.com… spreadsheets.google.com/a/do… spreadsheets0.google.com/a/d… spreadsheets1.google.com/a/d… spreadsheets2.google.com/a/d… spreadsheets3.google.com/a/d… spreadsheets4.google.com/a/d… spreadsheets5.google.com/a/d… spreadsheets6.google.com/a/d… spreadsheets7.google.com/a/d… spreadsheets8.google.com/a/d… UrlScan Dorking: page.url:"sites.google.com/a/*" page.url:"docs.google.com/a/*" You can replace * => the program domain Google Dorking: site:sites.google.com/a/* "inurl:/a/" Or for specific domain site:sites.google.com/a/* "inurl:/a/domain.com" GitHub Dorking: "sites.google.com/a/" Or for a specific domain "sites.google.com/a/domain.co…" Shodan Dorking: "sites.google.com/a" Web Archive web.archive.org/cdx/search/c… Don't forget: It's not just sites.google.com still you have to look for docs/groups/mail/drive/spreadsheetsX still working in Google Research and will add more and more soon ...... Happy Hunting♥ #bugbounty
1
173
fubxx retweeted
8 Dec 2025
You don't have to search the Google dorks one by one; just ask Gemini to do it for you. 😃
3
14
107
5,551
fubxx retweeted
~IDOR bypass techniques (*UUID protection) New video out too! youtu.be/EM7_ycB2Fjo #bugbounty
14
75
349
17,138
17 Jun 2025
出来就喜欢躺沟里
1
1
268
9 Jun 2025
This is disgusting. If H1 is banning people because of their race, they don’t deserve to call themselves a “global platform.” Shame on you, H1.
8
826
5 Jun 2025
瓜。不知道真的假的
146
30 May 2025
《A股圣经》
159
30 May 2025
Good tips!
30 May 2025
12 API hacking bug bounty tips you must try on your target! 😎 🧵 👇
1
229
23 May 2025
2
66
2,274
18 May 2025
牛逼 还能这样
When a single ID fails, a pair might pass. IDOR bypasses can be that simple 🔥 - Victim's ID: 5200 - Attacker's ID: 5233 GET /api/users/5200/info → Access Denied ❌ GET /api/users/5200,5233/info → Bypassed ✅ #bugbountytips #PenetrationTesting
1
299
9 May 2025
I earned $300 for my submission on @bugcrowd
1
6
224
5 May 2025
🌉
1
166
fubxx retweeted
I'm a big big fan of the bug bounty tips posted by @intigriti Here's 8 bug bounty tips posted by them that I feel you all should keep in your fingertips. 🧵👇 #bugbounty #cybersecurity #infosec #bugbountytips
22
128
347
59,181