CTF Player. Bug Bounty as a hobby.

Joined October 2008
122 Photos and videos
Manoel Abreu retweeted
Giveaway brought to you by @hackinghub_io: 5x Blind XSS vouchers 5x Web Exploitation vouchers How to enter: 1⃣ Follow @BugBountyDEFCON subscribe to our YouTube channel 2⃣Follow @hackinghub_io 3⃣ ❤️ 🔃 this post 4⃣Comment this post Winners will be picked on Friday 8/29 Youtube channel: youtube.com/@BugBountyVillag… And if you made it this far, you might as well join our other social media channels and subscribe to our mailing list! it only takes a minute, and It helps us a lot, and makes possible to bring these giveaways to you. Mailing list: bugbountydefcon.com/mail TikTok: tiktok.com/@bugbountydefcon LinkedIn: linkedin.com/company/bugboun… Instagram: instagram.com/bugbountydefco…
140
140
276
30,166
21 Aug 2025
This is awesome!
21 Aug 2025
Hackers, To make our pricing fairer worldwide, we’re trying out localized pricing. We’re starting with Brazil 🇧🇷, with Individual plan prices dropping by about 50%. 💸 Monthly: ~110 BRL → 55 BRL 💸 Yearly: ~1,100 BRL → 550 BRL Which country should we do next? caido.io/blog/2025-08-21-loc…
3
259
6 Jan 2025
Delayed Christmas gift. 😅 Thanks @arthurair_es
The year kicked off with an insecure deserialization vulnerability, giving us RCE. Collaboration with @reefbr 🔥
1
1
48
3,220
20 Jun 2024
"Additionally we set Attack Complexity to High because the attack depends on the victim using a computer"
"Additionally we set Attack Complexity to High because the attack depends on the victim being authenticated in their default browser" - Shopify
9
961
15 Dec 2023
Nice technique.
15 Dec 2023
This is a very unknown technique. Tried googling it and found no results, so maybe even a novelty. This allows you to dump all domains from a Cloudflare user by doing nameserver correlation. Great for finding base domains owned by the company. celes.in/posts/cloudflare_ns…
9
916
Manoel Abreu retweeted
Google's Product Security Team (my broader team!) is hiring in Brazil! Here's the link for the Manager we want to hire there to start the team! google.com/about/careers/app…

1
31
71
23,506
Manoel Abreu retweeted
10 Dec 2023
tramoia.sh ??.??.2024
14
117
303
41,035
9 Dec 2023
Começamos a Village de Bug Bounty na @h2hconference ! Teremos adesivos e camisas da @Hacker0x01 . Bora! @arthurair_es @0xTeles
8
48
4,289
Manoel Abreu retweeted
27 Nov 2023
🚨 @Hacker0x01 Bug Bounty Village na @h2hconference!!!! A agenda da nossa village de bug bounty na H2HC já está disponível. Vamos ter talks absurdas com bastante história e tricks. Para participar dos sorteios que irão ocorrer, se cadastra aqui: h1.community/events/details/…
2
24
73
15,356
Manoel Abreu retweeted
It’s so bad that I wrote a thread 🧵 ⤵️
HackerOne disclosed a bug submitted by @bebiksior: hackerone.com/reports/218052… - Bounty: $2,500 #hackerone #bugbounty
5
68
184
75,765
27 Oct 2023
Vamos ter uma Village de Bug Bounty durante a @h2hconference . Quer nos contar sobre algum bug ou técnica? Por favor, submeta sua talk! Vamos ter o apoio da @Hacker0x01 ! forms.gle/b1qAzsqJmshffvnr7

Se você quiser participar da Village de Bug Bounty que estamos organizando (@reefbr e @0xTeles ) na H2HC envie sua talk! linkedin.com/posts/manoelt_h…
7
38
3,592
Manoel Abreu retweeted
👀 Want to win a @flipper_net? 🐬 Retweet and Like to enter to win! 🦾 #defcon
🙌🏼 Thank you to @flipper_net for adding to our epic RTV CTF prizes! #defcon
76
795
1,111
105,206
12 Aug 2023
E agora o @arthurair_es me deu 3 moedas para distribuir.
12 Aug 2023
Brasileiro na Defcon? Tenho uns adesivos do Clube do Brasil da @Hacker0x01 .
1
1
17
1,692
12 Aug 2023
Brasileiro na Defcon? Tenho uns adesivos do Clube do Brasil da @Hacker0x01 .
5
3
58
4,142
7 Jul 2023
A nice response from @FIRSTdotOrg !
1
1
10
1,267
4 Jul 2023
Our happiness was ephemeral. @FIRSTdotOrg (silently?) removed the `self-service provisioned accounts` statement! Take a look at the doc now and the doc in the webarchive. What happened? first.org/cvss/v4.0/specific…
21 Jun 2023
Good news, CVSS 4.0 spec has this line regarding Privileges Required (PR) : Self-service provisioned accounts, that may be necessary to attack a cloud service, do not constitute a privilege requirement if the attacker can grant themselves privileges as part of the attack.
7
13
35
28,740
22 Jun 2023
I know a person that will probably say “this is only for cloud service”!!!! :D For me, it was always clear that self-service accounts were None for PR. Good news it is crystal clear now.
21 Jun 2023
Good news, CVSS 4.0 spec has this line regarding Privileges Required (PR) : Self-service provisioned accounts, that may be necessary to attack a cloud service, do not constitute a privilege requirement if the attacker can grant themselves privileges as part of the attack.
8
1,115
25 May 2023
From a RCE in a lambda I got AWS keys. The keys had access to all CloudWatch logs. Triager: Medium. Program: Medium. Me: Clown, as I decide to not download the logs to try any other escalation, to avoid any concern. All the day upset about this.
5
4
71
10,839
25 May 2023
The triaged did not change the severity, but commented internally to the client to pay as medium. I have no idea why. Conclusion: If you don't know the program, go deep in your exploitation, download everything to show the proper impact. Scan the whole VPC.
8
836