Full-Time Bug Bounty Hunter | Out of Scope Enthusiast | Top 100 @intigriti

Joined May 2020
8 Photos and videos
Saltify πŸ§‚ retweeted
BountySync Social was an absolute blast! 🀠 Last week at our new London office, we brought together researchers and security teams for a day packed with conversations, cocktails, and ice cream! πŸ˜„ A huge thank you to our host @appSecExp, guest speaker @CristiVlad25, and our very own Chris Holt and Greg Jenkins for leading a great multi-perspective discussion on AI and bug bounty! 😎 Thanks to everyone who joined us & see you at the next one! πŸ‘‡
1
4
26
2,314
Saltify πŸ§‚ retweeted
May 19
Caido projects bloat across engagements. Project Minify by @saltify_ Copy the essentials in one Project, Paste them in another. Bring only Scopes, Filters, Replay Sessions, Match & Replace rules and Environments. Give it a try πŸ”— github.com/saltify7/Project-…
1
25
2,288
Saltify πŸ§‚ retweeted
Bug hunters of Manchester β€” this one's for you! Join us for an in-person @HackerOne community meetup on 6th June. Network with fellow hackers, swap war stories, and level up your bug bounty game. h1.community/e/mgtbmn/ #BugBounty #HackerOne #Manchester #InfoSec
1
8
1,032
πŸ’€πŸ’€πŸ’€
I see some weird things but this takes the biscuit. A vulnerability in the Companies House website, that let anyone view the private dashboard of any one of the five million registered companies, see directors' personal details. And modify them.
1
97
Saltify πŸ§‚ retweeted
time to lock in and pollute the training data boys
6
9
171
14,327
Being 1 report late is the peak bug bounty experience πŸ˜‚
4
44
2,389
Big congratulations to everyone at the #1337UP1125 LHE in Belgium, and thank you to @intigriti for hosting such an amazing event! πŸŽ‰
2
12
828
I've created a @CaidoIO plugin to reduce Project File size by copying data (Scopes, Filters, Replay Sessions, M&R rules) into a new Project. Let me know if anyone has any issues! #BugBounty github.com/saltify7/Project-…
2
8
939
Finally made it to Top 100 on the All Time @intigriti Leaderboard!
3
10
427
I have released a new @CaidoIO plugin for table-based Authorization/Access Control testing. Feel free to check it out and let me know of any issues or feature requests! github.com/saltify7/Authify #BugBounty
2
5
16
2,175
Just scored another bounty @intigriti and hit 1234 rep Next goal: Top 100 on all-time leaderboard
3
367
Saltify πŸ§‚ retweeted
19 Apr 2025
This is 100% true in most things. Especially bug bounty.
18 Apr 2025
new one minute blog: the big lie about competition
2
17
223
15,012
Saltify πŸ§‚ retweeted
17 Apr 2025
Are you a Burp Repeater power user? The latest release introduces a new feature called 'Custom actions'. With these you can quickly build your own repeater features. Here's a few samples I made for you:
18
86
542
41,393
Saltify πŸ§‚ retweeted
"I built a SAAS in 3 days with 0 coding knowledge using AI. Developers are obsolete." Their project:
263
2,518
28,253
1,298,839
Happy to have finished in the top 15 on the leaderboard for Q1 2025 - thanks @intigriti for the great platform!
2
2
261
Saltify πŸ§‚ retweeted
Pentesters must rebrand themselves as Vibe Checkers.
45
296
2,805
104,691
Feel free to check out my recent bug bounty write-up!
I just published another bug bounty write-up detailing my recent experience learning XSS: "From β€˜alert(1)’ to Account Takeover: A Story of 4-digit Bounties and Bypassing HTML Sanitisers" medium.com/@saltify/from-ale…
3
487
I just published another bug bounty write-up detailing my recent experience learning XSS: "From β€˜alert(1)’ to Account Takeover: A Story of 4-digit Bounties and Bypassing HTML Sanitisers" medium.com/@saltify/from-ale…
5
654
New bug bounty achievement: - Submit a report - 90 minutes later the program posts an announcement - "New domain added to Out of Scope" - *It's the same domain* - πŸ™‚πŸ‘
2
2
251
What are the chances that as LLMs get better at coding and more production code is AI-generated, the most effective methodology for finding high-quality vulnerabilities switches from "What mistakes would a programmer make?" to "What do LLMs usually get wrong about security?"
1
229