Mayank.R (@mayankm0) 's Twitter Profile
Mayank.R

@mayankm0

MTS Vmware EUC/Omnissa

ID: 1507900444353654791

calendar_today27-03-2022 02:01:22

2,2K Tweet

632 Followers

2,2K Following

ghostlulz (@ghostlulz1337) 's Twitter Profile Photo

👻 Hacking SSO: Pre Account Takeover 👻 No email verification ➕ SSO 🟰 full account compromise. Read more on my blog: ghostlulz.com/blog/pre-accou… #bugbountytip #bugbountytips #hackerone #bugcrowd #infosec #redteam #CyberSec #bugbounty

payloadartist (@payloadartist) 's Twitter Profile Photo

🪲 Interesting SOQL injection bug in "contentDocumentId" parameter in Salesforce applications found by MasterSplinter, exposing user docs mastersplinter.work/research/sales…

🪲  Interesting SOQL injection bug in "contentDocumentId" parameter in Salesforce applications found by <a href="/m4st3rspl1nt3r/">MasterSplinter</a>, exposing user docs

mastersplinter.work/research/sales…
bugcrowd (@bugcrowd) 's Twitter Profile Photo

15 and hacking his way to an impressive portfolio. 😯 Patrick’s journey started early: “I got into technical writing at 11 after exploiting an info leak on my middle school’s website. It was simple, but it meant a lot to me back then,” he says. 💭 Get the full story and his top

15 and hacking his way to an impressive portfolio. 😯

Patrick’s journey started early: “I got into technical writing at 11 after exploiting an info leak on my middle school’s website. It was simple, but it meant a lot to me back then,” he says. 💭

Get the full story and his top
Intigriti (@intigriti) 's Twitter Profile Photo

New tool drop by Assetnote! 🛠️ Some instances only accept incoming traffic from 'trusted' sources such as AWS, GitHub/GitLab CI, etc. Newtowner is a simple tool to help bypass these weak IP whitelisting rules! 😎 Check it out! 👇 github.com/assetnote/newt…

New tool drop by <a href="/assetnote/">Assetnote</a>! 🛠️

Some instances only accept incoming traffic from 'trusted' sources such as AWS, GitHub/GitLab CI, etc. Newtowner is a simple tool to help bypass these weak IP whitelisting rules! 😎

Check it out! 👇
github.com/assetnote/newt…
Intigriti (@intigriti) 's Twitter Profile Photo

Latest Bug Bytes is live! 🚀 This month's issue is as usual packed with bug bounty tips: ✅ Becoming an Intigriti Pentester! ✅ Exploiting CORS in 2025 (and even when SameSite is set to ‘Strict’) ✅ A forgotten tool to quickly score new hidden endpoints (right before you close

Latest Bug Bytes is live! 🚀

This month's issue is as usual packed with bug bounty tips:
✅ Becoming an Intigriti Pentester!
✅ Exploiting CORS in 2025 (and even when SameSite is set to ‘Strict’)
✅ A forgotten tool to quickly score new hidden endpoints (right before you close
sw33tLie (@sw33tlie) 's Twitter Profile Photo

I don't know who needs to hear this, but if you have Param Miner installed in Burp Suite, you can use $randomplz anywhere (repeater, etc) to get a random value that can be useful as a cache buster #bugbounty

James Kettle (@albinowax) 's Twitter Profile Photo

"Funky chunks: abusing ambiguous chunk line terminators for request smuggling" - quality research by Jeppe Weikop! Also thankfully it doesn't overlap with my upcoming presentation 😅 w4ke.info/2025/06/18/fun…

Intigriti (@intigriti) 's Twitter Profile Photo

⏰ It's CHALLENGE O'CLOCK! 👉 Capture the flag before Thursday the 26th of June 👉 Win €400 in SWAG prizes 👉 We'll release a tip for every 100 likes on this tweet Thanks ToG for the challenge 👇 challenge-0625.intigriti.io

⏰ It's CHALLENGE O'CLOCK!
👉 Capture the flag before Thursday the 26th of June
👉 Win €400 in SWAG prizes
👉 We'll release a tip for every 100 likes on this tweet

Thanks <a href="/Toogidog/">ToG</a> for the challenge 👇

challenge-0625.intigriti.io
Intigriti (@intigriti) 's Twitter Profile Photo

Done with testing your target? Don't close Burp Suite yet! ❌ JSON2Paths by Somdev Sangwan can help you find a few quick bounties before you wrap up! 🤑 This simple Python tool helps you find hidden API endpoints and app routes by fetching Burp Suite's history! 🔗

Done with testing your target? Don't close Burp Suite yet! ❌ 

JSON2Paths by <a href="/s0md3v/">Somdev Sangwan</a> can help you find a few quick bounties before you wrap up! 🤑

This simple Python tool helps you find hidden API endpoints and app routes by fetching Burp Suite's history!

🔗
Doyensec (@doyensec) 's Twitter Profile Photo

📢Just published - Our new white paper comparing Semgrep's Code and Community editions! We dove into both versions of this popular tool to see what the differences were and how they performed against each other. doyensec.com/resources/Comp… #doyensec #appsec #security #semgrep

📢Just published - Our new white paper comparing <a href="/semgrep/">Semgrep</a>'s Code and Community editions! We dove into both versions of this popular tool to see what the differences were and how they performed against each other.
doyensec.com/resources/Comp…

#doyensec #appsec #security #semgrep
Intigriti (@intigriti) 's Twitter Profile Photo

For some bug bounty hunters, the Log4Shell hunt never truly ended... 😈 While most moved on, some researchers know this vulnerability is still hiding in production systems across the web, even today 👀 We just published a comprehensive guide showing exactly how to uncover

For some bug bounty hunters, the Log4Shell hunt never truly ended... 😈

While most moved on, some researchers know this vulnerability is still hiding in production systems across the web, even today 👀

We just published a comprehensive guide showing exactly how to uncover
Nikhil Mittal (@nikhil_mitt) 's Twitter Profile Photo

Hacker Summer 2025 giveaway! I am giving away a total of 3 seats for any of the highly coveted on-demand courses by Altered Security To participate - please Repost, Comment the course/certification name, what makes it useful to you and follow Nikhil Mittal and Altered Security

Hacker Summer 2025 giveaway! I am giving away a total of 3 seats for any of the highly coveted on-demand courses by <a href="/AlteredSecurity/">Altered Security</a> 

To participate -  please Repost, Comment the course/certification name,  what makes it useful to you and follow <a href="/nikhil_mitt/">Nikhil Mittal</a> and <a href="/AlteredSecurity/">Altered Security</a>
shubs (@infosec_au) 's Twitter Profile Photo

I hope everyone got some rest after DownUnderCTF this weekend. My colleague hashkitten wrote up a blog post on a novel technique for SQL Injection in PDO's prepared statements, required to exploit the “legendary” challenge, which only got one solve: slcyber.io/assetnote-secu…

Bug Bounty Village (@bugbountydefcon) 's Twitter Profile Photo

To celebrate our badge launch, we're giving away FIVE free 6-month licenses to @pentesterlab. ✅ Comment BADGELIFE and retweet this post to enter. Additionally, pre-order a custom badge at shop.bugbountydefcon.com for a chance to win one of FIVE Annual VIP+ subscription to