It's Steiner254 (@steiner254) 's Twitter Profile
It's Steiner254

@steiner254

Fellow @XYSecLabs & @Shield_Hackers | Developer & PenTester | EX - @varonis | Smart Contract Auditor | Bug Bounty Hacker 🙂 Honoured By @UN, @Huawei e.t.c

ID: 1319372923627577344

linkhttps://github.com/Steiner-254/ calendar_today22-10-2020 20:20:16

13,13K Tweet

5,5K Followers

673 Following

H4x0r.DZ (@h4x0r_dz) 's Twitter Profile Photo

Use google dork "site:join.slack.com" you will find tons of exposed invitation links to workspaces. you can join these workspaces even if the option "Require admin approval" is on. because these leaked invites are made by the admins it Self

staykov (@dinkostaykov) 's Twitter Profile Photo

[Day 12] Of Starting My Career As Web3 SR. -72% of Patrick's Security Course Covered -Covered -> Flash loans, Arbitrage , Centralisation vulnerability, upgradeability of smart contract, proxy contract -Everything writen down in my notes for easy access

Massimo (@rainmaker1973) 's Twitter Profile Photo

Fun fact. In Lugano, Switzerland, there's a striking statue celebrating the anonymity of Satoshi Nakamoto, the mysterious creator of Bitcoin. Designed by Valentina Picozzi, when viewed head-on, it disappears almost entirely.

Gotcha1G (@gotcha1g) 's Twitter Profile Photo

Just dropped my first write-up! Found a juicy auth bypass that gave me admin access through response tampering. Check it out and let me know what you think! medium.com/@arrasgotcha/a… medium.com/@arrasgotcha/a…

Just dropped my first write-up!
Found a juicy auth bypass that gave me admin access through response tampering.

Check it out and let me know what you think!
medium.com/@arrasgotcha/a…
medium.com/@arrasgotcha/a…
bugoverflow (@bugoverfl0w) 's Twitter Profile Photo

How to grab all Graphql query/mutation if introspection disabled? 1. Download all js files to directory js_files 2. Run this command: grep -Eo '(query|mutation) [a-zA-Z0-9_]+\(' js_files -R 1/n #bugbountytips #graphql

How to grab all Graphql query/mutation if introspection disabled?

1. Download all js files  to directory js_files
2. Run this command:
grep -Eo '(query|mutation) [a-zA-Z0-9_]+\(' js_files -R

1/n 
#bugbountytips #graphql
Patrick Collins (@patrickalphac) 's Twitter Profile Photo

I’m seeing more and more of the new wave of top security researchers come from Cyfrin Updraft. Keep crushing it all, and we will do our best to keep making your lives as researchers better 🦾

Godfather Orwa 🇯🇴 (@godfatherorwa) 's Twitter Profile Photo

Video of my talking in #PHDays at PT Security youtu.be/CJnXjWXXB1Y?si… Hope you like it and enjoy it #bugbounty #bugbountytip #bugbountytips #infosec

XSS Report (@xssreport) 's Twitter Profile Photo

🚨 PRO TIPS for XSS Hunters Stop pasting the same alert(1) everywhere! 🙅‍♂️💻 ✅ First, ask: Where does your input land? 📝 In a <textarea>? 🔒 Inside an attribute? 📄 Between tags? 🎯 Tailor your payload to the context. It’s not about luck — it’s about logic 🧠 </textarea><script

¯\_(ツ)_/¯ (@chocapikk_) 's Twitter Profile Photo

Just released WPProbe v0.6.0! It now includes a bruteforce mode and a hybrid scan (REST endpoints + bruteforce). Check it out: github.com/Chocapikk/wppr… (Thanks ibrahimsql for the PR)

Just released WPProbe v0.6.0! It now includes a bruteforce mode and a hybrid scan (REST endpoints + bruteforce). Check it out: github.com/Chocapikk/wppr… (Thanks <a href="/ibrahimsql/">ibrahimsql</a>  for the PR)
Kalp (@kalp_eth) 's Twitter Profile Photo

1. Deflation attack in Silo Labs (v2 is live) vault during a Code4rena contest Share = _assets.mulDiv(_newTotalSupply + 10^_decimalsOffset(), _newTotalAssets + 1, _rounding) What the problem here? totalAssets is based on redeemable market shares, but market rounding can cause an issue