
Johan Carlsson
@joaxcar
Father and full time bug hunter 🐞 currently on joaxcar.bsky.social
ID: 1478102382911311872
https://joaxcar.bsky.social 03-01-2022 20:35:31
1,1K Tweet
5,5K Followers
178 Following

Haven’t found any great bugs this week, but I got a mention in this Gareth Heyes \u2028 post and that just as great! Give it a read



Ben Sadeghipour The most valuable thing iv learned that reaches way beyond bounties is expectations management! its never personal. If a report gets valued in a different way than you wanted, or the triager dont understand the impact. work on your soft skills. i know it sounds off, but being






An interesting take on the behavior of SAAS companies to put security features in paid plans by Rasmus Holm. With an accompanying "name and shame" list

Was a blast hanging out with Bug Bounty Reports Explained a few hours in gray and cold Gothenburg! Glad that we finally got to meet in real life



SSRFs can be tough to make critical without metadata, especially against a target like GitLab that strengthens its infra with every SSRF. Yet Johan Carlsson broke through with the first critical SSRF on GitLab since 2020. Enjoy our explanation from Sweden🇸🇪🔥 youtu.be/YQ5ixykKnyY
