
Andrew Gömez
@red_darkin
Sushi. Skate. Ingeniería. offsec
ID: 191150299
15-09-2010 18:39:05
976 Tweet
209 Followers
798 Following



I'm excited to introduce the Damn Vulnerable MCP Server (#DVMCP) 🥳 a practical and accessible platform designed to help you explore common pitfalls and vulnerabilities in MCP implementations 🥷🥷🥷 github.com/pfelilpe/DVMCP HackerOne OWASP GenAI Security Project - Top 10 For LLM Apps OWASP® Foundation




403 on /get_all_users 404 on /get_all_userz Then Justin Gardner fuzzed until a double-encoded “S” slipped past the NGINX filter. Result: 4.5M users' PII dumped. Bounty: $15K–$20K Full talk → youtu.be/PXqlHAoF2wc #BugBounty #DEFCON #BBV #AppSec #WebSecurity







A shout-out to our newest Brand Ambassadors in the US & South America! 🇵🇪 Kawiri (Peru—new club!) 🇧🇷 caon & 🇧🇷 SGT_ (Brazil) 🇨🇴 Andrew Gömez (Colombia) 🇦🇷 criptex (Argentina) 🇺🇸 xssdoctor (US North) 🇺🇸 Gunnar Andrews & 🇺🇸 Nehal Pillai (US South) 🇺🇸 zero-trace


