zseano (@zseano) 's Twitter Profile
zseano

@zseano

#1 Amazon Security Researcher. hacking team with @jonathanbouman @fransrosen @avlidienbrunn

ID: 485460245

linkhttp://hackerone.com/zseano calendar_today07-02-2012 06:58:26

7,7K Tweet

77,77K Followers

687 Following

XBOW (@xbow) 's Twitter Profile Photo

Sometimes the most illogical approach wins. XBOW discovered XSS in Salesforce Aura by testing aura.format=JSON - which counterintuitively returns text/html content type instead of JSON. The kind of discovery that comes from systematic testing without assumptions. Full hunt

Sometimes the most illogical approach wins.

XBOW discovered XSS in Salesforce Aura by testing aura.format=JSON - which counterintuitively returns text/html content type instead of JSON.

The kind of discovery that comes from systematic testing without assumptions.

Full hunt
zseano (@zseano) 's Twitter Profile Photo

bug bounty industry is so fucking good these days… so many programs, good payouts, wide scopes. We are truly blessed 😇 get stuck in, there are bugs out there, and lots of them ! (And no AI isn’t close to replacing us, it’s helping us more than ever)

Sam Curry (@samwcyo) 's Twitter Profile Photo

When applying for a job at McDonald's, over 90% of franchises use "Olivia," an AI-powered chatbot. We (Ian Carroll and I) discovered a vulnerability that could allow an attacker to access the over 64 million chat records using the password "123456". ian.sh/mcdonalds

Ali Tütüncü (@alicanact60) 's Twitter Profile Photo

I know many of you aren’t fans of the new HackerOne dark mode. I’ve built a small Chrome extension to bring back the old look. There are still a few bugs (some purple elements remain), but I’ll be working on it more tonight. For now, it’s already a big improvement over the

I know many of you aren’t fans of the new HackerOne dark mode. I’ve built a small Chrome extension to bring back the old look.

There are still a few bugs (some purple elements remain), but I’ll be working on it more tonight. For now, it’s already a big improvement over the
zseano (@zseano) 's Twitter Profile Photo

another successful H1 event with the legend Jonathan Bouman, great bugs and gaining lots of new insights for future hunts! :) that's me done with hacking now til september, getting married in 2 weeks so i'm going afk to chill :D happy hacking, go get them crits✌️

zseano (@zseano) 's Twitter Profile Photo

XBOW has changed the bug bounty game tbh.. shits gonna get wild over the next few years! i can see lots of people having their own AI agents (I bet people are building one right now). kudos to them for being transparent on everything :)

shubs (@infosec_au) 's Twitter Profile Photo

Today, we're releasing the new Searchlight Cyber (Searchlight Cyber) tools website, which allows you to use several of our open-source tools for free via a web interface. You can self-register at tools.slcyber.io (+ all our wordlists will be released there from now on!)