Cyber Security Researcher - Red Team Member at Synack

Joined November 2016
Hello all security enthusiasts! During a recent security assessment for a private client, I came across a potential cross-site scripting (XSS) vulnerability that I wanted to share with you. 1/n #security #cybersecurity #penetrationtesting #informationsecurity #bughunting #xss
5
11
93
9,591
Shebiiiii retweeted
Just dropped a write-up on using Muse Code for Security Research with the folks at @metabugbounty and my good friend @phwd_ and @1_am_nek0 ! Particularly happy with the binary research section using @full_duplex's lldb-mcp with @clearbluejar's pyghidra-mcp 🔥🔥 bugbounty.meta.com/en-gb/lea…
2
31
1
161
7,597
Shebiiiii retweeted
Comment some of your best resources for prompt injection vulnerabilities! 👇
10
8
1
77
7,632
Shebiiiii retweeted
Added more training to the AI-CTF (it won't be fast but you can run this on a halfway decent laptop) - github.com/mubix/ai-ctf It teaches prompt injection and other paths prompt injection can take. All the answers are in the repo so it isn't about getting the flags but learning.
14
63
1
327
16,901
1/ Applied Agentic AI Security - Lab #2 I asked my AI agent for another customer's data. It gave it to me. No jailbreak. No prompt injection. Just broken authorization. Field Guide: rewanthtammana.com/who-let-t… Thread 🧵
14
12
26
1,097
🚀 Just released 𝗪𝗵𝗼 𝗟𝗲𝘁 𝘁𝗵𝗲 𝗔𝗴𝗲𝗻𝘁𝘀 𝗔𝗰𝘁? 🤖 An open-source Agentic AI security lab to break, inspect & learn AI Agents Security. rewanthtammana.com/who-let-t… #AISecurity #AgenticAI #LLMSecurity
4
2
11
525
Shebiiiii retweeted
My tweets haven't gone viral in a while now, so I must drop this banger: reburp And yes, it's a game changer in applicative pentest and bug bounty. Following me was worth it. Know how BurpSuite's API does not expose all that burpsuite can do in the UI? and how their MCP isn't better? it lets you read findings but can't do the workflows. reburp is a small burp extension that uses the extension's access to the internal Montoya API object to re-expose it over a localhost OpenAPI REST API to bridge all that a burp extension can do, to your AI agents in seconds ! Your agent can now use burp's: - active scan, stop/start scans, fuzzing, turbo intruder - iterate entire sitemap tree - websockets - use tools like Generate CSRF PoC - use other extensions e.g. Autorize - Create custom Bambda rules and custom scanners My favorite: you can explore burp features you haven't found in the UI even after 10 years using it github.com/forefy/reburp
12
46
1
382
28,460
Shebiiiii retweeted
I've seen a lot of Active Directory environments in the last 5+ years. These are some of the most dangerous issues I recommend reviewing and addressing in your environment. Treat it like a check list. If you have 0 of these, you're doing a great job.
7
144
3
686
185,554
Shebiiiii retweeted
list a useful AI tool or plugin that every bug bounty hunter needs to try! 👇
9
14
156
18,358
Shebiiiii retweeted
When fuzzing is no longer treated as merely bruteforcing, you start to unlock meaningful results 🤠 From discovering hidden assets to turning unusual behavior into exploitable vulnerabilities! 😎 In our latest article, we've teamed up with Orwa Atyat (@GodFatherOrwa) to dive deeper into mastering web fuzzing for reconnaissance and vulnerability exploitation. Read the article now! 👇 intigriti.com/researchers/bl…
2
65
1
329
35,924
Shebiiiii retweeted
Hey Hunters, just released: Burp Unrestricted MCP Free and open source, for hunters running AI agents against Burp on long engagements. A fork of @PortSwigger's Burp MCP Server that adds the 8 tools an agent actually needs to work a target end to end. github.com/RamanMG/Burp-MCP-… #Bugbounty
3
64
341
16,633
Most bug hunters stop at X-Forwarded-Host and wonder why their cache poisoning reports get $500. Someone spent 6 months studying CDN architectures. Here's what separates $500 reports from $10,000+ critical findings: 🧵👇
3
67
1
481
28,021
إذا كنت تدرس HTB CPTS، فهذا المستودع يستحق يكون من أول المصادر عندك يحتوي على ملاحظات مفصلة لكل وحدة من مسار HTB Certified Penetration Testing Specialist (CPTS)، بالإضافة إلى Cheat Sheets مرتبة تساعدك أثناء المذاكرة واللابات. يغطي مواضيع مثل: ✅ Enumeration ✅ Active Directory ✅ Web Exploitation ✅ Privilege Escalation ✅ Pivoting & Tunneling ✅ Password Attacks ✅ وأكثر... سواء كنت تذاكر للمسار أو تستعد للاختبار، وجود مرجع سريع ومنظم مثل هذا يوفر عليك وقتًا كبيرًا 🔗 github.com/0x1ceKing/HTB-Cer…
3
61
1
404
19,702
إذا كنت تستعد لـ OSCP أو CPTS، فهذا من أفضل المستودعات المجانية اللي تستحق تضيفها للمفضلة 🔥 📚 يحتوي على ملاحظات مرتبة تغطي: • Enumeration • Privilege Escalation • Active Directory • Pivoting • Web Exploitation • وغير ذلك الكثير... المميز فيه أنه يركز على المنهجية (Methodology) أكثر من مجرد حفظ الأوامر، ويتم تحديثه باستمرار. 🔗 github.com/dollarboysushil/o… إذا تعرف مصادر مجانية بنفس الجودة، شاركها تحت التغريدة 👇
2
35
1
253
17,636
Shebiiiii retweeted
Yh in June I made only $5,160 from my i consistent hunts. These were mostly IDORs, OAuth and GraphQL vulnerabilities. I released some writeups you can read: $500 to $1,500 Email Verif Bypass: medium.com/@tinopreter/from-… $2,000 Web Cache Deception medium.com/@tinopreter/crack…
8
28
296
8,346
Shebiiiii retweeted
Want to learn AI / LLM Security Assessment? Don't have the money for a training? Here are 🎯SEVENTY ONE🎯 FREE LLM security labs that we have curated for you! Like and share! (Link Below) <3 from @arcanuminfosec
22
180
7
783
59,840