Jacolon Walker

@calleax.bsky.social

One to Zero Chronicles Ex-founder | Security Researcher | 👨‍🌾 Homesteader Blog: blog.stellersjay.pub X: https://x.com/call_eax mastodon: https://infosec.exchange/@CALLEAX

Pro Tip: Dive into bug trackers. Huge value in studying previously reported and resolved bugs with security impact (vulnerabilities). Why it's great: - Learn unfamiliar subsystems. - Follow real-world PoCs from start to finish. - Apply insights directly to your own targets. Sharpens skills.

Mythical API defense 🧌 found: - Found a forbidden (403) path - Check for subpaths beyond that - Found an image - Sub-sequential response length grew from 1034 to 830319 🙃 Great defense or it's a bug...

Bug Hunting Tip: - 💯 Build your own API wordlist. - Why? Public lists are too well-known and overused. - Craft one tailored to your hunt for a competitive edge. - Don’t forget to test these wordlists on URL subpaths, you might uncover unique bypasses. #bugbountytips

It's important if code auditing to have >= 2 different projects that are unrelated to each other for reviewing. It helps keep you fresh and away from exhaustion. Also I would throw in a coding project as well which may or may not be related. #infosec

A lot of my time is spent diving into security advisories -> issues trackers -> code diffs (patches) to see how downstream consumers resolve bugs. I actually enjoy this part of the research as it paints the story of a bug turn potentially exploitable