Anton (therceman)
@therceman.bsky.social
Bug Bounty Hunter www.therceman.dev
Bug Bounty Tip Parameter Manipulation: Email Link Hijacking Cheers!
Bug Bounty Tip Parameter Manipulation: Email Link Hijacking Cheers!
Help Jobert Abma to claim his account. Report fake one with the proof to this X post x.com/jobertabma/s...
x.com
x.com
Heads up that @jobertabma.bsky.social is an impersonator and y'all should report the account 🙄
My latest blog post is live! nastystereo.com/security/cro... Read how to send a cross-site POST without including a Content-Type header (without CORS). It even works with navigator.sendBeacon
You can now download preview edition of my bug bounty book with 3 tips & tricks book.therceman.dev Cheers!
You can now download preview edition of my bug bounty book with 3 tips & tricks book.therceman.dev Cheers!
Bug Bounty Tip XSS WAF Bypass by multi-char HTML entities fj translates to fj >⃒ translates to > + [?] <⃒ translates to < + [?] [?] - Unicode symbol
The "bug bounty hunters and content creators" starter pack is now up to 60 users! Follow this to get instantly connected to the bug bounty community & let me know if I've missed you off! go.bsky.app/GD7hKPX
Bug bounty hunters & content creators
Join the conversation
go.bsky.app
My bug bounty book is now available on Lemon Squeezy, offering more payment options for your convenience. Cheers!
In case you missed it...the DEF CON video of my talk 'Splitting the Email Atom' is finally here! 🚀 Watch me demonstrate how to turn an email address into RCE on Joomla, bypass Zero Trust defences, and exploit parser discrepancies for misrouted emails. Don’t miss it: youtu.be/JERBqoTllaE?...
DEF CON 32 - Splitting the email atom exploiting parsers to bypass access controls - Gareth Heyes
YouTube video by DEFCONConference
youtu.be
Bug Bounty Tip You can hide your XSS payload inside SVG or Math element to bypass the XSS Sanitizer or WAF filter Cheers!
Any bug bounty people around? I'm creating a starter pack of people to follow but it's pretty brief currently! Let me know if you'd like to be added: go.bsky.app/GD7hKPX
Book: Bug Bounty Tips and Tricks Vol.1 Edition: Pre-Sale Tricks: 18 Tips and Tricks Price: $13.37 (33% OFF) 🔗 book.therceman.dev
Some cool new additions at CSPBypass.com by omidxrz For example: cspbypass.com#onetrust <3
CSP Bypass Search
cspbypass.com
How many bug bounty hunters and penetration testers are here? 😀