
yso
@0a_yso
Followers
632
Following
250
Media
55
Statuses
473
My crime is that of curiosity. Bug Bounty, Security Engineering, Dev and more Presented at Area41, DEF CON main stage, DEF CON Car Hacking Village
Zurich, Switzerland
Joined February 2019
💰 Just 10 public bug bounty reports paid researchers $26,075,042 - all in Web3/DeFi. These are some of the biggest public bounty payouts ever. We're collecting them - and hundreds more - at VulnIndex, now live: 1/6.#BugBounty #DeFi #AppSec #hacking
2
15
83
Oh wow, I just found out that @TechCrunch reported on a vulnerability 2 days after I discovered and reported. Despite that @OpenAI rejected me a bounty 🫠 #bugbounty.
techcrunch.com
A few ChatGPT users have noticed a strange phenomenon recently: occasionally, the chatbot refers to them by name as it reasons through problems.
0
0
0
Explore the alpha → (Mobile not yet supported).If you find it useful, like / repost / share so others in #AppSec and #BugBounty can too. #SecurityResearch #hacking #DeFi #infosec 6/6.
1
0
0
Who is Sadiq West and did they really get $500,000 bounty? Seems like a lie but if someone can confirm that - would love to hear. Link -> #bugbounty.
medium.com
A very simple to any pentester, but most ’em show no care about it and yet critical vulnerability to the company, i know it wasn’t very…
0
1
0
Just got to a 2nd place on the current Q3 at @yeswehack without submitting a single bug for more than 2 months :). Interesting situation
1
0
15
Parsed 12k+ bug-bounty write-ups & blogs (and counting 24/7) and mapped each to CWE + language. Quick hits:.• ~60% of RCEs happen in PHP/JS.• >50% of GraphQL bugs are plain access-control issues. Free site coming soon - reply "access" for an early invite! #bugbounty #hacking
149
22
240
If you ever want to get a similar database for free just follow and wait a few weeks as we are working on a product that will ship similar results for anyone to use and dig deeper into technologies they want #hacking #bugbounty.
If your GraphQL testing stops at introspection and ID swapping, you’re missing out. SQLi, CSRF, caching bugs, race conditions, WebSocket bypasses - it’s all there. I studies 90 real reports to find what actually works.
0
1
16
A single parameter in the OpenAI and Anthropic SDKs can let an attacker overwrite your AI agent's system prompt, hijack every response, and - in some cases - even open a reverse shell from your server. Check out: . #bugbounty #hacking #0day #aisecurity.
blog.ys0.dev
A single, unchecked parameter in the OpenAI and Anthropic SDKs lets an attacker overwrite your AI Agent's system prompt, take over every response, and, in some cases, open a reverse shell from your...
0
0
8
If you shared a ChatGPT chat link between April 16-18, your name may have been exposed - and it could still be publicly visible. Details on the privacy vulnerability in @OpenAI : #hacking #bugbounty #openai #chatgpt #airedteam #0day.
blog.ys0.dev
Sharing your chats has never been easier - you simply click Share, the conversation is anonymised, and you're clear to show what ChatGPT produced for you. There are no privacy implications - unless...
0
0
3
Am I just lucky? 2nd triage on @Bugcrowd and 2nd shit show in a row. The triager just makes 2 contradictory statements at the same time and there is no option to request a response from a customer???. #bugbounty #hacking #bugcrowd
1
0
3
I've never seen this happen on other platforms - only on @Bugcrowd today. Instead of engaging in a dialogue to fix the bug and coordinate disclosure, my message was perceived as a threat??? I guess I am going to be banned soon? 1/3. #bugbounty #hacking #disclosure #0day
2
0
10