YourFinalSin Profile Banner
3NVZ Profile
3NVZ

@YourFinalSin

Followers
4K
Following
1K
Media
47
Statuses
742

Dark Artist in the Making.

California
Joined August 2024
Don't wanna be here? Send us removal request.
@YourFinalSin
3NVZ
3 days
Just found an unauth SSRF, I accessed cloud metadata with💥. 1. Found a sub that used a third-party framework.2. Got the source code of the framework on GitHub.3. Code base had a SSRF sink that took in controllable input.4. Checked live target -> Access to internal/cloud metadata.
13
7
170
@YourFinalSin
3NVZ
7 days
Today was a good one
Tweet media one
6
1
138
@YourFinalSin
3NVZ
13 days
For anyone interested in Desktop Application Hacking - I found this talk to be a nice introduction:.
3
27
211
@YourFinalSin
3NVZ
19 days
Here is the full writeup on my full Bug Bounty Challenge, I documented. I hope this will answer all questions I keep receiving:.
Tweet card summary image
medium.com
Upon multiple requests, I will summarize my bug bounty journey here for you.
3
29
202
@YourFinalSin
3NVZ
1 month
Was looking today into Cache Poisoning/Deception and found these resources, which I think are going to be pretty helpful:.
4
30
165
@YourFinalSin
3NVZ
1 month
Just achieved a full ATO via XSS by bypassing Cloudflare WAF. Credits to @KN0X55 .The payload that bypassed the WAF was:
Tweet media one
5
15
258
@YourFinalSin
3NVZ
1 month
0
0
11
@YourFinalSin
3NVZ
1 month
but I also want to get into research and more low level stuff.- Still going to keep working hard every day and I will still keep posting, if I find something interesting.- There are also still 3 payouts pending which will be 2-3k USD.- Writeup will follow. Thanks to everyone ✌️.
3
0
33
@YourFinalSin
3NVZ
1 month
Day 150 - Bug Bounty. - Today will be my last post for this challenge, because I’ve achieved already all the goals I wanted to achieve .- I’m thanking everyone who followed along and I thank @techycodec08 who I got the initial idea from.- I will keep bug bounty hunting,. 1/2.
22
1
171
@YourFinalSin
3NVZ
1 month
Day 149 - Bug Bounty . - Got paid for one issue today 🎉.- Also found an access control issue on a main app in combination with a low entropy token.- Kept trying to go for a RCE on an open-source program, without success so far. Total earned so far: $5650
Tweet media one
4
8
270
@YourFinalSin
3NVZ
1 month
Day 148 - Bug Bounty . - Exploited today a Paddle Oracle which was pretty interesting and new.- Did source code review and found a promising reachable sink, which I kept working on.- Continued working on my source code lead automation. Total earned so far: $5425.
4
2
86
@YourFinalSin
3NVZ
1 month
Day 147 - Bug Bounty. - Kept going at a main application and found a couple of minor issues/gadgets.- One report came back as duplicate.- Found a potential RCE and worked on it multiple hours, just to realize that it wasn't exploitable at the end 💀. Total earned so far: $5425.
1
2
100
@YourFinalSin
3NVZ
1 month
Day 146 - Bug Bounty. - Focused today on auth and OAuth issues.- Went deep into different OAuth flows, such as implicit, auth code grant, etc. - Found this presentation on OAuth sec which I think was very good and technical:. Total earned so far: $5425.
2
4
105
@YourFinalSin
3NVZ
1 month
Day 145 - Bug Bounty . - Full day of hunting again today.- Focused mainly on auth and logic bugs.- Went through every feature and hunted with a goal, which helped thinking of different bypasses. Total earned so far: $5425.
2
3
121
@YourFinalSin
3NVZ
1 month
Day 144 - Bug Bounty . - Went today deep in authentication flows.- Learned a lot about different edge cases using different encoding/null bytes.- Found this repo, which constantly updates the best ATO H1 reports:. Total earned so far: $5425.
Tweet card summary image
github.com
Top disclosed reports from HackerOne. Contribute to reddelexc/hackerone-reports development by creating an account on GitHub.
4
40
271
@YourFinalSin
3NVZ
1 month
Day 143 - Bug Bounty . - Kept hunting on a main application today.- Found an email verification bypass which made pre-account takeover possible .- Played around with some secret detection automation. Total earned so far: $5425.
3
0
109
@YourFinalSin
3NVZ
1 month
Day 142 - Bug Bounty . - One report was triaged, it was a blind SSRF on a public target.- Focused today mainly on the authentication flow and logic of the app.- Found minor issues, but nothing reportable. Total earned so far: $5425
Tweet media one
9
2
128
@YourFinalSin
3NVZ
2 months
Day 141 - Bug Bounty. - Kept hunting today and only found a couple of gadgets.- Target seems pretty hardened.- Also kept on reviewing source code and for everyone asking, I found this to be an excellent resource for code review. Total earned so far: $5425.
2
2
87
@YourFinalSin
3NVZ
2 months
Day 140 - Bug Bounty. - Started on a new target today .- Went deep into the docs to understand the app first.- Found a couple of interesting gadgets.- Came across this blog post which was nice:. Total earned so far: $5425.
3
2
81
@YourFinalSin
3NVZ
2 months
Day 139 - Bug Bounty. - Continued reviewing source code.- Learned specifically about Python sinks that lead to code execution.- Was able to find code execution on a target with over 2000 stars on GitHub, but they don't pay bounties. Total earned so far: $5425.
8
1
103