bergee
@_bergee_
Followers
744
Following
3K
Media
54
Statuses
359
Webdev, bug hunter
Joined November 2017
My first CVE. Insecure deserialization and PHP objects injection in WP "Doubly" plugin. Thanks @wordfence . #cve
1
0
4
Today, thanks to @NahamSec I bought pretty solid VPS at @Hostinger for 2 years. It is Black Week deal so for $4,79 per month you got parameters as in the screenshot. I need it for bug bounty and hosting so if you need one here it is: https://t.co/ii9rgxuT0f
#BugBounty #deal
0
1
4
Dear bughunters. Have you ever heard about self-RCE? I did. I found RCE via command injection and the company said that it is self-RCE as the filesystem is isolated with some chroot and this RCE affects only the user's files. What do you think? #BugBounty #bugbountytips
0
0
0
https://t.co/mc8vSkjZSL The new write-up on credentials theft with XSS and Google Analytics. #bugbountytips #BugBounty #bugbountytip
0
1
2
Wbijaj na konferencję największej społeczności ITsec w Polsce! ✅ 4 ścieżki / ~40 praktycznych prezentacji, wiedza absolutnie z pierwszej ręki i bez ściemy ✅ Pokazy hackowania na żywo ✅ Jakość i niepowtarzalny klimat gwarantuje Sekurak ✅ 20 października w Krakowie:
0
9
35
I do recommend reading this blog. Good stuff. https://t.co/WgrdI3O7vt
#BugBounty
blog.voorivex.team
Voorivex's Team
0
0
1
How to read the files on server with zip files. The short story of zip symlink attack: https://t.co/XiEiUJrr4z Have a nice reading #bugbounty #bugbountytip #bugbountytips
bergee.it
Hi there There was an app which allowed me to buy domains and offered different types of hosting. First I was testing the free features of the app and found really cool XSS bug but it is the differ...
3
48
233
I found the crit on self-hosted program. Reading files on filesystem with unzipping the symlinks. Writeup soon. #bugbountytips #bugbounty #bugbountytip
3
0
13
How to get paid for subdomain takeover without taking over the domain... :) https://t.co/mZFgy2V2eb
#BugBounty #bugbountytips
bergee.it
Hello The title might have been clickbait but it is not. I started from recon and discovered as many subdomains as possible of the target.com company. Then I used dnsx tool to check all NXDOMAINS...
0
1
5
As Google wanted to close my developer account due to inactivity, I created this simple Dad Jokes app https://t.co/o7FO3xiFpF It is not so fast and easy to publish an app today. Pure Kotlin. No frameworks. #jokes #android #dev #Entertainment
play.google.com
A fun app that delivers endless dad jokes to make you smile
2
0
0
I updated my word game website. Now you can choose more categories and print the puzzles https://t.co/bBvojFwOZh
#wordle #puzzle #game #words #wordsearch #print
0
0
1
I have updated my game. Now you can play the clone of wordle: https://t.co/oUFZbeEYRx and the search word game: https://t.co/bBvojFwOZh
#wordle #words #games #PUZZLE #wordlees #indiegame
0
0
2
https://t.co/4BpdchIpDn Without experience in game dev I created this 3d zombie typo shooter using @cursor_ai and @ChatGPTapp. Type words to survive. Have fun. #indiegames #vibecoding #webgl #words #zombies
0
0
0
0
0
1
I am vibe-coding typo shooter 3d zombie game. We'll see how it goes. #indiegames #vibecoding #webgl #words #zombies
1
0
5
I've just updated my game. There are more categories. You can share puzzles. There is also better word marking experience, especially on mobiles. https://t.co/MtolWwZjeC
#games #Wordle #puzzles
0
0
3
This is brilliant extension for chrome to take frames of YT movie as screenshot. This way I can extract many useful tips and tricks from YT presentations regarding bug bounty. #BugBounty #bugbountytips #Extension #YouTube
https://t.co/SAPCAbnjZn
chromewebstore.google.com
Quickly extract video frames from YouTube and OK.ru and save to JPG images with just one click.
0
0
0
I created my first simple logic game - wordsearch puzzle. Feedback is welcome. Have fun. https://t.co/MtolWwZR4a
#game #puzzles #indiegame #fun
0
1
4
Good old SQL injection bugs are still here and there. My latest post on hacking one big company for fun and !profit. https://t.co/xoDGo8ZB3J
#bugbounty #bugbountytips #bugbountytip
bergee.it
I am a little bit late but Happy New Year 🙂 In the beginning of the year I decided to hack one company, let’s call it XXX as I can’t give the real name. The company is running VDP program and offers...
0
10
56