commando_skiipz Profile Banner
Ghost St Badmus Profile
Ghost St Badmus

@commando_skiipz

Followers
8K
Following
43K
Media
1K
Statuses
30K

Just a random guy, tweeting in front of the world. Sr. Application Security Engineer (API, Mobile, Web, Cloud, AI/ML) 💼. Creator (https://t.co/AspazxJI26 & https://t.co/pgYmTW2JVL)

…in your infra
Joined January 2019
Don't wanna be here? Send us removal request.
@commando_skiipz
Ghost St Badmus
5 months
I built an intentionally vulnerable banking application for security engineers/interns, developers, & QA analysts to learn, practice secure code reviews, and test their application security knowledge in areas such as SQLi, XSS, CSRF, race conditions, API vulnerabilities, & more.
Tweet media one
Tweet media two
Tweet media three
Tweet media four
@commando_skiipz
Ghost St Badmus
6 months
Where are the hackers/code reviewers? How many vulnerabilities can you spot in this code?.Apart from the hints, are there other places you can exploit? .Can you chain the vulnerabilities?
Tweet media one
Tweet media two
14
82
314
@commando_skiipz
Ghost St Badmus
7 minutes
Omo!!!!!!! You people didn’t tell me Call of Duty is this interesting and insanely addictive. What the fokk?! 🤯🔥.
2
0
2
@commando_skiipz
Ghost St Badmus
3 hours
RT @faechi_: I've been wanting to do things differently so here is to retracing my steps in my Cybersecurity journey. While I wait for the….
0
2
0
@commando_skiipz
Ghost St Badmus
4 hours
Some developers and security engineers in a certain industry won’t be happy I’m sharing this trick. But hey! fix your security implementations and stop relying on security through obscurity. 🫵🏽🙂‍↔️.
@commando_skiipz
Ghost St Badmus
4 hours
I’ve tested over 30 web apps that encrypt API requests client-side before sending them to the server, and return encrypted responses too. The frontend handles both encryption & decryption. Check those randomly generated JS files, the logic might just be hiding there.
1
3
6
@commando_skiipz
Ghost St Badmus
4 hours
I’ve tested over 30 web apps that encrypt API requests client-side before sending them to the server, and return encrypted responses too. The frontend handles both encryption & decryption. Check those randomly generated JS files, the logic might just be hiding there.
0
2
3
@commando_skiipz
Ghost St Badmus
4 hours
Look around the JS files(especially those with random characters .js), you might just find the secret key, IV and the encryption algorithm and mode.🤭🙂.
@40sp3l
Gospel
7 hours
What sought of encryption is this ? Can't do anything.
Tweet media one
2
0
7
@commando_skiipz
Ghost St Badmus
4 hours
RT @_DeejustDee: Don’t miss out on this event next Friday . @commando_skiipz will be live too 💃 . Register using this link . .
0
6
0
@commando_skiipz
Ghost St Badmus
4 hours
I’ll be doing a live hacking demo at The Hackers Secret Conference next week Friday! If you’re around, swing by and let’s break stuff together.
@_DeejustDee
DsL_a ʚїɞ ®
4 hours
Don’t miss out on this event next Friday . @commando_skiipz will be live too 💃
Tweet media one
Tweet media two
0
1
2
@commando_skiipz
Ghost St Badmus
5 hours
RT @adekunleGOLD: When we start celebrating brilliance the way we celebrate chaos, this country will change.
0
4K
0
@commando_skiipz
Ghost St Badmus
5 hours
RT @zoecyber001: Finally, I checked out Vulnbank💙, created by @commando_skiipz. I logged in first using SQL injection, no signup, proceeded….
0
3
0
@commando_skiipz
Ghost St Badmus
8 hours
Perfect excuse to finally play COD and God of War🤭.
0
0
3
@commando_skiipz
Ghost St Badmus
8 hours
If dem sack me for work, just know say na this game cause am😭.
0
0
2
@commando_skiipz
Ghost St Badmus
8 hours
Omo! 2026 too far, I couldn’t wait. 😭🧎🏾‍♂️
Tweet media one
Tweet media two
@commando_skiipz
Ghost St Badmus
27 days
I’m growing impatient for GTA VI, and hopefully, I’ll have gotten a PS5 before it’s released.
12
3
49
@commando_skiipz
Ghost St Badmus
10 hours
RT @hackSultan: Both of them could be struggling, but it’s the woman who’s loving a man at his lowest.
0
2K
0
@commando_skiipz
Ghost St Badmus
1 day
Sometimes, my idea of a reward after fixing an issue is just standing up to eat or stretch. That’s it. 😭. My babe go dey shake her head if she see these tweets 🤣.
1
0
0
@commando_skiipz
Ghost St Badmus
1 day
Some days get so complicated and stressful that I end up spending nearly 20 hours in the same spot, just trying to get to the root of an issue. For me, it’s not even about the money, it’s about the peace of mind that comes when everything finally works the way it should.
1
0
11
@commando_skiipz
Ghost St Badmus
1 day
I spend about 18 hours a day working and 6 hours sleeping, even on weekends sometimes, because I really enjoy what I do. 😅.
2
0
30
@commando_skiipz
Ghost St Badmus
1 day
See why you can’t rush a pentest 🫵🏽.
1
1
10
@commando_skiipz
Ghost St Badmus
1 day
Its one of my projects at work, to be released later.
0
0
1
@commando_skiipz
Ghost St Badmus
1 day
Something’s not quite right here….GraphQL API Hacking 😅. Can you spot the vulnerability?
3
1
8
@commando_skiipz
Ghost St Badmus
1 day
Someone finally exploited the vulnerability I kept hinting at in the virtual cards. Update card limit —> Exploit mass assignment (BOPLA) —> Auto-fund the card. Simple, yet deadly for any fintech company that overlooks it. Big shoutout to @bussyice 🫡👏🏾🔥.
@bussyice
B. R. O
2 days
This exploit is inspired by @DamilolaAbiona8's zero balance find, tho I took a slightly different route. I first exploited BOPLA in the update card limit endpoint by adding a "current_balance" parameter to the request and used it to pay a $400 bill. Then things got interesting.
Tweet media one
Tweet media two
3
6
36