
Corben Leo
@hacker_
Followers
70K
Following
11K
Media
282
Statuses
4K
I hack stuff (legally) | Co-founder @boringmattress
Brookings, South Dakota
Joined February 2016
Doing code analysis?. Use by @anysphere! . Whether youâre digging through a language you know or adventuring into a new one, using AI can definitely be helpful. Donât think itâll replace us yet, but auditing got more accessible. #typefully day 10
2
36
222
Finding vulnerabilities first = you get paid. Want to be the first to hack on new functionality? Monitor your targetâs JS files for new paths or parameters. (automate with a headless browser to grab all dynamically loaded JS). #typefully day 9.
4
24
246
Focus is a competitive advantage. Itâs tempting to jump around, but deep focus on one thing pays off. This applies beyond hacking, but you should stick to a target for a long time and become an expert. For example, @nnwakelam knew more about Yahoo than any Yahoo employee.
3
18
173
Lastly, you should search by organization name:. $ certsio search org âUber Technologies, Inc.â. Certificates can also contain emails,you should search for assets using them:. $ certsio search emails @example.com. #typefully day 7.
1
4
61
Companies run software they don't write. Ex: Jira, GoAnywhere, etc. Finding vulns in these types of software = lots of vuln targets = $$$. So, do code review!. Need the source? Find the software AWS's AMI Catalog. Launch a server. SSH in. Pull it. Review it. #typefully day 4.
1
37
263
7/ A whopping $250. But good laughs. Lessons:. 1. Don't assume that what's "supposed" to be internal is internally-facing. 2. Always change default credentials. đ€Šđ»ââïž. end #typefully challenge day 3.
7
1
70