
Gabriel (Umanhonlen | Sudo 🦜)
@sudosu01
Followers
1K
Following
12K
Media
279
Statuses
2K
You are the strength behind the system. | Founder @Jobdelve @Cyberodyssey_
#sudo
Joined September 2022
I am super proud to have been globally recognized in Microsoft Hall of Fame for privately disclosing a critical security vulnerabilities in one of their online services and also worked with them to remediate the issue. #applicationsecurity #cybersecurity
5
0
22
If you put in the work and follow the exact same pattern, the universe will not hesitate to send in the bird of good-luck towards your path. 🦜.
Most people sat down and built a tool/system 3/5 years ago that is currently working for them now. All of a sudden, you want to achieve similar results/success like them?. Nah - - . Sometimes, it doesn’t work that way. There’s definitely a story behind every glory. 🦜.
0
0
3
If you understand the logic of Unicode demonstrating impact rather than just saying 0 click ATO, they’ll have no option to accept your report. Impact and criticality of how it affects the business than just logic or bug. 🦜.
@sudosu01 Companies don't accept this.I found 0 click ATO but they require me to show how I exploit this in a real scenario. I use tools like Burp collab unfortunately I don't have access to domains like gmáil (with the Unicode á) so they end up not accepting my reports.
0
0
1
Someone is waiting for me to spill the dough, when I could actually mix it properly and make bread. 🦜.
Sometimes, you don’t really need any tools. Just apply some basic logic. Swap a common email domain like for a lookalike using punycode (. If it doesn’t throw a validation error, then validation failures are your friend. 🦜
0
0
3
Someone said he couldn't proxy the site on @Burp_Suite . Here's my tip to proxy the stubborn site. 1. Login using your [Normal] browser .2. Replay actual cookies [Copy and paste on @Burp_Suite browser].3. Enjoy your proxy. 🦜.
2
0
7