Log inSign up
shubs
2,201 posts
Image
user avatar
shubs
@infosec_au
Co-founder, security researcher. Building an attack surface management platform, @assetnote
halcyon
assetnote.io
Joined August 2013
1,948
Following
58.4K
Followers
  • user avatar
    shubs
    @infosec_au
    Apr 19, 2022
    Yay, I was awarded $135,750 on @Hacker0x01 #TogetherWeHitHarder
  • user avatar
    shubs
    @infosec_au
    Apr 9, 2022
    1/10 - I've been doing offensive security source code review for a long time now, and along the way I've learnt a lot of lessons that can make you more effective. Some of them include:
  • user avatar
    shubs
    @infosec_au
    Oct 10, 2020
    Image
  • user avatar
    shubs
    @infosec_au
    Mar 17, 2022
    Yay, I was awarded $73,500 on @Hacker0x01 #TogetherWeHitHarder
  • user avatar
    shubs
    @infosec_au
    Nov 18, 2020
    Good wordlists are so important when discovering content on an asset. At @assetnote, we've built a wordlists site that updates itself on a monthly basis. For added value, we've included some of our best wordlists that we've manually collected too.
    Image
    Assetnote Wordlists
    From wordlists.assetnote.io
  • user avatar
    shubs
    @infosec_au
    Jun 11, 2022
    You can bypass Akamai WAF's XXE filters by HTML encoding the SYSTEM entity within a payload like this: <!DOCTYPE foo [<!ENTITY % a "&#x3c;&#x21; ... omitted ... neat trick! used this today.
  • user avatar
    shubs
    @infosec_au
    Nov 21, 2020
    I've just added an API routes wordlist containing 953011 possible API paths from the HTTPArchive dataset. Download it at wordlists.assetnote.io - all paths which start with "/api/", "/v1/", "/v2", or "/rest/". Good luck hacking! Thanks for requesting this, hope it helps.
    Image
    Assetnote Wordlists
    From wordlists.assetnote.io
  • user avatar
    shubs
    @infosec_au
    Nov 26, 2022
    I just published a blog post for the people that want to get into bug bounties. I hope it helps people that are thinking about doing bug bounties, but haven't started yet. It explains what to expect and how to deal with common problems / situations:
    shubs.io
    So, you want to get into bug bounties?
    I've been doing bug bounties for over 10 years now and over time, I have grown fonder of the life changing effects it has had for me. From job prospects, to being able to financially support those...
  • user avatar
    shubs
    @infosec_au
    Dec 20, 2020
    Why I love hacking IIS servers: - Case insensitive, amazing for content discovery - IIS Shortname - VIEWSTATE deserialization RCE gadget - Web.config upload tricks - Debug mode w/ detailed stack traces and full path - Debugging scripts often deployed (ELMAH, Trace) - Telerik RCE
  • user avatar
    shubs
    @infosec_au
    Jun 5, 2025
    IP whitelisting is fundamentally broken. At @assetnote, we've successfully bypassed network controls by routing traffic through a specific location (cloud provider, geo-location). Today, we're releasing Newtowner, to help test for this issue:
    Image
    GitHub - assetnote/newtowner: Abuse trust-boundaries to bypass firewalls and network controls
    From github.com
    59K
  • user avatar
    shubs
    @infosec_au
    Jan 29, 2022
    I will be releasing a number of videos that go through my bug bounty reports in a redacted manner. I believe in transparency, and the videos are going to shine an honest light into what I have reported. It’s mostly aimed at beginners, but the reports get complex over time.
  • user avatar
    shubs
    @infosec_au
    Jul 11, 2023
    The security research team at @assetnote discovered a pre-authentication RCE vulnerability through a cryptographic flaw in Citrix ShareFile. It's been assigned CVE-2023-24489. You can read the technical blog post here: blog.assetnote.io/2023/07/04/cit…
    Image
    140K
  • user avatar
    shubs
    @infosec_au
    Jul 11, 2024
    Our security researcher @hash_kitten found one of the most critical exploit chains in the history of @assetnote. Affecting 40k+ instances of ServiceNow, we could execute arbitrary code, access all data without authentication. You can read our blog here: assetnote.io/resources/rese…
    Image
    73K
  • user avatar
    shubs
    @infosec_au
    Dec 26, 2021
    Damn. This is really cool. Achieving RCE via LFI using Nginx as a way to upload a temporary file, even when PHP is hardened so other techniques will fail - bierbaumer.net/security/php-l…

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

Terms·Privacy·Cookies·Accessibility·Ads info·© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up
Advertisement
Advertisement