Log inSign up
Shlomie Liberow
1,472 posts
user avatar
Shlomie Liberow
@Shlibness
Building aisy.ai - Former Head of Hacker R&D @Hacker0x01. All things hacking!
London
Joined June 2009
1,606
Following
2,775
Followers
  • Pinned
    user avatar
    Shlomie Liberow
    @Shlibness
    May 9, 2020
    Visit target.com --> SSO Visit target.com/admin--> login Reviews Javascript --> if (data == 'SUCCESS') { location.href = "/admin/<snipped>?uname="+username+""; } Visit: target.com/admin/<snipped>?uname=admin Admin Access... #bugbountytips
    target.com
    Target : Expect More. Pay Less.
    Shop Target online and in-store for everything from groceries and essentials to clothing and electronics. Choose contactless pickup or delivery today.
  • user avatar
    Shlomie Liberow
    @Shlibness
    Jul 4, 2021
    My brother [who is visibly Jewish] was attacked on the 113 bus, heading in direction of Oxford Circus, London at 11:33PM and threatened to "slit his throat for Palestine". Will anything be done about this rampant #Antisemitism @TfL @CST_UK @antisemitism
    Image
    00:00
  • user avatar
    Shlomie Liberow
    @Shlibness
    Jul 4, 2021
    Replying to @Shlibness
    Bus location: 262 Oxford Street, London, W1C 1DW. Drivers info: S. W - 2067909. VMH 2443 | 103 - 113. License plate: LK18 AFZ, Edgware Garage. All information is there for @metpoliceuk address fact that identifiably jewish people face extreme racism on a daily occurrence
    Image
  • user avatar
    Shlomie Liberow
    @Shlibness
    Jul 4, 2021
    Replying to @Shlibness
    Important note: It's been cleared up that the football fans in the early part of the video were not involved in the abuse and are in fact Jewish. The racial abuse came from this individual.
    Image
  • user avatar
    Shlomie Liberow
    @Shlibness
    Jul 4, 2021
    Replying to @Shlibness
    @Baddiel @stephenpollard @BoardofDeputies @Shomrim The above may be of interest of the typical experiences for someone wearing religious garb on public transport in London...
  • user avatar
    Shlomie Liberow
    @Shlibness
    Jul 4, 2021
    Replying to @Shlibness
    Audio threatening to slit his throat and shank him
  • user avatar
    Shlomie Liberow
    @Shlibness
    Nov 27, 2024
    Always a joy collaborating with @jayesh25 and digging in deep
    user avatar
    Jayesh Madnani
    @Jayesh25
    Nov 27, 2024
    🚨 Yay, we were rewarded with $20,000 on our @Hacker0x01 submission for a SSRF bug discovered in collaboration with @Shlibness! 💰🎉 🥳 We uncovered a Critical SSRF vulnerability, turning it into unauthorized access to internal admin endpoints, leading to PII leaks and
    Image
    11K
  • user avatar
    Shlomie Liberow
    @Shlibness
    Jul 4, 2021
    Appreciate it. Police have been in touch about an interview for Tuesday but I'm truly hoping this isn't just procedural and an actual investigation to find the suspect is carried out. The footage and the fact he used an oyster on the bus should be more than sufficient.
  • user avatar
    Shlomie Liberow
    @Shlibness
    Oct 19, 2024
    A must watch by @Blaklis_ covering some funky bug bounty exploits with all the juicy details. youtube.com/watch?v=MrNmdt…
    13K
  • user avatar
    Shlomie Liberow
    @Shlibness
    Jul 4, 2021
    Replying to @TfL and @MetCC
    He called the police but they said they were too busy. 999 rang for over a minute and no one picked up...
  • user avatar
    Shlomie Liberow
    @Shlibness
    Nov 12, 2024
    Took the plunge and started blogging about bug bounties - my first post is live! AI can be a powerful tool for bug hunting at speed when combined with human intuition. shlomie.uk/posts/Cracking… Feedback most welcome!
    14K
  • user avatar
    Shlomie Liberow
    @Shlibness
    Oct 19, 2019
    Submitted an HTTP Smuggling attack and was initially rejected on low impact but found a /redirect endpoint which followed a poisoned referer header. Since I was able to set poisoned headers to an external host... #bugbountytip
    Image
  • user avatar
    Shlomie Liberow
    @Shlibness
    Jan 15, 2025
    🚨 Last month @DaneSherrets and I hacked @virtuals_io, a $4.6B platform for deploying AI agents and their associated cryptocurrency earning a $10,000 bounty. Here’s how we uncovered a major vulnerability that could’ve rewritten how these agents think and behave. 🧵👇
    10K
  • user avatar
    Shlomie Liberow
    @Shlibness
    Jun 10, 2020
    Been a fun journey hitting the 1k club after hacking more actively recently. On to 2k... #TogetherWeHitHarder
    Image

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up
Advertisement
Advertisement