Log inSign up
gr3pme
370 posts
Image
user avatar
gr3pme
@gr3pme
Cohost @ctbbpodcast || Bug Bounty Hunter || hacker - OSWE, OSCP
Joined January 2019
654
Following
2,764
Followers
  • user avatar
    gr3pme
    @gr3pme
    Mar 21, 2024
    TIL: If you find API keys that look sus but can't quite figure out what service(s) to try with, @pdnuclei has 240+ token spray templates which you can pass a single token or a text file of tokens to: #BugBounty
    Image
    14K
  • user avatar
    gr3pme
    @gr3pme
    Feb 21, 2024
    Yay, I was awarded a $5,100 bounty on @Hacker0x01! hackerone.com/gr3pme #TogetherWeHitHarder #bugbounty
    Image
    hackerone.com
    HackerOne profile - gr3pme
    OSWE | OSCP | CRT -
    15K
  • user avatar
    gr3pme
    @gr3pme
    Aug 20, 2024
    Big shout out to @NahamSec for his SSRF workshop at Defcon. Come back home, started hunting and dropped 2x SSRFs -> RCE with some collabs with @ajxchapman I'd always look for it on pen tests but never bug bounty (I have no idea why), and it's massively paid off.
    14K
  • user avatar
    gr3pme
    @gr3pme
    Sep 23, 2024
    Stop the clock now please 😂 @Hacker0x01 #h10131
    Image
    6.6K
  • user avatar
    gr3pme
    @gr3pme
    Oct 11, 2024
    If you wanted a bit more insight into my approach when threat modelling for bug bounty, the LHE scene and how I pick and approach targets, last week's @ctbbpodcast HackerNotes is for you:
    Image
    [HackerNotes Ep.91] Zero to LHE in 9 Months (feat gr3pme)
    From blog.criticalthinkingpodcast.io
    4K
  • user avatar
    gr3pme
    @gr3pme
    Sep 26, 2024
    First LHE down at #h10131 with @Hacker0x01 in Scotland. Met some incredibly talented hackers and had a really enjoyable experience. Massive thank you to the team and @amazon for such a great event. Till next time!
    Image
    Image
    Image
    3.5K
  • user avatar
    gr3pme
    @gr3pme
    Nov 12, 2024
    We're back with a huge double whammy @ctbbpodcast HackerNotes. We cover how to attack Chrome extensions, their components & threat model, plus a whole bunch of cookie and clientside gadgets from Kevin Mizu + more. Check it out below:
    Image
    [HackerNotes Ep.95 & Ep.96] Cookies, Caching & Attacking Chrome Extensions with MatanBer
    From blog.criticalthinkingpodcast.io
    6.7K
  • user avatar
    gr3pme
    @gr3pme
    Dec 14, 2024
    Seeing all the Wrapped stats has made me reflect on what a wild year it's been! Starting with zero experience hunting, just an idea for @ctbbpodcast HackerNotes, and a total shot in the dark messaging @Rhynorater, it’s crazy to see how far it’s come. Those long hours were worth
    Image
    Image
    Image
    Image
    7K
  • user avatar
    gr3pme
    @gr3pme
    Apr 25, 2024
    The latest @ctbbpodcast HackerNotes has just dropped! Check out a bunch of fresh HTMX bypasses and a Cloudflare cdn-cgi gadget below 👇👇👇
    Image
    [HackerNotes Ep. 68]: 0-days & HTMX-SS with Mathias
    From blog.criticalthinkingpodcast.io
    11K
  • user avatar
    gr3pme
    @gr3pme
    Feb 21, 2024
    Yay, I was awarded a $2,100 bounty on @Hacker0x01! hackerone.com/gr3pme #TogetherWeHitHarder
    Image
    hackerone.com
    HackerOne profile - gr3pme
    OSWE | OSCP | CRT -
    2.3K
  • user avatar
    gr3pme
    @gr3pme
    Sep 3, 2024
    In case you missed it, Frans Rosen dropped some GOLD last week on @ctbbpodcast covering some fresh research & crazy tips on X-Correlation header injection. Check out the HackerNotes below: blog.criticalthinkingpodcast.io/p/hackernotes-…
    8.1K
  • user avatar
    gr3pme
    @gr3pme
    Oct 1, 2024
    Using Cursor for POC creation, fresh research with some SQLi, encryption oracles, content types for XSS and a $5k clickjacking bounty on Google with a bunch of neat gadgets. Check out last week's @ctbbpodcast HackerNotes below:
    Image
    [HackerNotes Ep.90] 5k Clickjacking, Encryption Oracles, and Cursor for PoCs
    From blog.criticalthinkingpodcast.io
    3.5K
  • user avatar
    gr3pme
    @gr3pme
    Aug 16, 2024
    This week's @ctbbpodcast HackerNotes has dropped, covering a bunch of takeaways with Lupin and Justin from Google's BugSwat event in Vegas! Check it out below:
    Image
    [HackerNotes Ep.84] 0xLupin & Takeaways from Google's Las Vegas BugSwat
    From blog.criticalthinkingpodcast.io
    4.3K
  • user avatar
    gr3pme
    @gr3pme
    Jul 12, 2024
    This week's @ctbbpodcast HackerNotes is a banger if CSS injection is on your radar, we've got: • Universal RCE - Browser Extensions Research • CSPT To XSS • Full-time Bug Bounty Blueprint • CSS Injection tips, tricks, techniques and writeups Check it out:
    4.2K

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

Terms of Service|Privacy Policy|Cookie Policy|Accessibility|Ads info|© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up
Advertisement
Advertisement