Log inSign up
Jon Bottarini
1,500 posts
Jon Bottarini profile banner
@jon_bottarini

Jon Bottarini

@jon_bottarini
Product Manager @ Google. I post about bug bounties, infosec, and everything in between. This is a personal account. Formerly: @Hacker0x01
Austin, TX
jonbottarini.com
Joined September 2012
754
Following
12.6K
Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • Pinned
    @jon_bottarini
    Jon Bottarini
    @jon_bottarini
    Sep 4, 2020
    Just fully disclosed ~30 reports encompassing over two years of hacking on New Relic - hackerone.com/jon_bottarini - most of the reports are PrivEsc/IDOR but there are some business logic bugs in here as well. No recon here! Just getting really familiar with the application itself :)
    Image
    hackerone.com
    HackerOne profile - jon_bottarini
    I ❤️ privilege escalation - https://www.jonbottarini.com
    19
  • @jon_bottarini
    Jon Bottarini
    @jon_bottarini
    Apr 2, 2025
    Entire confession is absolutely wild. Talk about an insider threat risk...
    @parkerconrad
    Parker Conrad
    Rippling
    @parkerconrad
    Apr 2, 2025
    Deel CEO and company founder @Bouazizalex personally orchestrated his company’s alleged spy scheme, the spy said in a full confession Alex allegedly recruited the spy, received the stolen info, and arranged payment via a person known only by their pseudonym: “The Watchman”
    Image
    Image
    Image
  • @jon_bottarini
    Jon Bottarini
    @jon_bottarini
    Sep 11, 2024
    Nation state behavior but you only have $20 - Taking over the mobi TLD WHOIS server:
    Image
    We Spent $20 To Achieve RCE And Accidentally Became The Admins Of .MOBI
    From labs.watchtowr.com
  • @jon_bottarini
    Jon Bottarini
    @jon_bottarini
    Jul 30, 2024
    Absolutely massive $500k bounty just awarded by @coinbase to @CertiKSkyfall - wow!
    Image
    16
  • @jon_bottarini
    Jon Bottarini
    @jon_bottarini
    Jul 7, 2024
    This... Just creates a WordPress user with the name "admin"... There is no vulnerability here. This could only be an issue if the site is configured to set every new user role as an Administrator but that would be exceedingly rare and it wouldn't matter what your username is.
    This Post is from an account that no longer exists. Learn more
    2
Advertisement
Advertisement