1. X
  2. Marius du Preez
Log inSign up
Marius du Preez
1,120 posts
Marius du Preez profile banner
@mdp_sec

Marius du Preez

@mdp_sec
Bug bounty hunter breaking Web2 apps, APIs & business logic. $102k in my first 6 months. Sharing what works and doesn't. 🇦🇺 bugcrowd.com/marius_dp
Australia
mdpsec.com
Joined March 2026
241
Following
2,060
Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • Pinned
    @mdp_sec
    Marius du Preez
    @mdp_sec
    Aug 28
    Most AI cybersecurity benchmarks answer the wrong question for bug-bounty hunters. They give the model source code, a known CVE, a vulnerability category, or a tightly framed objective. That is useful for measuring security knowledge and white-box reasoning. But it is not how
    Image
  • @mdp_sec
    Marius du Preez
    @mdp_sec
    12h
    GLM 5.3 added Not looking good for blackbox stuff. Dont trust them cyber benchmarks that are only whitebox...
    Image
    Image
    @mdp_sec
    Marius du Preez
    @mdp_sec
    Aug 28
    Most AI cybersecurity benchmarks answer the wrong question for bug-bounty hunters. They give the model source code, a known CVE, a vulnerability category, or a tightly framed objective. That is useful for measuring security knowledge and white-box reasoning. But it is not how
  • @mdp_sec
    Marius du Preez
    @mdp_sec
    Aug 29
    Adding one dot segment turned an admin login redirect into HTTP 200. Paid $750. The normal admin path redirected unauthenticated users to login. The same path with `/./` reached the protected controller without a session. The authentication filter and application router
    Image
  • @mdp_sec
    Marius du Preez
    @mdp_sec
    Aug 27
    Before assigning severity, write seven facts: 1. Attacker access required. 2. Victim action required. 3. Data or control gained. 4. Number of users or tenants exposed. 5. Access duration. 6. User visibility. 7. Reversibility. If those are strong, the report does not need
  • @mdp_sec
    Marius du Preez
    @mdp_sec
    Aug 26
    An API key in an APK can be limited, monitored, or designed for a public client. A production TLS private key has no reason to be there. One app shipped the encrypted key and the material needed to decrypt it. Once unpacked, the client contained the full credential used by the
    Image
Advertisement
Advertisement