Today I received a $12,000 bounty using the Sandwich Attack ! 🤑
The vulnerability allowed me to enumerate the API Keys of other users 🤯
How did I do that ? Well the API key was a UUIDv1. If you are not familiar with UUIDv1s you need to know that they are constructed in 6
🥳THIS IS HUGE
I just got awarded 17 000$ for a Dependency Confusion 100% found with our tool Depi 🤟🔥
Let me tell you something, this report has a crazy story behind it.
This is not the common Dependency Confusion that you think, and I'm planning on disclosing this specific
In 2 hours, I'm going to drop an article on how I made 17,000$ in #bugbounty with a super cool attack vector 🤟
Title: Exploiting Fortune 500 Through Hidden Supply Chain Links
I'm so excited to release this one 🔥
In 2 hours the video about how we made 5,000$ in #BugBounty with a super cool technique resulting in a 0 Click ATO 🤟
This is by far the best video I ever made and I'm looking forward to hear all your feedbacks about the #bugbountytips that we are sharing 🔥
Stay tuned !
We just released a new article on how we made 50,000$ in #BugBounty by doing a really cool Software Supply Chain Attack🔥
🔗Link: landh.tech/blog/20250211-…
With Snorlhax we just received a $50,500 bounty for a Software Supply Chain attack 🔥
We've of course asked to start a coordinated disclosure process to be able to write an article about this super cool attack vector !!!
We have so many articles pending 😉
Today I received another 17,000$ on top of the previous 17,000$ for a Dependency Confusion. $34k on the same target using Depi 🔥
I've explained the story on my latest blog post, so do not hesitate to read it if you want to know more 😉
🔗Link in the comments
Excited to announce the start of our company with my brother: Lupin & Holmes !
We focus in offensive cybersecurity and social engineering. We aim to inspire ourselves from the Hacking Culture to innovate with the spirits of Lupin & Holmes.
Ready to hack the planet! 🎩🔍🌍🔐