gr3pme Profile Banner
gr3pme Profile
gr3pme

@gr3pme

1,135
Followers
456
Following
12
Media
179
Statuses

HackerNotes Author @ctbbpodcast || Bug Bounty Hunter || OSWE, OSCP

Joined January 2019
Don't wanna be here? Send us removal request.
@gr3pme
gr3pme
7 months
TIL: If you find API keys that look sus but can't quite figure out what service(s) to try with, @pdnuclei has 240+ token spray templates which you can pass a single token or a text file of tokens to: #BugBounty
Tweet media one
2
43
192
@gr3pme
gr3pme
2 months
Big shout out to @NahamSec for his SSRF workshop at Defcon. Come back home, started hunting and dropped 2x SSRFs -> RCE with some collabs with @ajxchapman I'd always look for it on pen tests but never bug bounty (I have no idea why), and it's massively paid off.
7
6
115
@gr3pme
gr3pme
1 month
Stop the clock now please ๐Ÿ˜‚ @Hacker0x01 #h10131
Tweet media one
3
2
107
@gr3pme
gr3pme
28 days
First LHE down at #h10131 with @Hacker0x01 in Scotland. Met some incredibly talented hackers and had a really enjoyable experience. Massive thank you to the team and @amazon for such a great event. Till next time!
Tweet media one
Tweet media two
Tweet media three
2
0
67
@gr3pme
gr3pme
2 months
In case you missed it, Frans Rosen dropped some GOLD last week on @ctbbpodcast covering some fresh research & crazy tips on X-Correlation header injection. Check out the HackerNotes below:
0
3
50
@gr3pme
gr3pme
23 days
Using Cursor for POC creation, fresh research with some SQLi, encryption oracles, content types for XSS and a $5k clickjacking bounty on Google with a bunch of neat gadgets. Check out last week's @ctbbpodcast HackerNotes below:
0
4
47
@gr3pme
gr3pme
3 months
This week's @ctbbpodcast HackerNotes is a banger if CSS injection is on your radar, we've got: โ€ข Universal RCE - Browser Extensions Research โ€ข CSPT To XSS โ€ข Full-time Bug Bounty Blueprint โ€ข CSS Injection tips, tricks, techniques and writeups Check it out:
0
5
45
@gr3pme
gr3pme
4 months
@ctbbpodcast HackerNotes Ep 76 has dropped! Check out: ๐ŸŒ HackerOne AWC qualifiers ๐Ÿ” Zoom ATO deep dive ๐Ÿ›  SharePoint XXE writeup ๐ŸŒ Shazzer browser fuzzing ๐Ÿ’ก Match & Replace tips, tricks, and techniques And a bunch more below ๐Ÿ‘‡๐Ÿ‘‡
1
15
37
@gr3pme
gr3pme
7 months
๐Ÿ’ปThe latest @ctbbpodcast HackerNotes featuring @jhaddix has just dropped! Check out: THMB Live, recon techniques, WAF bypass tips and red teaming below ๐Ÿ‘‡๐Ÿ‘‡
2
6
35
@gr3pme
gr3pme
15 days
A little insight to my approach when threat modelling for bug bounty ๐Ÿ‘‡
@ctbbpodcast
Critical Thinking - Bug Bounty Podcast
15 days
. @gr3pme 's threat modelling methodology when approaching new targets. The goal is to list every possible attack vector, regardless of likelihood, as a reference for future exploration. This is a powerful yet extremely underrated skill for bug hunters! Take note!
Tweet media one
4
23
141
0
7
33
@gr3pme
gr3pme
2 months
@ctbbpodcast HackerNotes has landed, covering a bunch of takeaways from some of the research dropped by the PortSwigger team & Orange Tsai. Check it out!
0
10
33
@gr3pme
gr3pme
4 months
@ctbbpodcast HackerNotes Ep. 78 has dropped covering: โ€ข XSS WAF Bypasses: HTML Entities โ€ข NextJS Cache Poisoning Research โ€ข Polyfil Supply Chain Attacks โ€ข Reporting tips for better reporting Check it out below!
0
5
30
@gr3pme
gr3pme
2 months
First @defcon was a huge success. Massive thanks to @BugBountyDEFCON for hosting quality talks and getting the community together!
Tweet media one
1
1
31
@gr3pme
gr3pme
6 months
HackerNotes has dropped featuring last week's @ctbbpodcast episode with @joaxcar ! Check it out for: - CSP Bypasses - Browser behaviour gadgets - Critical bug writeups - Full-time bug bounty tips ๐Ÿ‘‡๐Ÿ‘‡๐Ÿ‘‡
1
5
27
@gr3pme
gr3pme
8 months
Check out the latest episode of @ctbbpodcast HackerNotes! ๐Ÿ’ป Youssef Sammouda shares some invaluable insights on client-side gadgets and tips for ATO. Don't miss out on this one!
0
7
27
@gr3pme
gr3pme
6 months
Check out the latest @ctbbpodcast HackerNotes: ๐Ÿ” Louis Vuitton LHE & Browser Market Shares ๐Ÿž Justin's Bug of the Week ๐Ÿ“ˆ Zero to Hero: 9 Month bug bounty journey with Justinโ€™s Methodology-ish ๐Ÿš€ Intent to ship: Upcoming browser features Read it here:
0
1
23
@gr3pme
gr3pme
1 year
Tough exam but the OSWE well worth it. Thank you @offsectraining ! Will be creating some resources to help others on the same journey soon
Tweet media one
0
1
20
@gr3pme
gr3pme
7 months
๐Ÿ’ปThe @ctbbpodcast HackerNotes has just dropped with Sam Curry. Expect tips for finding secondary context bugs, re-framing your perspective when hacking and cool research against ISPs, Tesla, airlines, JS frameworks and a bunch more below! ๐Ÿ‘‡๐Ÿ‘‡
0
3
19
@gr3pme
gr3pme
8 months
๐Ÿ’ป HackerNotes is back with this week's @ctbbpodcast pod episode starring @JR0ch17 . Check out some cool exploit chains, OAuth bugs and more below!๐Ÿ‘‡๐Ÿ‘‡
0
4
18
@gr3pme
gr3pme
8 months
We've got another gem from the guys on this week's @ctbbpodcast HackerNotes. If you're wondering what gadgets lead to some of the more exotic bugs you read about in writeups, this one is for you! ๐Ÿ’ป
0
2
18
@gr3pme
gr3pme
9 months
The latest episode of @ctbbpodcast HackerNotes is now live! ๐ŸŽ™๏ธ Join the guys as they share some seriously good takeaways from the @Hacker0x01 LHE. Don't miss out - check it out below:
0
4
14
@gr3pme
gr3pme
5 months
@ctbbpodcast HackerNotes EP 74 has dropped, covering all things dependency & supply chain from this week's pod with @0xLupin including: ๐Ÿ”น Supply chain lifecycle ๐Ÿ”น Supply chain threats ๐Ÿ”น Dependency confusion ๐Ÿ”น Enumeration & attack vectors And a whole bunch more below! ๐Ÿ‘‡
0
5
13
@gr3pme
gr3pme
5 months
@ctbbpodcast HackerNotes Ep 73 has dropped! Check out some WAF bypass techniques, iFrame research and clientside extensions below ๐Ÿ‘‡๐Ÿ‘‡๐Ÿ‘‡
0
2
12
@gr3pme
gr3pme
12 days
0
0
12
@gr3pme
gr3pme
3 months
Last week's @ctbbpodcast HackerNotes with MatanBer was packed with client-side hacking tips, including: โ€ข Using DevTools effectively to analyze a target โ€ข General client-side hacking tips โ€ข Common sources and sinks to look out for โ€ข Dealing with restricted XSS contexts
1
1
12
@gr3pme
gr3pme
4 months
@ITSecurityguard Aka โ€˜Changing severity because weโ€™re going to fix the bug in the next few hoursโ€™, 0/10 logic
0
0
12
@gr3pme
gr3pme
6 months
@ctbbpodcast [HackerNotes Ep. 70] has dropped! Check out: - Meta's Bug Bounty Program - NahamCon - CI/CD & Dependency Confusion - CSP Bypasses And more below! ๐Ÿ‘‡๐Ÿ‘‡
0
2
11
@gr3pme
gr3pme
2 months
Check this one out for some iframe sorcery. Stellar writeup from @aszx87410 !
@aszx87410
huli
2 months
there is a challenge in idekCTF 2024 called srcdoc-memos made by icesfont, it's about iframe, sandbox, CSP, navigation, session history and policy container. I spent like a week to understand how it works lol, really complex but also interesting.
3
46
177
0
3
9
@gr3pme
gr3pme
9 months
Missed last week's @ctbbpodcast episode? Don't worry, the latest HackerNotes post is packed with WordPress hacking insights from the pod โ€“ from tips and tricks for exploitation and code review to quirky WordPress behaviours. Full write-up and TLDR below ๐Ÿ‘‡
Tweet media one
0
5
9
@gr3pme
gr3pme
8 months
First bug, first crit ๐Ÿ’ฅ @Hacker0x01
Tweet media one
0
1
7
@gr3pme
gr3pme
9 months
@ctbbpodcast HackerNotes Ep. 56 just dropped - Using Data Science to Win Bug Bounty With Mayonaise (aka Jon Colston) check it out below! ๐Ÿ‘‡
0
1
7
@gr3pme
gr3pme
5 months
๐Ÿšจ @ctbbpodcast HackerNotes has dropped jampacked with a tonne of research this week, including: ๐Ÿ“„ PDF.JS Universal XSS via PDF ๐ŸŒ NextJS SSRF by AssetNote ๐Ÿ“ฆ Smuggling payloads + Slonser IPV6 Research ๐Ÿ”“ DomPurify Bypass And a whole bunch more. Check it out below! ๐Ÿ‘‡๐Ÿ‘‡
0
0
6
@gr3pme
gr3pme
4 months
@NahamSec @Bugcrowd @Hacker0x01 Seems to be a common theme at the moment
0
0
6
@gr3pme
gr3pme
8 months
@Rhynorater The first of many ๐Ÿ‘Œ
0
0
6
@gr3pme
gr3pme
5 months
@xnl_h4ck3r @NahamSec Gutted I missed some of these. I had my eye on the WAF bypass workshop for a while
0
0
4
@gr3pme
gr3pme
30 days
@gregxsunday Very good find mate ๐Ÿ‘
0
0
5
@gr3pme
gr3pme
20 days
@joaxcar Congrats!!
0
0
5
@gr3pme
gr3pme
7 months
1
0
3
@gr3pme
gr3pme
2 months
@gregxsunday @ArchAngelDDay beautiful ๐Ÿซฐ
0
0
3
@gr3pme
gr3pme
3 months
UK team finishes 5th in the 1st round ๐Ÿ‘€ #hackerone #awc
@Hacker0x01
HackerOne
3 months
The results are in!๐Ÿฅ‡ Congratulations to these 32 teams who will move on to the Group Round of the 2024 #AmbassadorWorldCup ! ๐Ÿ™Œ The next round kicks off at the end of August! Stay tuned for the latest info, and read more about the AWC here.
Tweet media one
46
58
304
0
0
3
@gr3pme
gr3pme
4 months
@ctbbpodcast HackerNotes Ep 77 has dropped! Check out: ๐Ÿ’‰MongoDB NoSQL Injection Techniques ๐Ÿ”’ 1 Click ATO - KakaoTalk โฒ๏ธ Time-Based Secret Leaks Attack Vectors ๐Ÿ’พ ORM Leaks ๐Ÿ“ฑ Mobile OAuth Attacks ๐Ÿ’ก Tips for Staying Sharp & Motivated in Bug Bounty And more below!๐Ÿ‘‡๐Ÿ‘‡
0
1
3
@gr3pme
gr3pme
4 months
More xss ๐Ÿช„ โœจ
@garethheyes
Gareth Heyes \u2028
4 months
We've released a new version of our XSS cheat sheet with some new exotic events from the community.
Tweet media one
14
48
255
0
0
3
@gr3pme
gr3pme
9 months
Very very good writeup, one to add to the bookmarks. This is the sort of content that needs to be in #bugbountytips
@bbuerhaus
Brett Buerhaus
9 months
Reversing and Tooling a Signed Request Hash in Obfuscated JavaScript Thanks to @hackinghub_io for putting together a lab to learn more about it:
Tweet media one
21
164
518
0
0
2
@gr3pme
gr3pme
5 months
Hey, @garethheyes , I've had some interesting results in Dominvader I'm struggling to understand. Do you mind if I drop you a DM?
1
0
2
@gr3pme
gr3pme
2 months
@ArchAngelDDay Iโ€™ve done 8 days of it and Iโ€™m SO ready for home
0
0
2
@gr3pme
gr3pme
27 days
@gregxsunday @Hacker0x01 @amazon Thank you sir - it was a good event I must admit
0
0
2
@gr3pme
gr3pme
9 months
@Rhynorater @ctbbpodcast HackerNotes cheatsheet ๐Ÿ‘€๐Ÿ‘€
1
0
2
@gr3pme
gr3pme
5 months
@xnl_h4ck3r All insurances are insane atm - I think itโ€™s a sign to search for some insurance based BB targets ๐Ÿง
1
0
2
@gr3pme
gr3pme
8 months
@G0LDEN_infosec ๐Ÿ‘๐Ÿ‘๐Ÿ‘
0
0
2
@gr3pme
gr3pme
4 months
Using burp with more than 2 extensions
@hetmehtaa
Het Mehta
4 months
Which software is he running? ๐Ÿง
Tweet media one
311
15
329
0
0
2
@gr3pme
gr3pme
4 months
1
0
2
@gr3pme
gr3pme
8 months
@MtnBer Gonna be waiting for the blog to drop for this one ๐Ÿ‘Œ
0
0
2
@gr3pme
gr3pme
2 months
@fransrosen @Rhynorater I was in disbelief for a lot of it - crazy stuff
0
0
1
@gr3pme
gr3pme
5 months
For my testers - if you have any open roles for a US based tester and need a solid app tester with good people + consultancy skills, hit him up ๐Ÿ‘‡
@BadAt_Computers
Roll4Combat
5 months
Excited to explore new web app pentesting opportunities! I'm seeking a mid-level role where I can continue to learn and grow. Looking for fully remote positions (MST timezone). Happy to provide an updated resume and would love to chat about any opportunities! #JobSearch
1
28
54
0
0
1
@gr3pme
gr3pme
8 days
@deadvolvo @ctbbpodcast ๐Ÿ‘Š๐Ÿ‘Š๐Ÿ‘Š
0
0
1
@gr3pme
gr3pme
8 months
0
0
1
@gr3pme
gr3pme
4 months
@PikuHaku Absolutely - will be an interesting read no doubt
0
0
1
@gr3pme
gr3pme
21 days
@nmatt0 Installing a game wrong on arch:
Tweet media one
0
0
1
@gr3pme
gr3pme
2 months
0
0
1
@gr3pme
gr3pme
6 months
@Yassineaboukir Absolutely, anxiety is a complex one. The right amount applied in the right context can fuel some impressive results
1
0
1
@gr3pme
gr3pme
2 years
@Jhaddix @AppSecEngineer @abhaybhargav Had my eye on this for months, great to see some good feedback
0
0
1
@gr3pme
gr3pme
4 months
@PikuHaku Penhaligons Halfeti is a strong contender imo
0
0
1
@gr3pme
gr3pme
1 month
@kevin_mizu We're waiting ๐Ÿ‘€
0
0
1
@gr3pme
gr3pme
4 months
BB program: hereโ€™s a user matrix and lots of docs to help you hack! *reports numerous bugs, referencing the docs* BB program: Ah the user matrix and docs are wrong. All of this is intended. Closing as informative. ๐Ÿ™ƒ
1
0
1
@gr3pme
gr3pme
8 months
@G0LDEN_infosec @Hacker0x01 Thanks bro! ๐Ÿ‘Š
0
0
1
@gr3pme
gr3pme
2 months
0
0
1
@gr3pme
gr3pme
6 months
Great post from @PikuHaku - I recommend reading for all the BB hunters out there
@PikuHaku
Eldar
6 months
I've got a new blog post about how bug bounty hunting has been going for me in 2024 and what I feel about different bug bounty platforms.
9
41
255
0
0
1
@gr3pme
gr3pme
20 days
@nmatt0 Thank you sir! Glad you enjoyed the episode!
0
0
1
@gr3pme
gr3pme
1 month
@BadAt_Computers Any XL variant of the secrets lab range. Changed the game for me, no back problems since
1
0
1
@gr3pme
gr3pme
14 days
@xssdoctor @Hacker0x01 Congrats! ๐Ÿฅณ
1
0
1
@gr3pme
gr3pme
3 months
@gregxsunday @defcon @BugBountyDEFCON ๐Ÿ™‹๐Ÿปโ€โ™‚๏ธ
0
0
1
@gr3pme
gr3pme
8 months
@vysecurity H1 is starting to implement some platform standards around situations like this. They seem to be basing it if problem(s) are systemic:
0
0
1
@gr3pme
gr3pme
8 months
@akita_zen @Hacker0x01 Just need a few more now ๐Ÿ˜‚
0
0
1
@gr3pme
gr3pme
8 months
@BadAt_Computers Something that took me a while to grasp when I first started getting into testing is to learn 1/2 vuln classes at a time, instead of trying to do them all
1
0
1
@gr3pme
gr3pme
6 months
@Mr_xhunt Smashed it ๐Ÿ’ฅ๐Ÿ’ฅ
1
0
1
@gr3pme
gr3pme
5 months
@joaxcar The sabbatical paid off, literally ๐Ÿ‘€
0
0
1
@gr3pme
gr3pme
28 days
1
0
1
@gr3pme
gr3pme
2 months
@huzayyfah @Rhynorater @ctbbpodcast @albinowax Drop me a DM - Iโ€™ll check this out
0
0
1