Подтвердите e-mail

Для публикаций, комментариев, реакций и сообщений подтвердите адрес.

Профиль

ToxSec

Профиль Vively

Security Engineer M.S. Cybersecurity, CISSP. AWS, NSA, USMC. www.toxsec.com

Project Raven Box (1970s) – Underground builders sold custom “black boxes” that simulated coin tones, letting phreakers make free pay-phone calls worldwide until Bell finally changed its signaling. #Hackers

010

Every “no” is just getting you closer to the “yes.” #bugbounty #grind

010

burp crashed again. i think it deserves a bounty. #bugbounty

000

What’s your pre-report ritual before hitting “Submit”? #BugBounty

000

How often do you revisit old programs after a scope expansion? #BugBounty

000

The 414s (1983) – A group of Milwaukee teens dialed into dozens of government and corporate systems—including Los Alamos National Lab—sparking the first U.S. Senate hearing on computer crime. #Hackers

000

funny how the broken things always hide behind the prettiest UIs. #bugbounty

000

ever find a vuln that makes you say “no way this is real” out loud? #bugbounty

000

The Max Headroom Broadcast Intrusion (1987) – Chicago TV viewers watched a hacker in a Max Headroom mask hijack two prime-time broadcasts using a rogue microwave link. The culprit was never caught. #hackers

000

LLM hallucinations feel like chatting with a confident liar. #AIsecurity

110

Probe every parameter. Don’t just test id=. Try integer fuzzing, negative numbers, encoded payloads, and nested JSON keys. Even “read-only” params can hide IDOR or injection bugs. #BugBounty

010

funny how “deprecated” endpoints are usually the most alive. #bugbounty

010

tracebit ran the context bomb through 100+ simulated attack runs in a fake aws environment. the whole idea is one content change to bait you already run. no new tooling, no new system. just a string that makes the attacker’s own model refuse itself. www.toxsec.com/p/context-bo...

Context Bombs: Defensive Prompt Injection TrapsA decoy secret loaded with text built to trip an AI attacker’s own safety training, so the model refuses itself.www.toxsec.com
000

How many Burp tabs is “too many” before you lose track? #BugBounty

020

sometimes the grind feels endless, but persistence is the real exploit. #bugbounty #motivation

020

The biggest risk in “serverless” is believing it means “securityless.” #Cybersecurity

020

your #AI injection defense has a blind spot: it can't tell you when it fails. a #classifier that misses an attack doesn't raise its hand. you find out from a support ticket.

010

model stealing sounds fancy until you realize it’s just downloading weights like a pirate. #machinelearning

020

Lockpick Village – Physical security meets hacking: attendees learn to pick real locks, often opening “secure” high-end cylinders in under a minute. A DEF CON tradition that’s outlived several encryption algorithms. #defcon

000

it’s always the endpoints with “test” in the name that give the best surprises. #bugbounty

001
Показать ещё