Подтвердите e-mail

Для публикаций, комментариев, реакций и сообщений подтвердите адрес.

Профиль

ToxSec

Профиль Vively

Security Engineer M.S. Cybersecurity, CISSP. AWS, NSA, USMC. www.toxsec.com

LOpht Heavy Industries (1998) This Boston hacker collective testified before Congress that they could take down the entire internet in 30 minutes. Instead of arrests, lawmakers asked for security advice. A turning point for hacker culture! #Hackers

000

Nepenthes, Iocaine, and Cloudflare's AI Labyrinth, broken down in full: www.toxsec.com/p/ai-tar-pit...

AI Tar Pits Are Drowning LLM Scrapers in Infinite GarbageHow tools like Nepenthes, Iocaine, and Cloudflare’s AI Labyrinth trap unauthorized crawlers in endless mazes of generated nonsense and poison the training set on the way out.www.toxsec.com
000

AI crawlers hit #Cloudflare's network with more than 50 billion requests a day. The defense that actually scales isn't a block list. It's a maze that feeds the bot infinite generated garbage until it burns its own #compute wandering pages that go nowhere.

120

every payload that fails is just one closer to the one that works. #bugbounty #infosec

020

Duplicate reports: rite of passage or character-building exercise? #BugBounty

020

Keep pushing. The best bugs usually show up after you almost quit. #bugbounty #hacking

010

Blue Boxing Steve & Woz (1971) – Before founding Apple, Jobs and Wozniak sold homemade blue boxes to college kids, bragging they could call the Pope by routing through Vatican City trunks. #Hackers

020

so the rumor has it that #chatgpt 5.6 is going to be dropping soon and that according to the #benchmarks it can beat fable in several key areas. all this leads me to wonder: if it's better than #fable with agentic coding, is it also going to be slapped with ear export #controls?

120

Have you ever found a high-impact bug outside of scope—did you report it anyway? #BugBounty

010

ever hit a scope so empty you wonder if it’s just a decoy? #bugbounty

010

#Fable 5 was pulled. The #jailbreak that pulled a frontier model offline for the whole planet: ask the model to read a codebase and find bugs. That's it. That's the weapon. Anthropic ran it and watched it surface vulns #GPT-5.5 hands you with no bypass at all.

130

no better feeling than watching your payload echo back in the response. #bugbounty

010

when burp’s history tab looks like a conspiracy wall. #bugbounty

010

Stay patient. Bug bounty is a long game, not a quick hack. #cybersecurity

010

HTTP Request Smuggling (CL:TE) How header mismatch between Content-Length and Transfer-Encoding lets attackers slip hidden requests past your edge and into the backend. Full breakdown of mechanics, recon tips, and real bug bounty angles. www.toxsec.com/p/http-reque... #Cybersecurity

HTTP/1.1 Request Smuggling | CL:TEToxSec | HTTP Request Smuggling Guide for bug bounty.www.toxsec.com
121

#Anthropic just release #Fable 5. ⚠️ The #Mythos class model made safe. Cybersecurity guardrails and impressive benchmarks. Can’t wait to see how it handles!

020

half of bug hunting is fighting with your own regex. #bugbounty

010

BGP Hijack of YouTube (2008) – Pakistan Telecom accidentally advertised a bogus route and knocked YouTube offline worldwide for two hours—showing how fragile the internet’s core routing really is. #Hackers

010

funny how bug bounties turn into archaeology… digging through layers of old code nobody’s touched in years.

010

sometimes the real vulnerability is the developer’s sense of humor in error strings. #bugbounty

020
Показать ещё