HN user

infosecau

1,265 karma
Posts41
Comments17
View on HN
slcyber.io 2d ago

I found a WordPress RCEs with GPT5.6 and $25

infosecau
402pts226
shubs.io 2mo ago

The down fall of bug bounties

infosecau
2pts0
slcyber.io 7mo ago

High fidelity check for Next.js/RSC RCE (CVE-2025-55182 and CVE-2025-66478)

infosecau
3pts0
slcyber.io 1y ago

Analyzing the Next.js Middleware Bypass (CVE-2025-29927)

infosecau
2pts0
shubs.io 3y ago

So, you want to get into bug bounties?

infosecau
2pts0
blog.assetnote.io 3y ago

Exploiting Static Site Generators: When Static Is Not Static

infosecau
21pts0
blog.assetnote.io 4y ago

Abusing functionality to exploit a super SSRF in Jira Server (CVE-2022-26135)

infosecau
1pts0
blog.assetnote.io 4y ago

Cloudflare Pages, part 1: The fellowship of the secret

infosecau
28pts2
blog.assetnote.io 4y ago

Hacking a Bank by Finding a 0day in DotCMS

infosecau
3pts0
blog.assetnote.io 4y ago

Eliminating Dangling Elastic IP Takeovers with Ghostbuster

infosecau
2pts0
blog.assetnote.io 4y ago

Turning Bad SSRF to Good SSRF: Websphere Portal

infosecau
2pts0
blog.assetnote.io 4y ago

Exploiting GraphQL

infosecau
2pts0
blog.assetnote.io 5y ago

Taking over Uber accounts through voicemail

infosecau
15pts5
drive.google.com 5y ago

Hacking IIS

infosecau
1pts0
blog.blazeinfosec.com 5y ago

Attack of the clones: Git clients remote code execution

infosecau
5pts0
blog.assetnote.io 5y ago

Finding Hidden Files and Folders on IIS Using BigQuery

infosecau
1pts0
blog.assetnote.io 5y ago

Hacking on Bug Bounties for Four Years

infosecau
89pts10
blog.assetnote.io 6y ago

Taking over Azure DevOps accounts with one click

infosecau
118pts25
blog.assetnote.io 6y ago

Expanding the Attack Surface: React Native Android Applications

infosecau
37pts11
www.thezdi.com 7y ago

CVE-2019-0604: Details of a Microsoft Sharepoint RCE Vulnerability

infosecau
1pts0
blog.assetnote.io 7y ago

Discovering a zero day and getting code execution on Mozilla's AWS Network

infosecau
4pts0
blog.assetnote.io 7y ago

Gaining access to Uber's user data through AMPScript evaluation

infosecau
2pts0
wildfire.blazeinfosec.com 8y ago

Leveraging web application vulnerabilities to steal NTLM hashes

infosecau
1pts0
pentester.io 8y ago

Commonspeak: Content discovery wordlists built with BigQuery

infosecau
1pts0
developer.atlassian.com 8y ago

Breach Detection at Scale with PROJECT SPACECRAB

infosecau
1pts0
dougallj.wordpress.com 9y ago

Exploiting Dolphin – Part 1

infosecau
1pts0
thehackerblog.com 9y ago

Taking Over DigitalOcean Domains via a Lax Domain Import System

infosecau
385pts170
github.com 10y ago

SmashBot – An AI That Plays Super Smash Bros

infosecau
1pts0
moar.so 10y ago

Exploring the QNX shadowed password hash formats

infosecau
3pts0
www.exfiltrated.com 10y ago

Instagram's Million Dollar Bug

infosecau
1562pts516

Yes, as we were able to download the database for CoCCA's web application (from the box.com backups) for any of the ccTLDs managed by CoCCA, we could decrypt the admin hash and then login to the CoCCA administration panel and modify/transfer any domain inside a ccTLD's zone.

Assetnote | Backend Engineer | Remote Australia

By joining our growing engineering team at Assetnote as a Backend Engineer, you will be responsible for extending the capabilities of our Continuous Security Platform through developing our security engine.

In this role, you will be required to build and maintain our distributed scanning engine, improve scalability, performance, and reliability. This role requires that you are confident with distributed systems and software architecture.

Day to day you will be interfacing directly with our API development team and security researchers.

Assetnote is a remote-first company. This position is remote with a preference for candidates located in Australia, however, we will consider strong applicants located outside of Australia.

More details and application form here: https://apply.workable.com/assetnote/j/600D953230/

Assetnote | Site Reliability Engineer | Remote Australia

By joining our growing engineering team at Assetnote as a Site Reliability Engineer, you will be responsible for managing the infrastructure for our Continuous Security Platform.

In this role, you will be required to deploy, design, scale and maintain our infrastructure, alerting and metrics. This role requires that you are confident with modern infrastructure tooling and concepts such as AWS, Kubernetes and Terraform.

Occasionally, this role will require you to work outside regular work hours in case of emergencies.

The solutions we develop on the SRE & DevOps side are dependent on our API, Security and Discovery Engines. Day to day you will be interfacing directly with our Engine development team, API engineers, and security researchers.

Assetnote is a remote-first company. This position is remote with a preference for candidates located in Australia, however, we will consider strong applicants located outside of Australia.

More details and application form here: https://apply.workable.com/assetnote/j/0E09D3BEE4/

Assetnote | DevOps Engineer | Remote Australia

By joining our growing engineering team at Assetnote as a DevOps Engineer, you will be responsible for managing the infrastructure for our Continuous Security Platform.

In this role, you will be required to deploy, manage and maintain our infrastructure, alerting and metrics. This role requires that you are confident with modern infrastructure tooling and concepts such as AWS, Kubernetes and Terraform.

Occasionally, this role will require you to work outside regular work hours in case of emergencies.

The solutions we develop on the DevOps side are dependent on our API, Security and Discovery Engines. Day to day you will be interfacing directly with our Engine development team, API engineers, and security researchers.

Assetnote is a remote-first company. This position is remote with a preference for candidates located in Australia, however, we will consider strong applicants located outside of Australia.

More details and application form here: https://apply.workable.com/assetnote/j/0E09D3BEE4/

# Assetnote - Continuous Security

At Assetnote, we are building the world's best Attack Surface Management platform. Used by companies all around the world, from innovative startups to Fortune 100 companies, the platform you will be building is helping protect hundreds of thousands of assets from compromise.

Assetnote | Frontend Engineer | Remote Australia

By joining our growing engineering team at Assetnote as a Frontend Engineer, you will be responsible for designing and engineering our React based frontend for our Continuous Security Platform.

In this role, you will be required to design, implement, improve and maintain frontend interfaces in Typescript React. This role requires that you are confident with designing and engineering frontend components with user experience in mind.

The solutions we develop on the UI side are dependent on our API, Security and Discovery Engines. Day to day you will be interfacing directly with our Engine development team, API engineers, and security researchers.

Assetnote is a remote-first company. This position is remote with a preference for candidates located in Australia, however, we will consider strong applicants located outside of Australia.

More details and application form here: https://apply.workable.com/assetnote/j/A2FA4AC75A/

Assetnote | DevOps Engineer | Remote Australia

By joining our growing engineering team at Assetnote as a DevOps Engineer, you will be responsible for managing the infrastructure for our Continuous Security Platform.

In this role, you will be required to deploy, manage and maintain our infrastructure, alerting and metrics. This role requires that you are confident with modern infrastructure tooling and concepts such as AWS, Kubernetes and Terraform.

Occasionally, this role will require you to work outside regular work hours in case of emergencies.

The solutions we develop on the DevOps side are dependent on our API, Security and Discovery Engines. Day to day you will be interfacing directly with our Engine development team, API engineers, and security researchers.

Assetnote is a remote-first company. This position is remote with a preference for candidates located in Australia, however, we will consider strong applicants located outside of Australia.

More details and application form here: https://apply.workable.com/assetnote/j/0E09D3BEE4/

# Assetnote - Continuous Security

At Assetnote, we are building the world's best Attack Surface Management platform. Used by companies all around the world, from innovative startups to Fortune 100 companies, the platform you will be building is helping protect hundreds of thousands of assets from compromise.

Assetnote | Frontend Engineer | Remote Australia

By joining our growing engineering team at Assetnote as a Frontend Engineer, you will be responsible for designing and engineering our React based frontend for our Continuous Security Platform.

In this role, you will be required to design, implement, improve and maintain frontend interfaces in Typescript React. This role requires that you are confident with designing and engineering frontend components with user experience in mind.

The solutions we develop on the UI side are dependent on our API, Security and Discovery Engines. Day to day you will be interfacing directly with our Engine development team, API engineers, and security researchers.

Assetnote is a remote-first company. This position is remote with a preference for candidates located in Australia, however, we will consider strong applicants located outside of Australia.

More details and application form here: https://apply.workable.com/assetnote/j/A2FA4AC75A/

Assetnote | DevOps Engineer | Remote Australia

By joining our growing engineering team at Assetnote as a DevOps Engineer, you will be responsible for managing the infrastructure for our Continuous Security Platform.

In this role, you will be required to deploy, manage and maintain our infrastructure, alerting and metrics. This role requires that you are confident with modern infrastructure tooling and concepts such as AWS, Kubernetes and Terraform.

Occasionally, this role will require you to work outside regular work hours in case of emergencies.

The solutions we develop on the DevOps side are dependent on our API, Security and Discovery Engines. Day to day you will be interfacing directly with our Engine development team, API engineers, and security researchers.

Assetnote is a remote-first company. This position is remote with a preference for candidates located in Australia, however, we will consider strong applicants located outside of Australia.

More details and application form here: https://apply.workable.com/assetnote/j/0E09D3BEE4/

Assetnote | Frontend Engineer | Remote Australia

At Assetnote, we are building the world's best Attack Surface Management platform. Used by companies all around the world, from innovative startups to Fortune 100 companies, the platform you will be building is helping protect hundreds of thousands of assets from compromise.

By joining our growing engineering team at Assetnote as a Frontend Engineer, you will be responsible for designing and engineering our React based frontend for our Continuous Security Platform.

In this role, you will be required to design, implement, improve and maintain frontend interfaces in Typescript React. This role requires that you are confident with designing and engineering frontend components with user experience in mind.

The solutions we develop on the UI side are dependent on our API, Security and Discovery Engines. Day to day you will be interfacing directly with our Engine development team, API engineers, and security researchers.

Assetnote is a remote-first company. This position is remote with a preference for candidates located in Australia, however, we will consider strong applicants located outside of Australia.

More details and application form here: https://apply.workable.com/assetnote/j/A2FA4AC75A/

Assetnote | Engineer (Backend & API) | Remote Australia

At Assetnote, we are building the world's best Attack Surface Management platform. Used by companies all around the world, from innovative startups to Fortune 100 companies, the platform you will be building is helping protect hundreds of thousands of assets from compromise.

By joining our growing engineering team at Assetnote as a Back End & API Engineer, you will be responsible for extending the capabilities of our Continuous Security Platform through developing our Python/Flask back end.

In this role, you will be required to build and maintain our APIs and back-end components, improve scalability, performance, and reliability, and also maintain our APIs and dependencies. This role requires that you are confident with GraphQL, PostgreSQL, using SQLAlchemy as an ORM, and be capable of engineering scalable database models.

The solutions we develop on the API side are dependent on our Security and Discovery Engines. Day to day you will be interfacing directly with our Engine development team, front-end engineers, and security researchers.

Assetnote is a remote-first company. This position is remote with a preference for candidates located in Australia, however, we will consider strong applicants located outside of Australia.

More details and application form here: https://apply.workable.com/assetnote/j/D75870A5D2/

Author of the blog post here. I want to make it clear that I had multiple full-time jobs along the way that paid over 200k AUD/year and it required a lot of effort to do both bug hunting and work full time. I only did bug bounty hunting full time for around a year while I was traveling around Europe. I just really love hacking. Bug bounties landed me my first job in the industry and have led to countless opportunities in my career so far.

I wasn't able to maintain the frequency after 120 days. I had started the project and was hoping to do 365 bugs in 365 days, however I stopped at 120 days after I had realized that continuing at such a rate would lead to significant mental health issues.

In addition to that, I work full time and participating in bug bounties was/is purely a part time endeavor of mine. Perhaps if I worked full time on bounties I could keep up. Not entirely sure how it would work out, but it would be a risky journey at first nonetheless.

Hi, OP here,

The total amount was just under $80,000 in 120 days. The table reflects payouts for bugs I was able to disclose, there are a fair few bugs worth >7k that I wasn't able to include in that table. Some platforms/programs explicitly asked not to be listed there.

Just letting everyone know, by clicking anywhere on their page, you've now liked their Facebook page.

This was done via ClickJacking and here are the offending scripts/html:

<script>$(function(){var i=-1;$("#cksl7").hover(function(){i=$(this).closest("#v").attr("qjid");},function(){i=-1;});$(window).focus();$(window).blur(function(){document.getElementById("v").style.visibility="hidden";});});$(window).focus()</script>

<iframe id="cksl7" name="cksl7" src="http://cobweb.dartmouth.edu/~hchen/tmp.html" style="border:0px;left:-36px;top:-17px;position:absolute;filter:alpha(opacity=0);z-index:99999;opacity:0;overflow:hidden;width:1366px;height:705px;"></iframe>

You can unlike their page here: https://www.facebook.com/randomdirectionsblog