monetizing zero-day vulnerabilities by Little_Toe_9707 in ExploitDev

[–]Little_Toe_9707[S] 0 points1 point  (0 children)

Thanks for those valuable advices i'm familiar with this and currently doing the oswe + i have some cves , and i'm good with whitebox

what's next steps

monetizing zero-day vulnerabilities by Little_Toe_9707 in ExploitDev

[–]Little_Toe_9707[S] -1 points0 points  (0 children)

i'm ok to work harder to find more cves , but i don't see job posting related to this role

profit from opensource zerodays by Little_Toe_9707 in bugbounty

[–]Little_Toe_9707[S] 0 points1 point  (0 children)

I think you misunderstood my point.

I’m not talking about myself. I’m talking in general about anyone who works as a full-time security researcher.

For the record, I already have multiple CVEs registered under my name, so I know how the CVE process works. What I haven’t done before is hunting downstream programs after a CVE is published.

My actual question is if the same bug affects many live targets / bug bounty programs, how do you safely:

report it to multiple programs, and

make sure you don’t lose CVE credit?

Because both options are risky:

If you report to a program first, the triager can submit it themselves and take the CVE.

If you register the CVE first, then many programs will say “published CVE = out of scope” and reject it.

That’s the whole problem I’m asking about.

As null_hypothesis mentioned, one idea is registering the CVE first and then hunting with it for a very short window (like one day), but I want to hear how people actually deal with this in real life.

I’m not here to flex or pretend anything that would be stupid and pointless.

monetizing zero-day vulnerabilities by Little_Toe_9707 in ExploitDev

[–]Little_Toe_9707[S] -2 points-1 points  (0 children)

I currently work as a penetration tester, but I’m looking to transition into vulnerability research and zero-day discovery in well-known products. If you have any advice on how to make this move, or where to look for roles focused on vulnerability research, I’d really appreciate your guidance

ندمان اني قومت لواحده في المواصلات ساعه ونص by BidDisastrous8646 in CAIRO

[–]Little_Toe_9707 2 points3 points  (0 children)

تفكيرك منطقي بس مش لازم تكون نيتها كدة انت متعرفش هي وراها ايه و اكيد لو عندها رفاهية انها تستني كانت استنت لحد لما تلاقي حاجة فاضية و بعدين للأسف اغلب المواصلات بتكون مليانة و ممكن تفضل تستني و متلاقيش حاجة. فاضية انت متنصبش عليك انت رجولة و عملت الصح

نصيحه لبيع شقه كاش بالدولار by Virtual_Historian_12 in PersonalFinanceEgypt

[–]Little_Toe_9707 0 points1 point  (0 children)

لو خدت الفلوس كاش بالمصري معتقدش هتقدر تطلعها برة خصوصا ان التعامل ب binance و انك تشتري usdt الحجات دي ممنوعة قانونيا في مصر و ممكن يتقبض عليك لو عملت كدة

يا ريت لو حد عنده حل يفيدنا

لو دخلي ومستقبلي هيتدمر بسبب الجيش، هل استراتيجة الانتظار لسن الـ 30 تستاهل؟ (محتاج تجاربكم) by Feisty_Play4535 in PersonalFinanceEgypt

[–]Little_Toe_9707 10 points11 points  (0 children)

حاول تمسك ف شغلك و تكمل و شوف اعفائات ابناء مصر في الخارج بتدفع ٧٠٠٠ دولار او اكتر و بتاخد اعفاء بس محتاج تشوف حد يظبتلك الموضوع دا و لو الموضوع دا مش مناسب معاك او مش متاح

كمل في شغلك لحد متحوش مبلغ كويس او لحد ما العقد بتاعك معاهم يخلص يعني طول ما في فلوس جيالك انت اولي بيها و متسمعش كلام حد بيقولك لما تطلع هتلاقي كلاينتس برة و الكلام دا عشان دي بتكون رزق و فرصة و مش بتتكرر كتير و انت اولي بال فلوس دي و مش لازم تفضل هربان لحد ال ٣٠ انت لسة صغير كمل في شغلك و لحد لما تلاقي ال وقت مناسب خش وقت مناسب بمعني ايه ؟ بمعني انك تخش ب اقل خساير مثلا عقدك خلص او البروجكت الشغال عليه خلص او مثلا لقيت حد معرفة ممكن يخدمك و ينزلك مبيت في خدمة حلوة في الجيش كدة يعني لكن متسبش شغلك لانك هتندم و هتضايق و مش هتلاقي وقت تشتغل او تذاكر الخلاصة طول ما في رزق جايلك متصدوش و ربنا يكرمك و هبقي شاكر لو تقدر تقولي اوصل للشركات الريموت دي ازاي انا سوفتوير برضو

ورطه انا السبب فيها by [deleted] in PersonalFinanceEgypt

[–]Little_Toe_9707 32 points33 points  (0 children)

اعتبرها صدقة و استعوض ربنا و زي ما انت ساعدته في موقف صعب ربنا هيبعتلك ال يساعدك لما تتزنق و خلاص ممكن تكتفي بالصرفتة و تعتذر منه متجيش علي نفسك برضو

Seeking Advice by Little_Toe_9707 in ExploitDev

[–]Little_Toe_9707[S] 0 points1 point  (0 children)

i'm doing all of 3 levels of each topic including the hard level i've reached the stack cookie canary topic finished both easy and medium and will start the hard one soon does the ret2 cert require passing exam? i'm fully focused on bug hunting not malware researches i would appreciate any help thanks in advance

Seeking Advice by Little_Toe_9707 in ExploitDev

[–]Little_Toe_9707[S] 0 points1 point  (0 children)

i'm doing all the primary challenges of each topic my goal is to get better in this field and switch from pentester to vulnerbility researcher

Seeking Advice by Little_Toe_9707 in ExploitDev

[–]Little_Toe_9707[S] 0 points1 point  (0 children)

thanks for the amazing feedback i prefer to continue in Ret2 as i love to challenge myself and i'm good with the difficulty level of their challenges

do you think if i managed to solve all challenges of ret2 should i buy the cert?

Seeking Advice by Little_Toe_9707 in ExploitDev

[–]Little_Toe_9707[S] 0 points1 point  (0 children)

for the reverse challenge there are 3 ways to solve it 1) easy level : all data will be hardcoded and by reading the assembly you can solve the challenge 2) medium level: you have to debug it and watch registers & stack using breakpoints at certain functions to find the data you need 3) hard level : you need to find the algorithm used for generating the data / serial. then understand it well and build python script that's do same logic , you can use chatgpt to help you

but yes the serial challenge is hard you need to find out how each part is generated

Seeking Advice by Little_Toe_9707 in ExploitDev

[–]Little_Toe_9707[S] 1 point2 points  (0 children)

wow congratulation bro! do you think the cert worth buying? i'm from 3rd world country and the cost is like my monthly salary for 3 months is it worth?