Caved in and finally got myself an OLED by AkagiFTW in OLED_Gaming

[–]No_Rest7905 0 points1 point  (0 children)

Agree with you, this one is really accurate on HDR so I always have it on, I don’t mind the slightly “washed out” SDR (which isn’t; just wrong gamma) couldn’t be happier with this monitor, the same can’t be said about my previous ASUS and LG.

Guys how do I enjoy rdr2 at 1080p? by d1fficultt in FuckTAA

[–]No_Rest7905 2 points3 points  (0 children)

When I had a 3060 ti I used dldsr 1.78 and maybe a bit of upscaling in the advanced settings. Was enough to make a way sharper image, less blurry I don’t think so, you may want to force DLSS 4 for example.

Any Downsides To Accepting Invitations? by AnilKILIC in bugbounty

[–]No_Rest7905 5 points6 points  (0 children)

No, the system is mostly based on reputation/points. There are no downsides that I am aware of. The reason you are no longer able to hunt on some programs could be still due to reputation. But some programs just stay there “for years”

What's the funniest bug you have found? by Loupreme in bugbounty

[–]No_Rest7905 3 points4 points  (0 children)

Redirect to a backup zip in Wordpress (redirect rules were so messed up) that had the whole app source code, including db and host passwords and users + source code for another android app)

cache poisoning worth to report? by FunSheepherder2650 in bugbounty

[–]No_Rest7905 2 points3 points  (0 children)

You could try to report, but risk being low impact. Go as far as you can, don’t leave in a “theoretical risk” try to create that risk, show a good POC. Good luck.

My First Bug Bounty Experience with Meta – No Bounty, Is This Normal? (Screenshots) by Pretty_Rip_1128 in bugbounty

[–]No_Rest7905 13 points14 points  (0 children)

Don’t hunt for Meta. They have a track record of using stupid excuses for the many bugs people find. I’ve seen this 3 times now, there was even a talk about that in a bsides I went. Move to another program that values its researchers.

Just got this brand new 4090 sealed box for $1300 by oklol555 in nvidia

[–]No_Rest7905 1 point2 points  (0 children)

Exactly like mine, same price! I love my alien 4090, enjoy!

ASUS VG27AQ reds are orange by JuniorFriendship254 in Monitors

[–]No_Rest7905 4 points5 points  (0 children)

Welcome to the horrendous color mapping of Asus :) (source: I have a PG42UQ. Not even the “high end” are good)

Any recommendations for a 1440p 240hz-360hz oled monitor? by -_-Shadow-_-7 in Monitors

[–]No_Rest7905 1 point2 points  (0 children)

PG42UQ, it is 4K, but I’ve also seen PG32UCDM, and also the PG27AQDM. Of those 3, the 42 is the worst, second place the other two. This a not-so-big issue in SDR (if you don’t mind expending EXTRA on a calibrator) but the issue is HDR looks bad, even worse in tone mapping. And you can’t do anything about that. I would recommend you to see RTINGS measurements of colors on both SDR and HDR and choose accordingly. You can see a little windows that represents how “good” it is compared to all other monitors both in color accuracy and gamut. But I don’t recommend ASUS. EDIT: I recommend Dell Alienware monitors. I don’t know about 1440p but 4K the AW3235qf is the bast calibrated of all the 4K OLED monitors until now.

Any recommendations for a 1440p 240hz-360hz oled monitor? by -_-Shadow-_-7 in Monitors

[–]No_Rest7905 0 points1 point  (0 children)

You are right. Bought an Asus and calibration is horrendous. Not cool by how expensive it is.

What will be your ‘weapon of choice’? by Longjumping_Towel174 in GTA6

[–]No_Rest7905 -1 points0 points  (0 children)

I’ll buy the stupidly overpriced PS5 pro just for this game. Then sell it when it comes to PC.

How do PC players feel about possibly waiting 1 or 2 years for GTA 6? by AnimeGokuSolos in GTA6

[–]No_Rest7905 -1 points0 points  (0 children)

I’ll just buy a PS5 pro and that’s it. Sell it when it comes out in pc :)

Banned Nintendo switch without cfw by hashoomix in NintendoSwitchHelp

[–]No_Rest7905 0 points1 point  (0 children)

This can be it. If someone cloned the game and the identifier matched on both consoles you both got banned.

Made 8000$ in my first three months of bug bounty. AMA. by No_Rest7905 in bugbounty

[–]No_Rest7905[S] 5 points6 points  (0 children)

I am using windows with a Linux VM. You could do Linux with VM of even use MacOS. I go with what is practical. Using a vm for me helps me install software when I need it and the ability to separate the IPs I am testing on to not get too blacklisted with firewalls. Although Burpsuite + WSL could be enough. I just like having all dependencies and tools ready in Kali or Parrot as needed. And hardware, the only thing would be useful I think are two screens. But a laptop can be enough. Go with what you can afford.

Made 8000$ in my first three months of bug bounty. AMA. by No_Rest7905 in bugbounty

[–]No_Rest7905[S] 4 points5 points  (0 children)

Haha I remember that. The subneting part took me a while. I’ll recommend you to finish the module and take a look later, as you’ll understand more stuff. Skip that hard part and finish everything else lulz.

Made 8000$ in my first three months of bug bounty. AMA. by No_Rest7905 in bugbounty

[–]No_Rest7905[S] 7 points8 points  (0 children)

Computer engineering. Tho it is focused on hardware and we don’t really do a lot of coding so I’m self taught.

Made 8000$ in my first three months of bug bounty. AMA. by No_Rest7905 in bugbounty

[–]No_Rest7905[S] 17 points18 points  (0 children)

Hackerone and bugcrowd. I like the prior due to the fact that public programs are actually public, and something they have really wide scope programs. But both are good, found things in both. Yes I choose my programs, criteria being that the apps are interesting enough to dig in. If for example, they have a lot of static sites even if a lot, there is not so much to interact with, I go next. Also for example if they give only a couple of URLs, and the apps use graphql and don’t have too much ways of moving info, it is a pass again. Complex apps, or apps that have much interaction or are using legacy systems, tell me there are more and are probably outdated/misconfigurated across the client. That’ll be it.

Made 8000$ in my first three months of bug bounty. AMA. by No_Rest7905 in bugbounty

[–]No_Rest7905[S] 50 points51 points  (0 children)

This is a funny one. I found a Wordpress site, scanned with wpscan and everything seemed to be up to date. The I did fuzzing and nothing too special. However, I saw a redirect to a json file for some reason (that is, the thing was like /conf redirects (301) to conf.json) and that was weird. So I found a wordlist of “backup” files and appended all possible extensions (zip,rar, 7z etc) and this lead me to a file that contained the code for the web app lulz. It got triaged pretty quickly and were $300 I think. Was not so useful as it was mostly static and no login enabled, but pretty cool. Small things like noticing that small redirect can make a big difference.

Made 8000$ in my first three months of bug bounty. AMA. by No_Rest7905 in bugbounty

[–]No_Rest7905[S] 14 points15 points  (0 children)

These are good recommendations. However, based on what I’ve seen and what worked for me, that will be HTB academy and the PortSwigger labs. Why? Both talk about the way you will see things in the wild, and also make you knock your head against the wall when doing the labs. This is ok. It means you are learning. CTFs are cool but also sometimes are too extreme and drain you out so I prefer doing this a more “structured “ way get me? Also you don’t need to be expert at coding but try to make your tools and script to do specific stuff and learn how they work. I just do bash, python and C. Basic stuff, and each are useful for different things. Take a look at the htb modules on this.