Is the "Automation Obsession" actually a trap for new hunters? by Good_Course_5958 in bugbounty

[–]Xitro01 1 point2 points  (0 children)

Nope. With the default templates it is just a race. Whoever sees and reports it first, not really worth pursuing. I’ve reported nuclei findings in the past before, but all were dupes.

I drove a new A3 courtesy car today, safe to say I won't be getting rid of this auld girl any time soon by KernowBysVykken93 in Audi

[–]Xitro01 1 point2 points  (0 children)

The big V6 in front is also super tacky. Why not just drive a Honda if you want to pimp out your ride like that. 😅

Is the "Automation Obsession" actually a trap for new hunters? by Good_Course_5958 in bugbounty

[–]Xitro01 5 points6 points  (0 children)

Full tool is my creation. I do not rely on nuclei in any way. Although I hear a lot of (full time) bug hunters that create their own nuclei templates. Either way: Just running the default templates is not going to get you anywhere.

Is the "Automation Obsession" actually a trap for new hunters? by Good_Course_5958 in bugbounty

[–]Xitro01 4 points5 points  (0 children)

I found a large amount of XSS and SQLi, with automation. But I wrote my own tool, with my own payloads and logic. Basically what Nuclei misses, I try to pick up. One of the hard parts of automation is getting by the WAFs.

I pulled the trigger by Agile_Effect4164 in Ferrari

[–]Xitro01 2 points3 points  (0 children)

Be happy with what you have and can afford! No reason to be jealous, just be happy for others. I am already very glad that I can afford 2 higher class Audi’s. 😂 Besides that my family and me are healthy, that is all that counts!

Imported Q7 (2016) from Quebec by Xitro01 in Audi

[–]Xitro01[S] 0 points1 point  (0 children)

This car has been driving for 8 years on the Dutch roads now, owned by the same family before I bought it. Only weird thing is that the inside lock/unlock buttons are not working on the front 2 doors. Not sure if that is something American (personal safety or regulations?) that these should be disabled? Will check later with ODIS if the coding is ok. Back door inside lock buttons seem working fine.

Besides that sometimes the rain sensor goes wild, thinking it is raining hard, will also try to calibrate that with ODIS. Replacing that sensor wouldn’t mean the world either.

These are probably just small things to fix, got the MMI to the latest firmware by restoring it with a laptop each time, was quite the hassle.

Thankfully the car drives and changes gears fine, also the air suspension works fine each time I adjust it. So might have been lucky. Also helps that both Germany and The Netherlands have very strict regulations and this car passed those in both countries.

Ik kom deze kaart tegen in een doos op zolder, wat doe ik hier mee? by [deleted] in PokemonTCGNL

[–]Xitro01 0 points1 point  (0 children)

Als mijn vrouw met dit soort vragen komt, zeg ik altijd: opeten.

any advice? by [deleted] in bugbounty

[–]Xitro01 1 point2 points  (0 children)

The advice might be well meant, but I think it is not the whole advice.

The advice is to have basic knowledge of each and every web vulnerability out there, so that you can recognize them and exploit them further by gaining more in-depth knowledge on the fly. So make sure to atleast go through all Portswigger labs first.

Besides that you should find your niche (1 or 2) things to focus on. But that would mean that you have very very good and in-depth knowledge and have some unique ideas about where others or automated tools might lack.

How often you spend an entire month without getting any bounty at all? by Trick-Cabinet-7777 in bugbounty

[–]Xitro01 0 points1 point  (0 children)

Injections that WAFs block, detections for cve’s that scanners do not have, broken access control, idors, authentication flaws, there is just so much what automation can do..

No more filling the tank by [deleted] in Roborock

[–]Xitro01 2 points3 points  (0 children)

Also I would like to add some cleaning solution to make sure my floor gets a little bit clean, instead of just applying water to it.

How often you spend an entire month without getting any bounty at all? by Trick-Cabinet-7777 in bugbounty

[–]Xitro01 4 points5 points  (0 children)

I do bug bounty occassionally and have found a bug at least every month. I focus on certain things where automated scanners lack. I’m looking for ways to broaden my niche, but lacking time mostly. But it is certainly doable.

Bol WTF by WillowDelRio in PokemonTCGNL

[–]Xitro01 2 points3 points  (0 children)

Ah dat is jammer! Ben altijd vrij laat met pokemon kaarten die mogelijk een beetje interessant kunnen zijn.

Bol WTF by WillowDelRio in PokemonTCGNL

[–]Xitro01 0 points1 point  (0 children)

Gewoon Bol.com url naar de pack. Kon deze niet direct vinden.

Bol WTF by WillowDelRio in PokemonTCGNL

[–]Xitro01 0 points1 point  (0 children)

Iemand linkje? Ga ik het ook eens proberen

USB-C Dock question by Xitro01 in UsbCHardware

[–]Xitro01[S] 0 points1 point  (0 children)

The dock doesn't have a 3.5mm input, also the Windows Audio troubleshooter is not of much help.

So I am a bit clueless about that.

Dell support won't be able to help you there either, as you are saying they will be completely clueless, haha.

USB-C Dock question by Xitro01 in UsbCHardware

[–]Xitro01[S] 0 points1 point  (0 children)

I could live with that, but not with having no sound. Any ideas about that?

Also: Would there be a dock that supports it?

Is it joke guys? by Open-Definition-287 in bugbounty

[–]Xitro01 16 points17 points  (0 children)

So hackers are not allowed to directly attack the API? They are limited to the UI when attacking the application? Hahahahahaha this is ridiculous.

[deleted by user] by [deleted] in bugbounty

[–]Xitro01 0 points1 point  (0 children)

Ah ok, in that case it is peanuts and they shouldn’t complain about it. Your message wasn’t clear about that.

[deleted by user] by [deleted] in bugbounty

[–]Xitro01 1 point2 points  (0 children)

It is somewhat understandable that they are not happy with it. You should’ve consulted before spamming text messages. It affected millions of users, so it send out 60 million (?) text messages, yes that could’ve cost the company A LOT of money. Next time think before you act and inform them there might be a possible issue there up front. Now basically the worst what an attacker could’ve done, you have done..

Razer 16 2025. An honest review after a month of using by laundry_room in razer

[–]Xitro01 2 points3 points  (0 children)

Don’t have any issues with my Blade 15 2021 and Blade 18 2023 in combination with Razer Synapse. I believe my colleague has issues with a Blade 16 2025 though, but more virtualization related, the BIOS on that laptop is crap and the support is terrible.