Anton (therceman)

Anton (therceman)

@therceman.bsky.social

Bug Bounty Hunter www.therceman.dev

809 Followers 80 Following 25 Posts Joined Nov 2023
9 months ago

Hello everyone πŸ‘‹
Almost 800 followers, wow πŸ˜€

1 0 0 0
1 year ago

Merry Christmas πŸŽ„

0 0 0 0
1 year ago
Post image

Bug Bounty Tip

SSRF: PDF iframe Injection

Cheers!

10 3 1 0
1 year ago
Bug Bounty Tips & Tricks Vol.1

You can purchase the pre-sale edition of the book or download the preview edition at book.therceman.dev

0 0 0 0
1 year ago
Post image

Bug Bounty Tip

SSRF: PDF iframe Injection

Cheers!

10 3 1 0
1 year ago
Post image

Bug Bounty Tip

Parameter Manipulation:
Email Link Hijacking

Cheers!

5 2 1 0
1 year ago
Bug Bounty Tips & Tricks Vol.1

You can purchase the pre-sale edition of the book or download the preview edition at book.therceman.dev

0 0 0 0
1 year ago
Post image

Bug Bounty Tip

Parameter Manipulation:
Email Link Hijacking

Cheers!

5 2 1 0
1 year ago

Help Jobert Abma to claim his account. Report fake one with the proof to this X post x.com/jobertabma/s...

0 0 0 0
1 year ago
Post image

Bug Bounty Tip

XSS Filter Bypass: mXSS

Cheers!

7 2 0 0
1 year ago
Post image

Bug Bounty Tip

XSS Filter Bypass: mXSS

Cheers!

7 2 0 0
1 year ago
Post image

My latest blog post is live! nastystereo.com/security/cro...

Read how to send a cross-site POST without including a Content-Type header (without CORS). It even works with navigator.sendBeacon

79 29 3 4
1 year ago

Thanks, good luck you too! πŸ™Œ

Waiting for my first payout from them, it’s in pending state currently. Let’s see how it goes…

Gumroad pays on time though, every thursday, but sadly only card payments accepted…

0 0 0 0
1 year ago
Post image

You can now download preview edition of my bug bounty book with 3 tips & tricks

book.therceman.dev

Cheers!

2 1 1 0
1 year ago
Post image

You can now download preview edition of my bug bounty book with 3 tips & tricks

book.therceman.dev

Cheers!

2 1 1 0
1 year ago
Post image

Bug Bounty Tip

XSS WAF Bypass by multi-char HTML entities

fj translates to fj
>⃒ translates to > + [?]
&nvlt; translates to < + [?]

[?] - Unicode symbol

3 0 0 0
1 year ago

I believe this can be the place to share everything you like on your life journey πŸ˜€

2 0 0 0
1 year ago

Awesome! Congratulations πŸ™Œ

0 0 0 0
1 year ago

Yup πŸ˜€

0 0 0 0
1 year ago

That’s EPIC! πŸ‘

0 0 0 0
1 year ago

Programming adds more value to cybersecurity and bug bounty.

It helps with automation, the creation of high-quality POCs, the ability to understand and review source code, the setup of local testing environments, and more.

0 0 0 0
1 year ago
Preview
Bug bounty hunters & content creators Join the conversation

The "bug bounty hunters and content creators" starter pack is now up to 60 users! Follow this to get instantly connected to the bug bounty community & let me know if I've missed you off!

go.bsky.app/GD7hKPX

87 22 19 4
1 year ago
Post image

My bug bounty book is now available on Lemon Squeezy, offering more payment options for your convenience.

Cheers!

3 0 0 0
1 year ago
YouTube
DEF CON 32 - Splitting the email atom exploiting parsers to bypass access controls - Gareth Heyes YouTube video by DEFCONConference

In case you missed it...the DEF CON video of my talk 'Splitting the Email Atom' is finally here! πŸš€ Watch me demonstrate how to turn an email address into RCE on Joomla, bypass Zero Trust defences, and exploit parser discrepancies for misrouted emails. Don’t miss it:

youtu.be/JERBqoTllaE?...

95 30 2 0
1 year ago

Hi πŸ‘‹

1 0 0 0
1 year ago
Post image

Bug Bounty Tip

You can hide your XSS payload inside SVG or Math element to bypass the XSS Sanitizer or WAF filter

Cheers!

16 1 0 0
1 year ago

Any bug bounty people around? I'm creating a starter pack of people to follow but it's pretty brief currently! Let me know if you'd like to be added: go.bsky.app/GD7hKPX

95 30 45 2
1 year ago

πŸ‘‹

1 0 0 0
1 year ago
Post image

Book: Bug Bounty Tips and Tricks Vol.1
Edition: Pre-Sale
Tricks: 18 Tips and Tricks
Price: $13.37 (33% OFF)

πŸ”— book.therceman.dev

4 1 0 0
1 year ago

Haha, every gov website has its own server PC under the table πŸ˜„

1 0 0 0