home.social

#bughunting — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #bughunting, aggregated by home.social.

fetched live
  1. Zsh history bug-hunters, get ready to 🤦‍♂️ as the author takes you on an epic journey through the wild world of #inotify, #fatrace, and #bpftrace, just to find out where his precious commands went! Spoiler alert: the solution is in the appendix, because who doesn't love a good footgun? 😜✨
    michael.stapelberg.ch/posts/20 #ZshHistory #BugHunting #CodingAdventures #HackerNews #ngated

  2. Summ3r Of h4ck 2026: разбор заданий отборочного этапа

    C 13 апреля по 10 мая был открыт приём заявок на стажировку Summ3r 0f h4ck 2026 . В этом году на обучающую программу в DSEC by Solar пытались попасть 225 человек – это в несколько раз больше, чем в предыдущие годы! В качестве испытаний в отборочном этапе нужно было решить 10 задач по практической информационной безопасности и пройти интервью. Спасибо всем, кто не только пользовался последними достижениями в области AI, но и активно работал над заданиями сам. Мы это очень ценим! Комментарий от технической команды Summ3r 0f h4ck 2026: « В этом году мы подобрали задания с упором на поиск уязвимостей в веб приложениях, аудиту корпоративной инфраструктуры и поиск уязвимостей в мобильном приложении. В одном из заданий кандидаты расследовали инцидент по логам HTTP-трафика: необходимо было понять, как приложение было взломано, и что смог получить атакующий. Для решения заданий не хватит вузовской программы — нужно активно интересоваться практической ИБ, решать задачи с CTF или лабы по типу Hack The Box. » На стажировку к нам попали 5 участников. Возможно, уже в скором времени они присоединятся к нашей команде. Мы покажем вам решение одного из тестовых заданий. Остальные решения вы можете найти

    habr.com/ru/companies/dsec/art

    #поиск_уязвимостей #vulnerability_research #bughunting #анализ_кода #безопасная_разработка #безопасность_веб_приложений #безопасность_мобильных_приложений #пентест #безопасность_инфраструктуры #active_directory

  3. My day so far

    Got up after a good long sleep and decided to add some pictures to my /me page. Decided that the pictures should be hosted on the same domain but that another subdomain was probably okay.

    Got sidetracked checking out my many open tabs with the intention of closing some. More tabs are now open.

    Browsed places I have previously shared pictures.

    Got sidetracked looking at my past photography.

    Post the first picture to my social media node (here). Added it to my /me page.

    Added a link to my site about my dad as it was relevant.

    Got sidetracked updating the code that runs the site. All up to date.

    Posted said first post. That’s odd; the manual ping did not send. Sent a ping.

    Got sidetracked when I remembered one of my blogs was flooding someone’s website with mentions.

    Got sidetracked reading their blog while trying to remember which site I linked to it on.

    Remembered and opened the blog in question.

    Got sidetracked checking comments held for moderation.

    Got sidetracked replying to comments

    Got sidetracked following a link in the comments

    Got sidetracked reading about ADHD diagnosis options

    Got sidetracked messaging my sister about an idea from following the link

    Got sidetracked posting a reply thanking for link

    Got sidetracked back to bug hunting.

    Got sidetracked when asking AI why the pings keep sending; learned I might want to look at the post meta for pings sent. Realised I needed to know the blog ID as it is part of a network.

    Went to the blog’s parent blog to look up its blog ID.

    Got sidetracked removing spam from parent blog

    Got sidetracked checking which email domains spammers were using and blocking them

    Got sidetracked refreshing RSS feeds for the parent site.

    Looked up blog ID; opened PHPMyAdmin to look at post meta. Yep, the flooded site is not listed.

    Went to GitHub and found someone had opened an issue about this. Posted my findings to the issue.

    Got sidetracked browsing the issues on GitHub

    Got sidetracked commenting on issues

    Got sidetracked when I panicked and thought it was Thursday, and I was running late. I was halfway to getting ready to go out when I realised it was Wednesday.

    Got sidetracked writing this post about how often I got distracted today

    What do you mean by attention issue?

    I guess I will try and find my way back to adding photos to my /me page.

    https://www.youtube.com/watch?v=SSUXXzN26zg

  4. 🔍🤯 Oh, the thrill of chasing a barely pubescent bug through the tangled jungle of #SQLite with TLA+! 🐛🕵️‍♂️ Meanwhile, enjoy unwanted pop-ups about Ubuntu updates and futile attempts at unsubscribing—because nothing says "bug hunting" like a barrage of irrelevant notifications! 📬🙄
    ubuntu.com/blog/hunting-a-16-y #TLA+ #BugHunting #UbuntuUpdates #TechHumor #HackerNews #ngated

  5. RT @TheRegister: TRANSLASATION: Linus Torvalds sagt, dass KI-gestützte Bug-Hunter die Linux-Sicherheits-Mailingliste „fast vollständig unmanageable“ gemacht haben.

    mehr auf Arint.info

    #AI #BugHunting #CyberSecurity #LinusTorvalds #Linux #OpenSource #arint_info

    https://x.com/TheRegister/status/2056158625371193418#m

  6. El lado del mal - "Bug Hunter": Guía, herramientas y técnicas del Bug Bounty en la era de Inteligencia Artificial. Nuevo libro en 0xWord elladodelmal.com/2026/04/bug-h #0xWord #Libro #BugHunting #BugHunter #0xWord

  7. Das @Krokodil, auch bekannt als professionelle Bugjägerin, hat mir ein niedliches kleines Short über ihren Arbeitstag zukommen lassen.

    99 little bugs in the code...

    🌀 youtube.com/shorts/PHw2OuydiOQ

    #programming #programmerslife #bugfix #bughunting #bugs #bugfixes #programmer #code #coding #codecheck

  8. 213/338 - takový je stav migrace tweetbotů ze starého do nového systému.

    Počty ostatních zdrojů se nemění, neb již aktuálně není co migrovat.

    #zpravobot #bughunting

  9. Stav k dnešnímu večeru:

    V novém ZBNW-NG je celkem 274 zdrojů rozdělených takto:

    118 RSS - nejvíc, hlavní páteř systému
    85 Twitter - druhá největší platforma
    29 Facebook - významná skupina
    17 YouTube - video obsah
    14 Bluesky - rostoucí platforma
    9 Instagram - vizuální obsah (všechny přes RSS)
    2 feed - Bluesky custom feeds

    A teď jdu spát. Brou.

    #zpravobot #bughunting

  10. Povšechná informace o implementaci Zprávobot.news Next Generation:

    Dnes jsem dle všeho dokončil vývoj. Nové featury přidávat nebudu a provádím jen fixy bugů.

    Účty do nového systému migruju postupně dle toho, co zrovna potřebuju testovat. Každopádně jsou přemigrované všechny BS, FB, IG, YT a také RSS z RSS.app. Kromě toho po novu běží i vyšší desítky Xbotů.

    A prosím o pomoc s lovem brouků. Pokud najdete něco "divného", dejte mi vědět a mrknu na to. Díky.

    #zpravobot #bughunting

  11. Анатомия Prompt Injection: Как я вошел в топ-10 глобального рейтинга Lakera Agent Breaker

    Как пробить многоуровневую защиту LLM-агента, обученную на 80+ млн атаках? В декабре 2025 я вошел в топ-10 глобального рейтинга Lakera Agent Breaker. В этой статье - не просто обзор решения, а детальный разбор уязвимостей современных LLM-систем и архитектура кастомного фаззинг-пайплайна.

    habr.com/ru/articles/979476/

    #информационная_безопасность #искусственный_интеллект #llm #языковые_модели #хакатон #cybersecurity #ai #leaderboard #ctf #bughunting

  12. 🚨BREAKING: Software engineers discover bugs exist in their codebase! 🎉 After a week of bug-hunting, they are shocked—shocked, I say—to learn their roadmap wasn't paved with 189 "Oopsies" all along. Nothing says "progress" like finally realizing your app shouldn't crash on Tuesdays! 🤦‍♂️✨
    lalitm.com/fixits-are-good-for #softwareengineering #bughunting #technews #appdevelopment #oopsies #HackerNews #ngated

  13. Hello! I’m building a mentoring platform for aspiring #hackers and security learners who want deeper, non-corporate guidance. It’s for self-taught people and students (OSCP, cybersecurity degrees) who want 1-on-1 help. learn2hack.today is almost ready and accounts will open soon. If you're interested, fill this: tally.so/r/J9KZkz
    #hacking #mentoring #students #hackerculture #hackers #students #cybesecurity #security #redteam #pentesting #hackingisnotacrime #oscp #ctf #bughunting

  14. 🚫 403 Forbidden: When your "investigative journalism" turns into a digital knock-knock joke 😆. Apparently, the real bug here is your ability to access anything beyond the error page. 🐞🔍
    mensfeld.pl/2025/11/ruby-ffi-g #403Forbidden #InvestigativeJournalism #DigitalJoke #AccessIssues #BugHunting #HackerNews #ngated

  15. 👽 So, software is the mysterious 'Area 51' of engineering, where developers claim to have seen unicorns (or bugs) no one else can find? 🚀 Apparently, we're all just code conspiracists waiting for our own Roswell moment. 😂
    codemanship.wordpress.com/2025 #softwareengineering #codeconspiracies #techhumor #developerlife #bughunting #HackerNews #ngated

  16. 🚨 Breaking news: After years of blissful ignorance, our protagonist discovers that #PyTorch is not, in fact, infallible! 😱 Instead of the usual user error, it turns out the culprit was a PyTorch #bug all along—cue the collective gasp of shock and awe. 🎉 Here's to the next few years of bug-hunting instead of actual learning! 🐛🔍
    elanapearl.github.io/blog/2025 #Discovery #UserError #BugHunting #MachineLearning #HackerNews #ngated