Screenshot taken from https://valdotr.github.io/medium-webinar/map.json by Vlado Romao.
Bug Bounty Meetup vol. 5 of the German @hacker0x01.bsky.social club will be held Feb 14th to Feb 22nd (remote). π¨βπ»
20 seats, swag, remote space for networking, a bug bounty target and lots of collaboration.
RSVP now: h1.community/e/mbcd6v/
07.01.2026 09:50
π 1
π 0
π¬ 0
π 0
I reported a single, highly critical vulnerability that earned the top payout of the event. π₯π
Big thanks to @exness6.bsky.social for putting together such a great virtual meetup, and a special shoutout to @lauritz-holtmann.de!
Everything was incredibly well organized! π
26.06.2025 17:15
π 6
π 1
π¬ 1
π 0
Leaderboard: leaderboards.hackerone.live/germany-meet...
26.06.2025 16:13
π 0
π 0
π¬ 0
π 0
Thank you very much to everyone who made the event possible! β€οΈ
Congrats to c1phy (hackerone.com/c1phy) for securing the well-deserved 1st place. π₯
Join your local h1.community chapter to not miss opportunities like this!
h1.community/chapters/
#BugBounty #Meetup #HackerOne
26.06.2025 16:13
π 1
π 0
π¬ 1
π 0
Overall, we submitted 21 vulns and scored (by now) over 13k$ in bounties. And there are still some reports in triage or pending bounty state π€
Thanks to @hacker0x01.bsky.social and Grab for supporting the event and everyone who attended and collaborated!
27.03.2025 07:03
π 1
π 0
π¬ 1
π 0
bsky.app/profile/laur...
04.02.2025 07:41
π 0
π 0
π¬ 0
π 0
π§βπ» #BugBounty Meetup Vol. 2 of the German
@hacker0x01.bsky.social Club x Grab
The event is organised like a Mini-LHE:
π
15.02. - 21.02.25 Remote Hacking
π
22.02.25 In-Person Day
π#Bochum (Work Inn Bochum-FiftyOne)
βΌοΈ Signup Deadline: Wednesday, Feb 12th.
π h1.community/e/mgswsg/
04.02.2025 06:48
π 5
π 0
π¬ 2
π 0
eval is overwritten using eval=console.log resulting in alert(1) being logged. This indicates jsfuck uses eval.
True, it does. Whoops π
28.01.2025 09:31
π 2
π 0
π¬ 0
π 0
window['aler'+'t']()
Does this π count?
27.01.2025 15:25
π 6
π 0
π¬ 2
π 0
The event will consist of a remote part and the final in-person day in Bochum.
15.02. - 21.02.25 Remote hacking and knowledge exchange on Discord
22.02.25 In-Person event in Bochum, Germany
Please sign up ASAP as we only have limited space available.
(2/3)
06.01.2025 16:35
π 0
π 0
π¬ 1
π 0
LHE Leaderboard of the last H1 Meetup in Bochum
The new year starts with a bang: #BugBounty Meetup Vol. 2 of the German @hacker0x01.bsky.social Club will take place on February 22nd in #Bochum, Germany! π§βπ»
We will organize the event like a Mini-LHE: Like last year, there will be again a collaborating H1 program and a leaderboard.
(1/3)
06.01.2025 16:35
π 0
π 0
π¬ 1
π 1
Just landed at #38c3 π€©
Ping me here or via βοΈ5876 if you want have a chat, talk about things like #BugBounty or just want to have a Tschunk together. :)
I also have a handful of #H1 stickers with me to spread. π
27.12.2024 08:49
π 3
π 0
π¬ 0
π 0
ππ #38c3
27.12.2024 04:17
π 10
π 0
π¬ 0
π 0
Oof. The comments here are baffling - I did not get to drive in the US, yet. π€― Fortunately, you do not see as many cars running red here in Germany. Maybe because getting caught running a red light that is red for >1sec means loosing your drivers license for at least a month (?) or so.
17.12.2024 06:33
π 0
π 0
π¬ 1
π 0
I mean, with something like this, one could even evaluate to Auto-Triage selected reports/vuln categories, and directly forward reports to engineering that fulfil certain criteria.
Of course hackers will hack, but could be worth it. π€·ββοΈ
29.11.2024 12:51
π 1
π 0
π¬ 0
π 0
Have not looked much into it, but I like the approach of www.facebook.com/whitehat/fbdl
At least for (most of the times) easy reproducible things like XSS.
I suppose in these cases you also do not give much IP out of hand that would enable anyone to automize your manual methodology. π
29.11.2024 12:47
π 1
π 0
π¬ 1
π 0
Got my #38c3 ticket, see you in Hamburg π
23.11.2024 10:35
π 5
π 0
π¬ 0
π 0
Dead Domain Discovery - Chrome Web Store
Scans the page for external iFrames, Scripts, and Styles, logs them to the console, and checks if their domains are resolvable.
The "Dead Domain Discovery" Extension is now available from Chrome Web Store:
π chromewebstore.google.com/detail/opfeo...
Keep in mind that the extension needs broad permissions to work. I'd recommend to only install it to your "research browser".
Github: github.com/lauritzh/dea...
21.11.2024 22:18
π 2
π 0
π¬ 0
π 0
The Flickr ATO using AWS Cognito recently turned "3" and it is still my favorite bug bounty story π
Check out the blog post in case you missed it: security.lauritz-holtmann.de/advisories/f...
H1 disclosure: hackerone.com/reports/1342...
15.11.2024 21:50
π 6
π 2
π¬ 0
π 0
#BurpSuite #Bambda to detect Blind SSRF via OpenID Connect "request_uri" using out-of-bound detection (e.g. Collaborator).
The vulnerable URL is b64-encoded and included within the canary URL.
π gist.github.com/lauritzh/7b3...
π security.lauritz-holtmann.de/post/sso-sec...
30.11.2023 23:37
π 2
π 0
π¬ 0
π 0