123┌▄──────────────────────────────────────────────────────────────────────▄┐4├■▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀■[ YESWEHACK PROPHILE ON S5S ]■▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄ ┤5├■──────────────────────────────────────────────────────────────────────■┤6├■▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀▄▀■┤7└▀──────────────────────────────────────────────────────────────────────▀┘823th of April, 2021.9╔══════════════════════════════════ WHOIS ═══════════════════════════════╗10║ Handle: saber ║11║ AKA: s5s ║12║ Age of your body: 28 ║13║ Produced in: China ║14║ Urlz: http://sbim.github.io/ ║15║ Computers: MacBook Pro (16-inch, 2019) ║16║ Active Since: 2020 ║17║ Superpowers: sleep ║18║ Life in a sentence: Good good study, day day up ║19╚════════════════════════════════════════════════════════════════════════╝2021 QUOTES22╔════════════════════════════════════════════════════════════════════════╗23║ One of the worst traps to fall into is dooming a great idea ║24║ by assuming it won't works and not trying it ║25╚════════════════════════════════════════════════════════════════════════╝2627 ARMORY28╔════════════════════════════════════════════════════════════════════════╗29║ Burp Suite and BApps ║30╚════════════════════════════════════════════════════════════════════════╝313233▀▄█▓▒░ Hello, how are you ?34│ ─────────────────────────────────────────────────────────────────────────35└─ I'm fine. Thank you, and you?363738▀▄█▓▒░ Do you remember your first contact with a computer ?39│ ─────────────────────────────────────────────────────────────────────────40└─ When I was 8 years old, I started to contact with a computer. During41the next years, I become a computer lover because of some interesting42computer games:)434445▀▄█▓▒░ Can you relate your first successful exploitation/abuse of a system ?46│ ─────────────────────────────────────────────────────────────────────────47└─ At college I found a hidden endpoints and an idor issue that would leak48all students private information. At the time I din't know anything about49hacking but it was a wonderful experience505152▀▄█▓▒░ What moment pushed you in the pro computer security whirlpool ?53│ ─────────────────────────────────────────────────────────────────────────54└─ Every time a bug was triaged or accepted.555657▀▄█▓▒░ Memorable people or readings you care to share about ?58│ ─────────────────────────────────────────────────────────────────────────59└─ The most memorable people is @albinowax, his writeups are really helpful.60Also @PentesterLand who collect many bug bounty information.616263▀▄█▓▒░ What will you learn next ?64│ ─────────────────────────────────────────────────────────────────────────65└─ Improve my recon strategy and code review skill.6667For recognition, I don't have a precise plan, I could only do things that68I didn't do or lazy to do before. Maybe I'll try more recon steps like vhost69scan, wayback machine data gathering, shodan dork...etc.7071For code review, I have a plan that reads some of the high/critical reports72at https://gitlab.com/groups/gitlab-org/-/issues?scope=all&utf8=%E2%9C%9373&state=closed&label_name[]=HackerOne,74since Gitlab is open-source I can check the code to know where the75vulnerability happens. I believe such a process will improve my code review76skill.777879▀▄█▓▒░ Three most important rules you would write in a Bug Hunter Manifesto?80│ ─────────────────────────────────────────────────────────────────────────81└─ 1. Learn 2. Practice 3. Persistent8283Learn and Practice. Continuous learning is very important. 2 years ago when84I first start to learn about web hacking, I found Jams Kettle's wonderful85writeup about Desync attacks by coincidence. I spend some time understanding86the writeup and the tool. Then I try this exploit on bug bounty programs and87result in many valid reports. That was also my first critical findings. It's88a very amazing experience, a new attack surface appeared, As a starter I89learned it and practiced it, then result in some valid findings9091Persistent. To be honest, I'm not a persistent-pro, but doing bug hunting92is just a process that you failed 99 times and then succeed in the next 1.93You won't know which try will give you a successful exploit. Also persistence94will lead you to go deeper and deeper to a program. That's why it's very95important. Also you will know why many great hunters will talk about96**mental-health**, keep good and positive mental health will ensure97your persistence.9899100▀▄█▓▒░ You are active on YesWeHack and have practiced others BB platforms,101| What are your Do/Don't?102| What are your expectations ?103│ ─────────────────────────────────────────────────────────────────────────104└─ == Do/Don't: ==105- Read the program's policy carefully before start the hunt. Don't submit106bugs that are out of scope. If a bug's final decision is not go your way,107Just hunt your next one.108109== Expectations: ==110- I hope the platforms will allow hackers to rate and leave comments on111certain programs, build a point/reputation system on the program side.112113114115▀▄█▓▒░ What advice can you give to someone who wants to start in116│ bug bounty?117│ ─────────────────────────────────────────────────────────────────────────118└─ Read as much as possbile. Start with a program you use a lot or you are119familiar with, this may make your first bug easier.120121Everything is hard in the beginning. My personal experience is that hunt on122a program you use a lot will make it easier because you will notice the point123that others won't. Another piece of advice is that you should focus on one124program instead of going through different programs randomly. It could be125hard to find the first valid bug, lots of hunters will experience a few126duplicates/NAs when they join the bug hunting community. But remember it's127also a process of learning. Read as much stuff as you can, think about how128others hunt and how they write reports.129130131▀▄█▓▒░ Is there a life AFK ?132│ ─────────────────────────────────────────────────────────────────────────133└─ Yes of course. Sometimes duplicates or long time no response will make134people feel upset. I'll have a short AFK time.135136137▀▄█▓▒░ How do you see the future ?138│ ─────────────────────────────────────────────────────────────────────────139└─ More programs will appear and more hunters will join. Also more attack140surface will be discovered by these talents.141142--------[ EOF143144

YESWEHACK PROPHILE ON S5S
May 4, 2021


