manuel valdez
banner
saur1n.bsky.social
manuel valdez
@saur1n.bsky.social
▪️Hacking my way through life
▪️Part time Bug Bounty hunter
▪️Engineer
▪️Teacher
▪️x.com/saur1n
It's just like that sometimes
May 29, 2025 at 12:15 PM
May 25, 2025 at 11:49 PM
Swag's here! As part of an active campaign from 12build program run by @intigriti.com, I managed to find a few cool bugs. Great program, good quality💯 t-shirts

#bugbountytips
May 23, 2025 at 1:11 AM
Part 8:
May 5, 2025 at 1:09 AM
Part 7:
May 2, 2025 at 8:13 PM
Part 6:
May 1, 2025 at 5:07 AM
Part 5:
April 29, 2025 at 12:38 PM
Part 4:
April 28, 2025 at 7:25 PM
Part 3:
April 26, 2025 at 12:17 PM
Os Inception
April 26, 2025 at 2:39 AM
Part 2:
April 25, 2025 at 12:02 AM
I'm starting a new series called: Weird SSRF outputs
April 24, 2025 at 3:10 AM
March 28, 2025 at 3:17 PM
This is the bad thing about sharing testing environments. This guy has been hammering an HTMLi on a invitation email request for three days now, which I'm 99.9% sure has been reported before **several times**.
March 28, 2025 at 3:14 PM
I feel sorry for triagers seeing this type of... Thing on bug bounty reports
March 13, 2025 at 1:16 AM
The entire model handed to you
February 26, 2025 at 3:00 AM
📷
February 21, 2025 at 4:33 PM
Decompressing
February 20, 2025 at 10:11 PM
To wrap it up:
- Uncheck that option
- Add Scope items only to the Interception filters and Ignore OPTIONS requests, to keep the history a bit cleaner.
February 7, 2025 at 3:52 PM
I guess this is well known by experienced WebApp pentesters/bug hunters/Burp Suite power-users, so this is targeting beginner users.

While loading the Burp Suite extension Autorize, it has by default this box checked:
1/n
February 7, 2025 at 3:52 PM
Stored XSS is cewl but have you heard about a store full of XSS's? 🙄
February 7, 2025 at 12:28 PM