Posts

[Life Tip] Choose expensive really good quality product instead of a cheap so-so quality one

1. Recently, I bought a $1500 Apple Studio Display. I never think of buying a monitor this expensive before, it costs more than the computer I am using. 5 Years ago, I would think this is a stupid buy, and I buy for the brand, not for the value. But no, this monitor reduces my eyes tiredness significantly compares to my old monitor. This allows me to have 1 more hour of screen time, If I spend this 1 extra hour to bug hunting every day, I will earn $1500 back very soon. Then this purchase has a really good Return of Interest. It improves quality of life too. 2. Previously, I didn't pick a mattress myself, I slept on any bed my current place has. One of them was very rough, I had to wake up at night to change position, otherwise my blood can't flow. The other one was very soft, my back was tired even after a night sleep.  I just bought a $600 Kymdan mattress last week. I don't wake up at night anymore, for the whole week. This leads to more restful sleep, I have more energy ...

A Good Exercise to Learn Programming and Web Application Development

For any bug bounty hunters/hackers who think they should learn some web application programming and want to learn how to program. https://github.com/trieulieuf9/A-Web-App-from-Stratch

Be a security researcher, not a bug bounty hunter.

Image
  You can't control your result in bug bounty. Only effort. The word Hunter makes us feel like we need to find some bugs. Otherwise, we fail to be a hunter, our job is worthless, the process is just a mean to an end. If we think ourselves as bug hunters, we will have a lot of unnecessary thoughts, which leads to  unnecessary  stress, which leads to  unnecessary  burnout and procrastination. We have these unnecessary thoughts because we try to control the result, we think the more thoughts we put in it, the better we can control result. But in fact,  we can't control our result in bug bounty. Instead, be a security researcher. Who emphasis on the process, not the result. When testing a target, we learn how its security works, learn its features capacities, discover some quirks, and see if we can spot any security bug out of them. This leads to more enjoyment and less stress while hunting for bugs. With this small change in attitude and mindset, you will get ...

[Journaling][30-Aug-2024] The Universe do listen to what you say

  https://www.youtube.com/watch?v=GoW8Tf7hTGA I just watch this video again. Maybe the 10th times. This time, I realize that there is something that connect everything else, people are pulled toward center on the Earth. All planets in the Solar System are pulled toward center of its center. The Solar System and many of its equivalents get pulled toward the center of a galaxy. Many galaxies are connected to form a supercluster of galaxies, at this point, we can't even see what is in the center that power all these galaxy-connections. The whole universe now looks very much like a living being. Each person is a cell of this GIGANTIC being. There is a rule in the universe, that's everything is available in abundance. When creatures on Earth need energy, the sun provides 100 times of what is needed. When these creatures need water, they are provided with rivers and rains. When they need air, there are so much air they take them for granted for the rest of their life. The Earth is va...

[Journaling] [05-Jul-2024] Just a little bit of time spend consciously can make a huge different

Image
Note : this is a journal. Me talks to myself. I think this is a good one, so I properly format it and post here. Yesterday, I spent around 7 minutes sky-gazing, I felt grounded, my mind is clear after that. Today, after I finish testing a small feature, I am about to switch to another feature. But I stop and brainstorm for 5 minutes for new ideas to test on this feature. And I indeed get some good ideas. I just realize that just a little bit of time spent consciously can make a noticeable impact. That's how generous life is to us. Life gives human 16 waking hours (960 minutes) everyday and we only need to spend 7 minutes to feel grounded, calm, clear. 30 minutes to exercise for a good health. And the rest is up to us to use. People who usually complain about not having enough time must have shove their heads in a lot of entertainment. Entertainment, on the other hand, is a counter-life activity. Because we usually spend a lot of time on it and feel foggy, lethargy afterward. We spe...

Bug hunter's search for meaning in Low/Medium bugs.

Image
Three years ago, I started to find bugs more often. 95% of my bugs were low/medium. Although bounties were nice, I often wondered if my reports have any impact on the security of companies I submitted to. If my reports were useful to developers, security teams, or they were a waste of time, and bug bounty programs have to accept low/medium just to comply with bug bounty community standard, but what they really want are high/crit reports. I felt unease, while writing a new report for a low bug. I often thought If this report was really needed, or it was a waste of time for program staffs and everyone involved. Of course, the bounties were still larger than these doubts. So I reported. I tried to answer these doubts many times, some answers I had come up with are: Many of my low bugs are fixed, that means developers care about these bugs. Otherwise, they can just leave them in backlog for years. They have option to not pay for low bugs at all, but they pay, that means these reports have ...

Avoid burning out

Image
- Taking some weeks or months off always help. After months of doing bug bounty, you usually develop liking to something other than bug bounty. This is a good time to do it. Try to train like a pro-gamer in a game you like for a month is also a good option. - If you are burning out, there is a good chance that you are having many items in your bug bounty todo list. Just creates a file call archive.txt and move all these items to this and move this field to the deepest place in your computer. It will light up your head instantly. - Realize that there is no must-do, have-to-do, ought-to-do, should-do things in bug bounty (in life as well). You do them because they feel right for you, because they are interesting to you. And if they are not feel right for you, you don't need to do them. The worst that can happen is you lose some bounties. But you just save yourself from a lot of stress and burning-out. If you stick to this principle, your mind is clear and light. Hunting bugs with thi...