Ajay Yadav

49 posts

Ajay Yadav

Ajay Yadav

@smart_hacker__

Joined Kasım 2023
90 Following2 Followers
Vipul 🇮🇳
Vipul 🇮🇳@GodSpeed000123·
11 bugs. One target. $40,000. Critical infra leak. ATO. SSRF x2. OAuth bypass. DoS. Sometimes one target is all you need. #BugBounty
English
20
17
398
12.6K
Ajay Yadav retweeted
Modern Dad
Modern Dad@ModernxDad·
Only Men can understand this feeling ❤️🥺
English
20
115
1.2K
48.2K
Ajay Yadav retweeted
N G U R I
N G U R I@Nguri__·
🇮🇳 Un livreur indien croise une ancienne camarade. Elle le filme en se moquant : « Toi qui motivais tout le monde à l’école te voilà livreur de pizzas je vais envoyer la vidéo à nos amis » pendant qu’il sourit en cachant sa douleur.
Français
162
163
3.8K
1.4M
Ajay Yadav retweeted
0xaudron
0xaudron@0xaudron·
Anthropic on its way to solve “security problem” with Mythos. Meanwhile, their own bug stats. You can check their program on hackerone:
0xaudron tweet media
English
4
12
151
11.6K
Ajay Yadav
Ajay Yadav@smart_hacker__·
@7h3h4ckv157 I've read all these books 4–5 times: The Web Application Hacker’s Handbook Bug Bounty Bootcamp Real-World Bug Hunting Web Hacking Arsenal Solved 80% of portswigger lab
English
0
0
0
22
Ajay Yadav
Ajay Yadav@smart_hacker__·
@7h3h4ckv157 Bro,I started learning bug hunting in Oct 2022. By the time I was ready to hunt seriously, Claude AI changed everything. I invested 4–5 years but got nothing — not even a single bounty, all my H1 reports were marked informational. Should I continue or switch to another field?
English
1
0
0
24
7h3h4ckv157
7h3h4ckv157@7h3h4ckv157·
Manifesting 🤞🏻❤️
7h3h4ckv157 tweet media
English
48
164
2K
105.1K
Ajay Yadav
Ajay Yadav@smart_hacker__·
@hamidonsolo I started hacking in 2022 & read all these books 4-5 times The WebApplication Hackers Handbook Bug Bounty Bootcamp RealWorld Bug Hunting Web Hacking Arsenal Solved 80% of portswigger lab and got $0 from bounty yet. But Bro You motivated me to start my bug bounty journey again.
English
0
0
3
203
Ajay Yadav
Ajay Yadav@smart_hacker__·
@a13h1_ Bro What do you think about claude ai that automate vunerabilty checking in source code and automate bug hunting.
English
0
0
0
30
Abhi Sharma 𝕏
Abhi Sharma 𝕏@a13h1_·
Lets go for bug hunting here😁
Abhi Sharma 𝕏 tweet media
English
1
0
6
374
7h3h4ckv157
7h3h4ckv157@7h3h4ckv157·
Tell me… What’s next?!
7h3h4ckv157 tweet media
English
2
0
4
827
7h3h4ckv157
7h3h4ckv157@7h3h4ckv157·
Recently I identified and responsibly reported a vulnerability in Grok (xAI) via H1. 2 crafted prompt allows the attacker controlled code can be rendered through the AI output, enabling scenarios such as phishing link injection, UI manipulation, and visual defacement since the CSS overlays including fullscreen interface takeover by wiping chatbox too. Grok conversations can be publicly shared, injected interface could potentially be distributed externally with deceptive or phishing content appearing as legitimate platform output (Publicly accessible). The report was marked as a duplicate as another researcher had already reported the issue. Still, it was an interesting exercise in exploring how AI can be hacked.
7h3h4ckv157 tweet media7h3h4ckv157 tweet media
English
8
3
57
6.4K
Coffin
Coffin@lostsec_·
Which video + article should I drop next? 1️⃣ Google API Key Mass Hunting & Exploitation for Bug $$Bounties Finding exposed keys at scale and turning them into real bounty-worthy impact. 2️⃣ Dependency Confusion Attacks: Zero to Hero Understanding the attack, setting up the lab, and exploiting it in real-world scenarios.
English
76
9
217
19.1K
Ajay Yadav
Ajay Yadav@smart_hacker__·
@tabaahi_ Bro what happened to you. Why are you not hunting for bugs since few months.?
English
0
0
0
2
Mohsin Khan
Mohsin Khan@tabaahi_·
@hetmehtaa 18hours of thinking & Doing nothing, Me Before going to sleep..... i am whatever he said 😂
English
1
0
1
183
Het Mehta
Het Mehta@hetmehtaa·
Why am I unable to understand this high level language?
Het Mehta tweet media
English
5
0
13
1.6K
Ajay Yadav
Ajay Yadav@smart_hacker__·
@7h3h4ckv157 Bro anyway to bypass cloudflare waf for react2shell please..
English
2
0
3
399
7h3h4ckv157
7h3h4ckv157@7h3h4ckv157·
- I understand that running react2shell-ultimate[.]py against random websites isn't research. - I understand that "I removed the identifying info" doesn't undo the unauthorized access. - I understand that #BugBounty doesn't apply when there's no bounty program. - I understand that finding my site on Shodan doesn't constitute authorization. Well said @gothburz !! 👏
Peter Girnus 🦅@gothburz

Someone found an RCE on my website yesterday. CVE-2025-55182. React2Shell. I don't have a bug bounty program. I never asked for a security assessment. I woke up to a DM: "Hey I found a critical vulnerability in your site. I only ran the exploit to verify it worked. Here's my PayPal for the bounty." Bounty? I checked my logs. Forty-seven requests to my RSC endpoint. Something, something ... Prototype pollution payloads. They used the GitHub script. The one with 2,000 stars. The one that runs id automatically "for verification purposes." They spawned a shell on my production server. uid=1001(nextjs) gid=65533(nogroup) They took a screenshot. They posted it on Twitter. "Popped a Shell on a Live Website 🚀💀 #BugBounty #CVE-2025-55182 #YOLO" They got 84781 likes. My customers' data was on that server. I asked them to delete the screenshots. They said "I removed the domain name, you should be thanking me." Thanking them. For unauthorized access to my production infrastructure. For running arbitrary commands on systems I own. For posting proof of exploitation for clout. They called it "responsible disclosure." I called my lawyer. They called me "ungrateful." I called the FBI. Now they're in my DMs explaining that "this is how the industry works" and I "don't understand pen testing." A pen what? I understand it perfectly. I understand that running react2shell-ultimate.py against random websites isn't research. I understand that "I removed the identifying info" doesn't undo the unauthorized access. I understand that #BugBounty doesn't apply when there's no bounty program. I understand that finding my site on Shodan doesn't constitute authorization. Their followers are defending them now. "Presumption of innocence." "You don't know if it was authorized." "The screenshots were redacted." Three hundred people are calling me a bootlicker for reporting a crime. Someone said I should be grateful they didn't deploy a cryptominer. The bar is underground. I just wanted to run a small Next.js app. I didn't ask to be someone's proof-of-concept. I didn't consent to being their "first" I didn't sign up for an unscheduled penetration test from a stranger with a GitHub account. There is no safe harbor for spraying public exploits at random websites. There is no legal protection for "I was just verifying the vulnerability." There is no ethical framework where unauthorized prototype pollution is a favor. But sure. Thank you for your service. You found a CVE that was already public. Using a tool someone else wrote. Against a target that never authorized you. And you posted about it on main. For likes. Hero.

English
2
0
35
7.1K
Ajay Yadav
Ajay Yadav@smart_hacker__·
@sudo_a7med Bro How many bug did you reported till and How many accepted?
English
1
0
0
61
sudo
sudo@sudo_a7med·
دا الواحد كان بدأ ينسي بيكتب ريبورت ازاي
sudo tweet media
العربية
10
0
66
14.1K
Ajay Yadav
Ajay Yadav@smart_hacker__·
@sudo_a7med Bro Have you not found any bug whitin 90 days?
English
1
0
0
70
sudo
sudo@sudo_a7med·
#day_89 of trying to get my first bounty 🔎 hunting: 2 h 📚 studying: 0 h 🐞 bugs reported: 0 💻 One hour studying js: ❌
English
2
0
12
840
Gospel
Gospel@4osp3l·
Our first CRITICAL on @yeswehack with @d3q0w & @amsubedi2; got access to critical user's PII including emails, passwords, secrets.. e.t.c
Gospel tweet media
English
20
17
303
12.3K
Vipul 🇮🇳
Vipul 🇮🇳@GodSpeed000123·
Found a critical vulnerability by poisoning the password-reset flow by injecting Collaborator into headers using Burp FakeIP, resulting in account takeover. Scored $4,000 Tip: Use the FakeIP extension to check for link poisoning. #BugBounty #bugbountytips #CyberSecurity
Vipul 🇮🇳 tweet media
English
15
38
536
33.7K