Ares47
42 posts

Ares47 retweetledi

Add `/faketoken` to your wordlist
While fuzzing API endpoints, found a dev-only debug route "faketoken" left exposed in production. It returns a valid JWT for any registered user, just by supplying their mobile number (no auth, no OTP) - 0 Click ATO.
#Bugbountytips

English
Ares47 retweetledi

TL;DR - I discussed how I got started in cyber security and my initial struggles as well as my motivation to become a bug bounty hunter and my goal to ultimately become an offensive security researcher.
cqawam.github.io/posts/Becoming…
English

@ReebootToInit5 Mind blowing bro what's your hunting methodology how do you approach a target 🎯 can you permit me to send you DMs too thx bro.
English
Ares47 retweetledi

Day 203/365 of the Until get 10.0 Critical report
📤 Reports Submitted:- 0
🟠 triaged - 3
🟦 program review - 0
🟤 Duplicate - 0
🟣 New - 2
⚪️ Info - 0
💰 Paid - $3487
💻 Worked- 7 HOUR
#BugBounty
English

@krishnsec Really inspiring how do you hunt, what's your methodology how do you approach wild card target and main apps?
English

Give these a try!
Vishal Vishwakarma@rootxvishal
Built 2 free browser-based recon tools for bug bounty 🛠️ No install, no API keys, nothing logged. 🔍 Subdomain enum → recon.rootxvishal.com 🕸️ Passive URL crawler → crawler.rootxvishal.com Open a tab, type a domain, go. Authorized recon only free sources, so a source may rate-limit/block occasionally. #BugBounty #Recon #OffensiveSecurity #InfoSec #CyberSecurity #OSINT #PenetrationTesting #AppSec #bugbountytips
English
Ares47 retweetledi

I just found out that some AI-generated "hacking" blogs are using my name, claiming that I'm making statements I've never made. This is weird...
undercodetesting.com/ethical-hacker…

English
Ares47 retweetledi

@AresForty7 @Bugcrowd I just saw your message and have already replied. Feel free to reach out anytime. I'm always happy to connect and share experiences with fellow hunters 😊
English

Just hit a small milestone on @Bugcrowd
I crossed 2,000 reputation points.
Looking forward to finding more bugs and continuing the journey 🚀
#BugBounty #Bugcrowd #Cybersecurity #EthicalHacking

English

@Eyax0 @cantinasecurity Hi am interested to learn from you what's your hunting methodology? permit me to DM you
English

@hackerspider1 Permit me to send you DMs would like to learn from you what's your hunting methodology?
English

Started bug bounty in February.
I started bugbounty to learn new things, stay sharp, buying a new house, and keep improving. Most of these findings came from weekends, late nights, and a lot of curiosity.
A few months later: $50,000+ earned in bug bounties while working a full-time job.
Combined with @HarshDRanjan1, we’ve crossed $100,000+.
Proof that a few focused hours each weekend can compound into something much bigger.
Still hunting.
#BugBounty #HackerOne #CyberSecurity #EthicalHacking
English
Ares47 retweetledi

Bug Bounty Complete Course!
Learn Bug Bounty to identify and report System vulnerabilities before cybercriminals exploit them.
A Udemy Complete Course.
Download Link:
drive.google.com/drive/folders/…
For more valuable resources and Insights Follow @ZabihullahAtal
DM me for Collaboration.

English

I just published a full write-up about how I discovered a Critical PII leak using google dorking and fuzzing
in a private bug bounty program in bugcrowd .
@mrx_w_/how-i-discovered-23-000-leaked-records-through-google-dorking-7894df815109" target="_blank" rel="nofollow noopener">medium.com/@mrx_w_/how-i-…
#BugBounty #BugBountyTips #Bugcrowd #CyberSecurity
@Bugcrowd

English














