Mohamed Yusuf

671 posts

Mohamed Yusuf banner
Mohamed Yusuf

Mohamed Yusuf

@Edx103

Bug Bounty Hunter | Finding Bugs

Somalia Katılım Kasım 2020
2.3K Takip Edilen743 Takipçiler
Sabitlenmiş Tweet
Mohamed Yusuf
Mohamed Yusuf@Edx103·
After 4 months, 28 rejected reports, countless sleepless nights, and moments I almost gave up… Today, I finally got my first valid bug. One triaged report. One step closer to my dream. Bug bounty is hard, but giving up is harder. This is just the beginning. 🚀 #BugBounty
Mohamed Yusuf tweet media
English
50
14
319
16.6K
Mohamed Yusuf retweetledi
Rahmat Qurishi
Rahmat Qurishi@RahmatQurishi·
all easy bugs , just reading js files, copying endpoints, and throwing them into repeater😅
Rahmat Qurishi tweet media
English
10
21
428
12.3K
Mohamed Yusuf retweetledi
Eyad
Eyad@Eyax0·
My first payout $$$$ on @Bugcrowd 🖤
Eyad tweet media
English
28
2
328
8.7K
Mohamed Yusuf retweetledi
Vishal Vishwakarma
Vishal Vishwakarma@rootxvishal·
🔥 Ultimate IDOR Testing Checklist 🔥 📌 mrdesoky0.notion.site/Ultimate-IDOR-… IDOR is still one of the most impactful bugs in bug bounty. Many critical findings start by simply changing an ID in a request. 💡 This checklist covers: ✔️ ID & UUID manipulation ✔️ API & version bypasses ✔️ Multi-account testing ✔️ GraphQL & WebSocket ✔️ Race conditions & batch abuse ✔️ Mobile, gRPC & blind IDOR If you want high-impact bugs, don’t skip this. 🚀 #bugbountytips #bugbounty #infosec #cybersec
English
2
51
236
8.7K
Mohamed Yusuf retweetledi
Lagan Parihar
Lagan Parihar@lagan_parihar·
$600 bounty from a simple misconfiguration found during recon. Exposed database credentials ,company's internal zoom meetings and some kt sessions. #bugbounty #infosec
Lagan Parihar tweet media
English
3
1
83
1.5K
P4
P4@wearehackerone·
Test 50 endpoints Find NOTHING
English
9
2
45
4.1K
أسامة 🇵🇸
أسامة 🇵🇸@pent0ss·
مفيش احلى من إنك تنزل أجازة من الجيش تلاقى البونتى مستنياك 🤤😂 الحمد لله المنّان الوهاب ❤😍 First bounty at @Bugcrowd
أسامة 🇵🇸 tweet media
العربية
10
0
126
3.3K
yoyomiski
yoyomiski@yoyomiski·
Today triaged 4 bug > 2 bugs IDOR and LFI were found using AI. It discovered issues that I had previously missed during manual testing — really amazing 🥳🥳 > 2 bugs were found manually as usual Let’s keep pushing forward! #bugbounty #AI #IDOR #LFI
yoyomiski tweet media
English
9
9
273
13K
Mohamed Yusuf
Mohamed Yusuf@Edx103·
@Bugcrowd why does your triage teams to triage my submissions sometimes take about a week? My report has been waiting for triage even though the program lists an expected triage time ?
English
0
0
1
106
bugcrowd
bugcrowd@Bugcrowd·
Me when I see all the new bug bounty programs on Bugcrowd
bugcrowd tweet media
English
2
2
44
4K
Mohamed Yusuf
Mohamed Yusuf@Edx103·
How long does it usually take for the @Bugcrowd triage team to review a report? My submission has been in triage for about a week even though the program has an expected triage time. Is this normal? #bugbounty
English
2
0
0
496
Mohamed Yusuf
Mohamed Yusuf@Edx103·
It has been 1 month since my report was triaged by the @Bugcrowd triage team, but @intercom has not provided any response or taken any action on the submitted report. Hi intercom internal security team @intercom Could you please check the status and provide an update?
English
4
0
14
2.2K
root@AkashHamal0x01:~/ # 🇵🇭
root@AkashHamal0x01:~/ # 🇵🇭@AkashHamal0x01·
Hunting on Bugcrowd be like : - 1 week gaps between replies = late triage - No manual severity? Found a vulnerability that is P2 or P1 but impact is not in VRT category? congratulations you cannot select severity and now your report will take like 1 week to be seen
English
7
3
89
13.4K
Mohamed Yusuf retweetledi
Patrickbatman
Patrickbatman@hamidonsolo·
I made close to $10,000 from bug bounties this month. I'm 19. Still in engineering school. Here's what I didn't show you. I found a Critical RCE — Remote Code Execution via path traversal on a company's server. The kind of bug that pays $5,000-$20,000. Duplicate. Someone found it 12 days before me. $0. Same work. Same skill. Same report. Wrong timing. That's one of dozens. For every bounty I post, there are 15+ reports that got: → Duplicated → Marked informative → Ignored for months → Closed as "not applicable" → Lowballed after months of follow-ups But you know what I do when that happens? I wake up. No emotion. No hate. I open Burp Suite. Next target. Next report. Because if I don't, someone else will. Every day I take off is a day someone else dupes me on the next find. So I show up. Even when I don't feel like it. Even when it hurts. Bug bounty is not "find bug, get paid." It's find 50 bugs, fight for 6, get duped on some of your best work, get ghosted on others, and still show up the next morning. The $10K months are real. But behind every mountain is a hundred steps nobody sees. If you're starting out and getting duped and rejected — that IS the path. You're not doing it wrong. You're doing it. Keep going.
Patrickbatman tweet mediaPatrickbatman tweet media
English
40
53
797
54.3K
Mohamed Yusuf retweetledi
Patrickbatman
Patrickbatman@hamidonsolo·
Bug bounty tip most beginners don't know: Don't hack Google. Don't hack Apple. Don't hack Facebook. Start with small startups on HackerOne that have 0-5 hackers looking at them. Less competition = faster first bounty even public programs. I found my first bug in a program after 1 month full tiem Paid $2500. Next post: how to find YOUR bug type — the one thing you get so good at that money becomes inevitable subscribe to be alerted when it comes .
Patrickbatman tweet media
English
18
12
382
16.4K
Hugo Picanzo
Hugo Picanzo@hugopicanzo·
@Edx103 @Bugcrowd So fast! How much time between you reporting and that final answer? I’m starting to think that I have a bad taste when choosing programs
English
1
0
0
78