Sadra
559 posts

Sadra
@MrMSA16
18 y/o, Bug Hunter, Security Researcher

20 days ago I found a uXSS and reported, it got triaged now, I'll publish a blog post after fix and vendor permission, it's my first bug that I'm not happy with due to recent H1 situation 🖤


Can you spot the XSS vulnerability? 👀 Test it out live at: pwnbox.xyz


Combining two techniques I recently showed: attribute merging of <html>/<body> tags and using hidden=until-found to trigger onbeforematch via fragment navigation in Firefox. #xss" target="_blank" rel="nofollow noopener">storage.googleapis.com/nowaskyjr/poc_…
#xss


I’ve been hunting on H1 for almost 3 years, ranked #18 in 2025, have always tried to contribute positively to the hacker community. I’ve earned around $500k in bounties and was on the road to $1M. Yet I don’t even have HSM, and I feel I haven’t been recognized as I should 1/4


@Hacker0x01 is now banning people without explanation or providing how the terms and conditions were violated. While other platforms are advancing, H1 revolutionary new vision is to track hackers on social media, make assumptions and ban them without a real proof.

















