Shuvonsec

416 posts

Shuvonsec banner
Shuvonsec

Shuvonsec

@shuvonsec

Security Researcher. Ethical Hacker. Application Developer | World's #1 Monthly Top Ranked on TryHackMe

Meme coin Katılım Eylül 2022
2.4K Takip Edilen541 Takipçiler
Sabitlenmiş Tweet
Shuvonsec
Shuvonsec@shuvonsec·
if you’re new here, let me introduce myself. i’m Shuvon aka (Shuvonse). i break into systems legally and get paid for it. i hacked NASA ethically when i was 17. they sent me an official appreciation letter for it. that story got picked up by The Daily Star, The Peninsula Qatar, The Daily Warriors, and other international outlets. my university did a full spotlight on it too. since then i’ve found bugs in Google, Meta, Amazon, Sony, and 50+ other companies through HackerOne and Bugcrowd. I ranked #1 global on TryHackMe. i also build things. claude-bug-bounty an open source AI bug hunting tool. 1.7k stars, 298 forks on github. founder of @AwareXone , a safety and trust infrastructure company based in Malaysia. on the side, i build websites for meme coins and crypto projects. most ship in under 24 hours. you’re getting a builder who actually understands security, not just frontend. dm me or join t.me/shuvonsec.
English
10
3
20
3.4K
Shuvonsec
Shuvonsec@shuvonsec·
that empty part at the beginning? that's me. years of wanting to build something real. having the ideas. telling myself i'd start when i felt ready. i never felt ready. so one day i just stopped waiting and built claude-bug-bounty. every green square after that is a day i showed up anyway. 749 of them. not because i was always motivated. because i decided this thing was worth more than my excuses. --- here's what shipped today. 5 pull requests. merged from people i've never met, never spoken to. just builders who found the tool, used it, and made it better. that's the part nobody talks about when they say "open source." it's not just code. it's strangers trusting your work enough to improve it. here's what they built: -> the tool used to only accept domains. now it takes single IPs and full network ranges too. one change that opens up a whole different category. internal pentests, private programs, corporate networks. huge. -> reports used to be plain markdown. now they look like a real pentest firm delivered them. dark mode, cover page, risk bars, CVSS scores, PoC evidence. the kind of report that makes a program actually take you seriously. -> MFA bypass and SAML checks, automated. SAML signature stripping alone is a critical account takeover path. testing this used to take hours. now seconds. -> CVSS 4.0 scoring. programs are already requiring it on submissions. we were still on 3.1. fixed. -> 6 real bugs gone. one was marking SQLi as MEDIUM severity. SQLi is CRITICAL. that's not a cosmetic bug. that's bounty money left on the table. fixed. --- community caught two issues the same day they were reported. /resume was colliding with claude code's built-in command and silently breaking sessions for everyone. renamed to /pickup. fixed same day. one tester spent hours with the tool and came back with 6 improvement ideas. session isolation, multi-target support, token optimization, smarter prompts, chrome MCP, source code mode. all of them shipped. --- i'm building the best AI agent for bug bounty hunting that exists. not because it's the most popular thing to build. because it's the thing i actually needed and nobody had built it right. 749 days in. still going. the empty squares at the start were the most honest part of the whole chart. that's where most people stay. the green ones are just what happens when you stop waiting.
Shuvonsec tweet media
English
8
5
21
741
Shuvonsec
Shuvonsec@shuvonsec·
note 3: one contributor found 6 real bugs while testing and fixed all of them. 1. tool was leaving processes running in background after finishing. fixed. 2. whole thing was broken on mac. fixed. 3. SQLi was showing MEDIUM severity. SQLi is CRITICAL. real bounty money was wrong. fixed. 4. same url getting scanned multiple times. waste of time. fixed. 5. one bad return was crashing the entire scan early. fixed. didn't ask for permission. just found problems and fixed them.
Shuvonsec tweet media
English
0
0
1
58
Shuvonsec
Shuvonsec@shuvonsec·
note 2: pull requests = someone built something and asked me to add it to the project. 1. 16 closed = 16 improvements reviewed and shipped 2. contributors = real people i never met who showed up and built anyway 3. merged = i approved it, now it lives in the tool forever 4. this is how open source works. strangers just show up and make it better.
Shuvonsec tweet media
English
0
0
1
54
Shuvonsec
Shuvonsec@shuvonsec·
this is how open source grows. strangers show up, do real work, and make the thing better. i just have to be worth showing up for.
Shuvonsec@shuvonsec

that empty part at the beginning? that's me. years of wanting to build something real. having the ideas. telling myself i'd start when i felt ready. i never felt ready. so one day i just stopped waiting and built claude-bug-bounty. every green square after that is a day i showed up anyway. 749 of them. not because i was always motivated. because i decided this thing was worth more than my excuses. --- here's what shipped today. 5 pull requests. merged from people i've never met, never spoken to. just builders who found the tool, used it, and made it better. that's the part nobody talks about when they say "open source." it's not just code. it's strangers trusting your work enough to improve it. here's what they built: -> the tool used to only accept domains. now it takes single IPs and full network ranges too. one change that opens up a whole different category. internal pentests, private programs, corporate networks. huge. -> reports used to be plain markdown. now they look like a real pentest firm delivered them. dark mode, cover page, risk bars, CVSS scores, PoC evidence. the kind of report that makes a program actually take you seriously. -> MFA bypass and SAML checks, automated. SAML signature stripping alone is a critical account takeover path. testing this used to take hours. now seconds. -> CVSS 4.0 scoring. programs are already requiring it on submissions. we were still on 3.1. fixed. -> 6 real bugs gone. one was marking SQLi as MEDIUM severity. SQLi is CRITICAL. that's not a cosmetic bug. that's bounty money left on the table. fixed. --- community caught two issues the same day they were reported. /resume was colliding with claude code's built-in command and silently breaking sessions for everyone. renamed to /pickup. fixed same day. one tester spent hours with the tool and came back with 6 improvement ideas. session isolation, multi-target support, token optimization, smarter prompts, chrome MCP, source code mode. all of them shipped. --- i'm building the best AI agent for bug bounty hunting that exists. not because it's the most popular thing to build. because it's the thing i actually needed and nobody had built it right. 749 days in. still going. the empty squares at the start were the most honest part of the whole chart. that's where most people stay. the green ones are just what happens when you stop waiting.

English
4
2
13
350
Shuvonsec
Shuvonsec@shuvonsec·
note 1: (for people who don't know what this means) github is where builders put their code for others to see and use. these numbers are the score. 1. stars (1.8k) = 1,800 people said "this is good" 2. forks (301) = 301 people copied it to build on top of it 3. watching (10) = people who get notified every single update i didn't buy any of this. i just kept building.
Shuvonsec tweet media
English
0
0
2
66
Shuvonsec
Shuvonsec@shuvonsec·
@OnlyTerp Getting better every day. Respect. If you’re into real-world bug hunting, check this: github.com/shuvonsec/clau… Practical bug bounty workflows and real attack paths. Contribute if you’re serious.
English
0
0
3
30
Terp
Terp@OnlyTerp·
Getting better everyday at creating githubs to help people. I love contributing :)
Terp tweet media
English
5
3
28
779
Shuvonsec
Shuvonsec@shuvonsec·
seeing more people star and use the tool every day, it is growing naturally i am getting addicted to building this, going deeper every day this is long term for me, i will keep shipping consistently....
English
5
3
12
305
Shuvonsec
Shuvonsec@shuvonsec·
@OnlyTerp I'm building Claude bud bounty is AI product
English
0
0
2
63
Shuvonsec
Shuvonsec@shuvonsec·
$BUG forever.
Shuvonsec tweet media
English
0
0
17
362
Shuvonsec
Shuvonsec@shuvonsec·
$BUG forever.
Shuvonsec tweet media
English
1
2
15
742
SD
SD@capitalist_sd·
Aped $SIGMOID as LongTerm Hold. But Why? - $SIGMOID is the first ever Precision Market Launchpad, with Riskr Conviction system where one can lock their collateral to prove their conviction (Never before globally). - @solana is slowly turning into Hub for AI, Prediction Market and Solana ecosystem enhancing projects. $Sigmoid falls as one of the best Prediction Market projects launched on Solana till date. - Currently its on testnet phase. I tried with Paper trades- yes. It is fully operational and works as it is claimed. (Advanced Prediction Trading truly) - Tried to Compare with $RALLY, $ISO and $SIGMOD.. Though all 3 projects are technically strong and leading as Top3 Prediction based projects/ infra on @solana, $SIGMOID stands out to be the best to me for a major reason--> Strong winner towards UX for both creators and traders, through its launchpad for precision markets. Will $SIGMOID be a competitor to @Polymarket and @Kalshi in coming months? or will Polymarket or Kalysi endorse and integrate all that $SIGMOID does as first mover now. Either way, $SIGMOID as the intrinsic value of @SigmoidMarkets should be at 50Mill+ MC in coming months. Dyor. Very Early!! 98oXBs8bwb5b7L2k8thZDr3S2ub4H5vDNjLm7uvpump
SD tweet mediaSD tweet mediaSD tweet mediaSD tweet media
Alpha Seeker@AlphaSeeker21

Prediction Markets are one of the strongest narratives on Solana right now. We’ve already seen multiple plays in the sector run hard and that’s not random. It’s one of the few areas in crypto with clear product-market fit. $SIGMOID @SigmoidMarkets is starting to carve out its own lane in the space. Sub $70K MC is real alpha. Feels similar to $RALLY back when it was sub $100K MC. 98oXBs8bwb5b7L2k8thZDr3S2ub4H5vDNjLm7uvpump

English
4
7
20
2.6K
Terp
Terp@OnlyTerp·
Nvm testing in the big surf
English
1
0
2
186
Shuvonsec
Shuvonsec@shuvonsec·
Thanks meme coin.
Shuvonsec tweet media
English
3
2
15
901