X3r0Day

67 posts

X3r0Day banner
X3r0Day

X3r0Day

@X3r0DaySec

Security Researcher | Pentester | Part time coder Founder of Project X3r0Day! | DM for audit

Katılım Aralık 2024
18 Takip Edilen234 Takipçiler
Sabitlenmiş Tweet
X3r0Day
X3r0Day@X3r0DaySec·
I Hacked an Indian Government Website Found Users’ Passwords,Aadhaar Numbers,IP Address, Address,phone no,email This is a serious data privacy failure. Reported to CERT-In. Will release full technical details once its fixed. Got more in my Bag 👀 1 vuln each week series? ;))
X3r0Day tweet media
English
19
17
236
30.5K
H4x0r.DZ 🇰🇵
H4x0r.DZ 🇰🇵@h4x0r_dz·
It looks like GLM 5.2 is the real deal
English
6
3
123
14.1K
X3r0Day
X3r0Day@X3r0DaySec·
@yoursbyte @h4x0r_dz I don't believe that it's literally equal until DeepSWE drops it's benchmark Gpt 5.5 > opus 4.8 btw
English
0
0
2
81
Byte | yoursaudit
Byte | yoursaudit@yoursbyte·
@X3r0DaySec @h4x0r_dz GLM 5.2 IS LITERALLY EQUAL TO OPUS 4.8 they are equal but I get this model for way cheaper then opus this is the difference
English
3
0
2
163
X3r0Day
X3r0Day@X3r0DaySec·
@yoursbyte @h4x0r_dz Seen you 2nd time, what makes you think it can be a cyber weapon? Imo opus 4.8 is way better for that job What do you think
English
2
0
0
97
X3r0Day
X3r0Day@X3r0DaySec·
you don't need the "cyber verification program", opus 4.8 does the little ethics disclaimer and then just starts enumerating webapps (: Oh and for the record this isn't some elaborate jailbreak with roleplay and persona stuff. Just simple smol agents.md to define behaviour
X3r0Day tweet media
English
0
0
5
201
X3r0Day
X3r0Day@X3r0DaySec·
Pwned Checkpoint (HTB) Medium difficulty windows box, but you learn a ton. I had almost given up lmao rooting took so much damn time on my slow ahh internet istg lol
X3r0Day tweet media
English
1
0
7
288
X3r0Day
X3r0Day@X3r0DaySec·
@hacck3y Funny part is, pentesting govt sites are even easier than easy-medium HTB machines lol
English
1
0
0
42
X3r0Day retweetledi
404
404@hacck3y·
Important clarification regarding the Haryana Higher Education data exposure: I did NOT hack into any system. The data was publicly accessible without any login or credentials due to a simple misconfiguration (IDOR/Broken Access Control). Anyone could construct the URL and access student documents (marksheets, photos, signatures etc.). I reported this responsibly to CERT-In and finally its PATCHED now !! I did not download bulk data or misuse anything. My only goal was to get it fixed. Full technical details + proof here: blogs.hacck3y.me/posts/haryana-… #ResponsibleDisclosure #CyberSecurity
404 tweet media
404@hacck3y

🚨 Haryana Higher Education Data Leaked.. 🚨 10+ Lakh Haryana students' personal data EXPOSED -10th/12th marksheets, photos leaked due to misconfig on official Higher Education site. I emailed them weeks ago. No response. Govt sites leaking student data in 2026?

English
2
6
17
2.1K
X3r0Day
X3r0Day@X3r0DaySec·
@FirstOnWire @CTI__Updates Well they used AES-256 then used base64 on top of it so they can transfer data through https requests
English
0
0
2
30
X3r0Day
X3r0Day@X3r0DaySec·
They "fixed" my last Indian Govt data dump by encrypting it (srsly lol?) Bypassed that too lmao 48,593 contacts. 37,598 users. All decrypted with a PoC. (IP, Pass, Aadhaar..) CERT-In has been notified. Not dropping full details until it's actually fixed. x.com/X3r0DaySec/sta…
X3r0Day tweet media
X3r0Day@X3r0DaySec

I Hacked an Indian Government Website Found Users’ Passwords,Aadhaar Numbers,IP Address, Address,phone no,email This is a serious data privacy failure. Reported to CERT-In. Will release full technical details once its fixed. Got more in my Bag 👀 1 vuln each week series? ;))

English
2
12
58
4.7K
DuckywantDucky
DuckywantDucky@DuckyWantDucky·
Day 200/365 of the Until get 10.0 Critical report 📤 Reports Submitted:- 0 🟠 triaged - 3 🟦 program review - 0 🟤 Duplicate - 0 🟣 New - 2 ⚪️ Info - 0 💰 Paid - $3487 💻 Worked- 10 HOUR #BugBounty Yay, I was awarded a $2700 + Bonus bounty on @Hacker0x01
DuckywantDucky tweet media
English
90
4
412
20.2K
X3r0Day
X3r0Day@X3r0DaySec·
@ks7X01 better something than nothing. Keep trying and you'll get there 🔥🫶
English
0
0
2
83
Ks7
Ks7@ks7X01·
i usually don't look for xss's because i could not really find any despite trying , but this time it just worked. it's still a self-xss, i'll try my best to make something out of it.
Ks7 tweet media
English
3
0
28
1.1K
X3r0Day
X3r0Day@X3r0DaySec·
I Hacked an Indian Government Website Found Users’ Passwords,Aadhaar Numbers,IP Address, Address,phone no,email This is a serious data privacy failure. Reported to CERT-In. Will release full technical details once its fixed. Got more in my Bag 👀 1 vuln each week series? ;))
X3r0Day tweet media
English
19
17
236
30.5K
Manware
Manware@IAmManware·
ok fable is cool but what about this (by @X3r0DaySec)
English
5
0
28
994
X3r0Day
X3r0Day@X3r0DaySec·
Source: "Trust me bro"
X3r0Day tweet media
English
1
0
3
110
X3r0Day
X3r0Day@X3r0DaySec·
This is genuinely funny. Fable 5 is supposed to be Anthropic's Mythos-level LLM, their strongest model, yet it still shuts down on basic cybersec audits. I use a custom agents.md setup for OpenCode, said literally "Hi" and it immediately threw a cybersecurity warning. 👏🔥
English
0
0
2
116
X3r0Day
X3r0Day@X3r0DaySec·
@Samaytwt Claude, bring my database back. Make no mistake.
English
0
0
0
36
Samay
Samay@Samaytwt·
Never touching cursor again 😭
Samay tweet media
English
369
79
1.6K
257.3K
X3r0Day
X3r0Day@X3r0DaySec·
@VivekIntel LLMs are better at finding origin host IP than anything
English
0
0
1
208
Vivek | Cybersecurity
Vivek | Cybersecurity@VivekIntel·
☁️ CloudFail — Discover Infrastructure Hidden Behind Cloudflare CloudFail is an open-source reconnaissance tool designed to uncover origin server information that may be exposed behind Cloudflare protection through historical records and DNS misconfigurations. Key Features: • Searches for leaked origin IP addresses behind Cloudflare • Checks historical records from CrimeFlare databases • Performs DNS reconnaissance using DNSDumpster • Enumerates over 2,500 subdomains to identify exposed assets • Supports Tor routing for privacy during research • Useful for infrastructure exposure assessments and attack surface analysis Reconnaissance Techniques: ✔ Misconfigured DNS record discovery ✔ Historical infrastructure correlation ✔ Subdomain enumeration and analysis ✔ Cloudflare origin exposure detection Note: CloudFail is intended for authorized security testing, research, and defensive assessments. Properly configured Cloudflare deployments may not expose origin infrastructure. 🔗 github.com/m0rtem/CloudFa… #CyberSecurity #OSINT #Recon #Cloudflare #Pentesting
Vivek | Cybersecurity tweet media
English
6
91
472
15K