Deepak bug_vs_me

5.5K posts

Deepak bug_vs_me banner
Deepak bug_vs_me

Deepak bug_vs_me

@bug_vs_me

security researcher | Bug Bounty hunter

Bharat 🇮🇳 Katılım Mart 2020
698 Takip Edilen13.5K Takipçiler
Sabitlenmiş Tweet
Deepak bug_vs_me
Deepak bug_vs_me@bug_vs_me·
@bug_vs_me/how-to-escalate-a-sql-injection-if-there-is-a-strict-waf-2a7798bb769e" target="_blank" rel="nofollow noopener">medium.com/@bug_vs_me/how…
ZXX
6
34
203
21.6K
Deepak bug_vs_me
Deepak bug_vs_me@bug_vs_me·
@0xSilvermist Ws always immunefi scammers, 1 critical and 1 high paid 0 , Admin access , drain project personal wallet they fixed they say it is OOS then Ban. 😂
English
1
0
3
803
Silvermist
Silvermist@0xSilvermist·
I found a valid High bug in a bug bounty. The project confirmed it. But I got $0. Here's what happened 👇
English
32
5
198
22.9K
Deepak bug_vs_me
Deepak bug_vs_me@bug_vs_me·
Registration = ₹5 Post /register {"Id":"123"} > already registered {"Id":"123 "} > 200 Ok +₹5 Repeat 🔁 until you become millionaire Thanks me later
English
4
1
102
7.5K
itewqq
itewqq@lyq_sqsp·
POV: your AI agent found a bug that is weird enough to make the maintainer ask that question😂
itewqq tweet media
English
2
1
143
14.3K
PeterSR
PeterSR@PeterSRWeb3·
So many people jumping into bug bounties right now... I'm genuinely curious—what's the actual success rate? Like, what % of hunters actually land their first payout? Or consistently make money? Feels like 95%+ quit early with zero $$$ 😅 Thoughts? Stats? Your experience? 👇
English
21
1
105
10.9K
☆Arookiech⚡️☆
☆Arookiech⚡️☆@Mhiztabjay·
Submitted a Dom-Based OR, marked as informative cause it won't escalate into XSS 😤
☆Arookiech⚡️☆ tweet media
English
2
0
38
1.8K
dawgyg - WoH
dawgyg - WoH@thedawgyg·
Maybe should sell to the brokers next time lol
dawgyg - WoH tweet mediadawgyg - WoH tweet media
English
35
5
322
18.7K
Mr Dami3n
Mr Dami3n@mrdami3n·
@PeterSRWeb3 well I tried web3 as I have experience with BB on "web2". I submitted reports and got banned. so, so far it's not been worth it for me on the web3 side of things 😅
English
2
0
6
1.3K
.
.@696e746c6f6c·
First triaged epic games report 🙂
. tweet media
English
5
0
151
9.8K
Aashif
Aashif@Cyb3rX7u·
@bug_vs_me Working for 12 hours straight is insane. Your dedication and hardwork is great.
English
1
0
0
228
Deepak bug_vs_me
Deepak bug_vs_me@bug_vs_me·
I spent 12 hours on an XSS and WAF bypass, and chained it to ATO for a $$$$ bounty 🙂. It was fun and I learned many new things. However, I noticed that I can’t leave work until I finish it. It’s kind of crazy that I worked straight for 12 hours. It was a vuejs ssti to xss
English
13
2
210
7.7K
Deepak bug_vs_me
Deepak bug_vs_me@bug_vs_me·
@deadvolvo i have all kind of WAF bypass, except 1 payload </script> close script tag and my 4-5 xss on hold
English
0
0
0
157
d3d aka dead (dead, мёртв, 死了)
@bug_vs_me Good question. I have seen people do this in the past when trying to validate bypasses. I guess you could say if it works on the main Akamai page, AND it works against other Akamai customers too, it could be a actual bypass. Testing on any one domain usually isn't good enough.
English
1
0
0
217
d3d aka dead (dead, мёртв, 死了)
#bugbounty For *ANYONE* who thinks you have an Akamai WAF bypass, you can't verify that against a single Akamai target alone because some customers don't enable specific rules - ESPECIALLY those that have BBP programs, they may WANT to allow specific traffic to their tech stack.
English
3
0
26
2.4K
Ash King
Ash King@AshleyKingUK·
Can you spot the problem? Just waiting on Google to push a fix for their one then I can share my blog post on this behaviour. Spoiler: Chromium are not addressing the underlying issue so Web applications need to implement mitigations!
Ash King tweet mediaAsh King tweet mediaAsh King tweet media
Ash King@AshleyKingUK

Interesting behaviour in #Chromium: if you drag and drop a Data URI-based SVG image into a new tab, any generated dialog will display an inherited origin 👀

English
2
0
37
6.2K