Deepak bug_vs_me

5.6K posts

Deepak bug_vs_me banner
Deepak bug_vs_me

Deepak bug_vs_me

@bug_vs_me

security researcher | Bug Bounty hunter

Bharat 🇮🇳 Katılım Mart 2020
705 Takip Edilen13.6K Takipçiler
Sabitlenmiş Tweet
Deepak bug_vs_me
Deepak bug_vs_me@bug_vs_me·
@bug_vs_me/how-to-escalate-a-sql-injection-if-there-is-a-strict-waf-2a7798bb769e" target="_blank" rel="nofollow noopener">medium.com/@bug_vs_me/how…
ZXX
6
34
202
23.3K
MorningStar
MorningStar@0xMstar·
Consumed 500 million tokens in Deepseek v4 , just cost me 15$ .. Very cheap .
English
12
1
98
9.5K
mo7mead
mo7mead@mo7meadwael·
mo7mead tweet media
ZXX
5
0
124
3.1K
Pierre
Pierre@pierrecoins·
Tell me in one word why you need $200 right now
English
1.3K
50
911
105.4K
Deepak bug_vs_me
Deepak bug_vs_me@bug_vs_me·
any bug bounty hunter have Akamai ?id=</script> ( close script tag payload bypass Dm me i have 6 xss we can do 50/50
English
3
1
55
5K
Janpreet Singh
Janpreet Singh@janpreet4340·
@bug_vs_me sorry bro it still made the = in the end : ( <input type="hidden" name="transactionType" value="" oncontentvisibilityautostatechange"alert(1)"="" style"content-visibility:auto""="">
English
1
0
1
70
Janpreet Singh
Janpreet Singh@janpreet4340·
Any good tips for XSS in hidden endpoints like: <input type="hidden" name="transactionType" value="" hello"> where =, URL-encoded or HTML-encoded get appended at the end? Example: ?ttype=%22%20hello=%x becomes: <input type="hidden" name="transactionType" value="" hello"x"="">
English
2
3
24
2K
Deepak bug_vs_me
Deepak bug_vs_me@bug_vs_me·
@github So, when I reported that a GitHub employee had exposed push/pull access along with a GitHub API key, you awarded a high bounty. I classified it as a critical impact, considering its implications in a real-life scenario. Now we also have a real-world scenario too
English
0
0
1
494
GitHub
GitHub@github·
1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories. Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.
English
584
3.6K
11.6K
7.4M
Ethical Hacker
Ethical Hacker@whithat444·
Found a DOM XSS sink via `location.href`. I can redirect to another domain, but I’m not yet able to achieve JavaScript execution. Need help with a bypass. Whoever helps me get successful JS execution gets a 50% bounty split. DM me I’ll share more details.
English
4
0
15
10.8K
Deepak bug_vs_me
Deepak bug_vs_me@bug_vs_me·
@RBI @PSBIndOfficial As oer new guidelines all banks need to use .bank.in domain but as old domains still index into Google search and bank should hold old domains and redirect user to new domain, but @PSBIndOfficial released there domain and it is takeover scammer,
English
2
1
10
1.9K
Alex Birsan
Alex Birsan@alxbrsn·
hey @Bugcrowd can we please make this checkbox do something thanks
Alex Birsan tweet media
English
29
27
390
17.9K
0xSabir
0xSabir@0xSabir·
If you ask ChatGPT to pick a random number from 1 - 100, It only pick 73. 🥴🙌🏻 Try this bro
0xSabir tweet media
English
5
0
12
1.6K
Deepak bug_vs_me
Deepak bug_vs_me@bug_vs_me·
@krishnsec Nah they just pay bounty late, and past month because of payment issue they sent no bounty " they mentioned in one of my reports" so bounty paid in April ≠ bounty paid for reports in April
English
0
0
5
418