Coco Melon
74 posts


Taking down some android apps for a €€€€ bounty… It was fun trying something different for a change.. 💪🏻🔥
#bug #bugbounty #android #owasp #infosec #security #ethicalhacking #whitehat #codereview

English

@XamanWallet Hi team, I’ve identified a potential security issue affecting your platform. I tried reaching out via DM but didn’t receive a response. Could you please provide a proper channel for responsible disclosure?
English

Something BIG is coming.
Faster, more efficient and cheaper trades on the $XRP Ledger coming soon!
Be in control with @XamanWallet.
English

@BugBunny_ai @Zaddyzaddy Give me one free trial and if it's good I'll subscribe to that one month plan
English

@coco_melon95043 @Zaddyzaddy thanks for opening dms
English


@makemytrip Hi, I reported a security issue around 7–8 months ago but haven’t received any updates yet.
Could someone from your security team please take a look? Happy to assist with any additional details.
English

@policybazaar It’s been months since I reported a serious security issue affecting users, and there has been zero response or acknowledgment.
Ignoring valid disclosures like this is unacceptable. Please have your security team review this immediately.
English

Chained Self‑Stored XSS and Achieved Full 0‑Click ATO 🎯
Honestly, it took me 3 full working days to achieve ATO becasue i am not professional 🙂
Now, hoping for the best InshAllah.
Want the write‑up? Drop a comment and I’ll share the full breakdown. 👇
#BugBounty #ATO #XSS

English

One more Duplicate on @Bugcrowd
#BugBounty #InfoSec #2FA #EthicalHacking #SecurityResearch #BugBountyTips #CyberSecurity

English

70% of people will scroll past this.
20% will save it and do nothing.
10% will go to the comments and drop a duaa 🤲 or a motivation quote.
That 10% gets personally from me:
→ Free registration link to my hacking course
→ Early waitlist access — 2,000 spots only
This is the exact methodology I used to go from $0 → $15,129 in 7 months.
19 years old. Morocco. No degree. No mentor. Just obsession.
I'm not selling anything.
I don't want your money.
I just want to make the world a little better than I found it.
discord.gg/PVaw2dZ5
Free. لله. No fees. No catch. Ever.
My full mission 👇
onehacker.space/mission.html
Now go to the comments.
Type a duaa. Type something that keeps you going.
Or stay quiet and don't blame God, don't blame life — look in the mirror.
🔁 RT — someone on your timeline needs this today

English

@being__aman @github @GitHubSecurity @Hacker0x01 I also reported a bug. It triaged and waited for their response.
English

@the_IDORminator @Bugcrowd I found xss but it's out of scope 😢
English

T-mobile just added like 100 sites into its supplemental assets on @Bugcrowd -- I'd head there ASAP... bugcrowd.com/engagements/t-…
I'm still on #bugbounty break so I need you all to go out there and get the bugs for me!
If I were me, and I am, I'd start with search engine dorking interesting domains (duckduckgo, yandex, yahoo) and see if you can find any easy wins. Use GAU, Waymore, etc -- quick exploration mode GO.

English

@theXSSrat Dm me bro I have a best secret method to find 6 types of rxss.
English

I added a full lesson guide to my 907 - The bug bounty hunter's path!
thexssrat.podia.com/907-000-introd…
Let me guide you through my course landscape while you earn XP and have fun with me learning bug bounties!
thexssrat.podia.com/big-beautiful-…

English

@f_r_e_d_d_y_1 @coco_melon95043 Did u guys had access to document.cookie with js? lol
English











