Mahesh Yadav

129 posts

Mahesh Yadav

Mahesh Yadav

@hackrul3r

Web Security Researcher and Bug Bounty Hunter GitHub: https://t.co/sDcOI4uG48

Katılım Mart 2023
389 Takip Edilen142 Takipçiler
Mahesh Yadav retweetledi
Jsmon | AI-Powered Attack Surface Management
We've been heads-down shipping some major upgrades to Jsmon. Here’s what’s new 👇 ⚡ 6.2× Faster Scans: We migrated our infrastructure from NoSQL → SQL and refactored core backend components. Result: scans are 6.2× faster. 🔎 Configurable Scan Depth (1–4) • Depth 1 - Target page only • Depth 2 - Target + linked pages • Depth 3 - Recursive crawl (1 level deeper) • Depth 4 - Full deep recursive crawl 🛡 WAF Bypass Support: Jsmon now simulates a browser-like environment, allowing scans on assets that were previously unreachable. More improvements coming soon. Feedback welcome👇 Happy hacking 🎯
Jsmon | AI-Powered Attack Surface Management tweet media
English
0
6
6
289
Mahesh Yadav retweetledi
Jarvis0p
Jarvis0p@Jarvis0p1·
@PortSwigger Anyone else facing this issue?
Jarvis0p tweet media
English
0
2
1
95
Mahesh Yadav retweetledi
Behi
Behi@Behi_Sec·
There are dozens of JS analysis tools available for bug hunters. Each one has its own unique strengths. Here are 4 tools I personally use to streamline my workflow: 🧵
English
3
30
172
12.8K
Mahesh Yadav retweetledi
Jsmon | AI-Powered Attack Surface Management
Here's how you can do better API-contextful fuzzing by using JS files: 1. Scan domain/URL at jsmon.sh 2. Go to JS Intelligence > API Paths 3. Export all the API endpoints Make a wordlist and use ffuf or kiterunner to fuzz on dev/prod/staging APIs. #bugbountytips
English
0
9
68
19.9K
Mahesh Yadav retweetledi
André Baptista
André Baptista@0xacb·
If you found a package.json file in the wild, you might find some internal packages vulnerable to a dependency confusion attack 👀 Check for it quicker using this cool new tool by JSMon: app.jsmon.sh/tools/npm-vali… 👇
English
7
84
362
22.9K
Mahesh Yadav retweetledi
Jsmon | AI-Powered Attack Surface Management
From your feedback, to our team’s hard work → Jsmon 2.0 is here. ✨ Cleaner design 📊 Easier reporting ⚡ More power under the hood Thank you for helping us build the future of JavaScript security 💜 Check it out → jsmon.sh
Jsmon | AI-Powered Attack Surface Management tweet media
English
1
2
8
2.1K
Mahesh Yadav retweetledi
Jarvis0p
Jarvis0p@Jarvis0p1·
Hey i am at psy9 booth at besides Ahmedabad
Jarvis0p tweet media
English
1
1
8
475
Mahesh Yadav retweetledi
Jsmon | AI-Powered Attack Surface Management
New search query implemented today, over domain + subdomains of the domain for searching over JS URLs. This've increased the searches JS URLs count by a lot.
Jsmon | AI-Powered Attack Surface Management@jsmonsh

🚀 JS Explorer is live now! Discover JS URLs from domains for free. Powered with 500M JS URLs and updating every week. Visit jsmon.sh/jsexplorer/ now. ✅ Retweet, bookmark and share link with your friends in bugbounty, cybersecurity and OSINT research.

English
0
7
22
8.4K
Mahesh Yadav retweetledi
Jsmon | AI-Powered Attack Surface Management
🚀 JS Explorer is live now! Discover JS URLs from domains for free. Powered with 500M JS URLs and updating every week. Visit jsmon.sh/jsexplorer/ now. ✅ Retweet, bookmark and share link with your friends in bugbounty, cybersecurity and OSINT research.
English
4
31
113
12.5K
Mahesh Yadav retweetledi
Jsmon | AI-Powered Attack Surface Management
🎉 We just crossed 2,000 users on Jsmon! From day 1, we've been focused on helping developers uncover JavaScript-based security risks in frontends, and today, 2,000 of you trust us to do just that. Thank you for the support, feedback & belief in the mission.
English
1
2
7
296
Mahesh Yadav retweetledi
Jsmon | AI-Powered Attack Surface Management
🎉 GIVEAWAY TIME! 🎉 Want to try Jsmon Pro for free? We're giving away 3 one-month subscriptions (worth $195 total)! Here's how to enter: ✅ Follow @jsmonsh 🔁 Retweet this post 📸 Share a screenshot of your scan and tag us! That's it. Winners announced in 7 days.
English
6
12
18
2.5K