Karan Sharma

88 posts

Karan Sharma banner
Karan Sharma

Karan Sharma

@karan_srma

Full-Stack Developer | Bug Hunter

Katılım Mayıs 2025
69 Takip Edilen17 Takipçiler
Frozt Nova
Frozt Nova@FroztNova127·
Day 1 - Bug Bounty - Focusing on hunting BAC, found 3 bug and submitted Submitted: 3 Triaged / Pending: 0 Accepted: 0 Total bounty: 0$
English
7
0
95
3.9K
Karan Sharma retweetledi
Vivek | Cybersecurity
Vivek | Cybersecurity@VivekIntel·
Google VRP Writeups — Real Exploits, Real Bounties 🐛🔥 Curated list of Google VRP (Vulnerability Reward Program) writeups: • Real-world bugs → XSS, SSRF, RCE, IDOR, Privilege Escalation • High bounty cases → $100k+, $50k, $20k reports • Google Cloud, YouTube, Gmail, Chrome attack surfaces • Both blog + video writeups from top researchers If you're serious about bug bounty, this is where real learning happens — not theory. 🔗 github.com/xdavidhu/aweso… #BugBounty #GoogleVRP #Pentesting #CyberSecurity #Infosec #AppSec
Vivek | Cybersecurity tweet mediaVivek | Cybersecurity tweet mediaVivek | Cybersecurity tweet mediaVivek | Cybersecurity tweet media
English
2
73
383
17.6K
Karan Sharma
Karan Sharma@karan_srma·
I was tired of manually finding leads… so I built my own tool 🤝 This Python tool scrapes Google Maps and gives you business leads in minutes 🚀 → Keyword + Location → Auto scraping → Export data 100% free & open-source 👇 github.com/KaranSRMA/goog… Would love feedback 🙌
English
0
0
0
19
Karan Sharma retweetledi
DevsCure
DevsCure@devscure·
reddit.com/u/devscure/s/5… Security Testing Program – Gym Web App 🚀 Looking for beginner/intermediate testers to practice on a real app. Focus: Auth, API security (IDOR), XSS Rules apply • No automation • Limited slots DM me if interested #bugbounty #infosec #websecurity
English
0
2
1
15
Karan Sharma retweetledi
Behi
Behi@Behi_Sec·
When I started bug hunting, I went from $0 to $3K/month in just 6 months. No secrets, no shortcuts, just a refined process. Here is the exact framework I followed: 🧵
English
9
52
367
19.4K
Josephine
Josephine@_josephine0_·
No cheating.
Josephine tweet media
English
7.6K
329
6.9K
1M
Nitesh Singh
Nitesh Singh@nitesh_singh5·
Role - Junior Frontend Developer Salary - 9-30 LPA Location - Remote - HTML5, CSS3, JavaScript (ES6+) - Basic experience with at least one frontend framework Let us know if you are Interested 👇
English
651
26
842
84.7K
Nitesh Singh
Nitesh Singh@nitesh_singh5·
Role - Software Development Engineer - Intern Stipend - ₹ 20k/month Experience - Freshers Let us know if you are Interested 👇
English
592
35
1K
81.4K
Prince 👑
Prince 👑@princeofweb3·
No cheating guys Go !
Prince 👑 tweet media
English
22.8K
1K
32.8K
4.2M
Security Trybe
Security Trybe@SecurityTrybe·
Hi @X I'm looking to Connect with people who are interested in: 🔒 Cybersecurity 🕵️‍♂️ Ethical Hacking 🔐 Network Security 🛡️ Penetration Testing 📊 Security Analytics 👨‍💻 Cyber Forensics 📚 Cybersecurity Research 🚨 Risk Management 🧑‍💻 Secure Coding 🪲Bug Bounty Drop a hi and let’s connect
English
1.2K
230
3.3K
250.8K
Karan Sharma
Karan Sharma@karan_srma·
I’m a beginner in bug hunting. Tried many programs but found nothing 😫. I think I picked the wrong targets. Could you suggest one beginner-friendly program to safely practice and learn? Not looking for bounties, just a place to build skills. Thanks a lot! 🙏 #BugHunting
English
0
1
0
72
Karan Sharma
Karan Sharma@karan_srma·
@FroztNova127 @yeswehack Congrats on finding the bug and getting the bounty! 🎉💰 Honestly, you really motivate me, seeing your success makes me believe that one day I’ll also find my first valid bug. 💪🔥
English
1
0
2
105
Frozt Nova
Frozt Nova@FroztNova127·
My first valid bug and bounty from @yeswehack LFG!!!! 😭😭🔥🔥
Frozt Nova tweet media
English
35
3
228
8K
Karan Sharma retweetledi
Behi
Behi@Behi_Sec·
💡 XSS Trick: Split payload across fields. Example: FName=<img src=x LName=onerror=alert(1)> When the app renders FName + LName, your pieces join and fire. Good to try on the signup/profile forms.
English
2
13
102
4.3K
Karan Sharma retweetledi
Behi
Behi@Behi_Sec·
Bug Bounty Tip: If you have a UUID-based IDOR and can't find a valid UUID of other users, do this: Search the endpoints that hold UUIDs on GitHub! You will usually find that other users have left their UUIDs in their sample codes/scripts.
English
4
18
156
7K
Karan Sharma retweetledi
Karan Sharma
Karan Sharma@karan_srma·
I’m a beginner in bug bounty. Completed @PortSwigger labs (mostly with solutions) and now hunting real sites. People say ‘just hunt and learn’ but I feel stuck since I can’t even find the bugs I learned in labs. Any advice to overcome this stage? 🙏 #bugbounty
English
0
1
0
61
Karan Sharma retweetledi
Karan Sharma
Karan Sharma@karan_srma·
Bug hunters, how do you usually test for IDOR? I know the basics (checking params, object IDs, user IDs etc.), but curious what patterns or workflows you use in real hunts. #BugBounty #WebSecurity #InfoSec
English
3
4
51
5.7K