Kanhaiya Sharma

3.4K posts

Kanhaiya Sharma banner
Kanhaiya Sharma

Kanhaiya Sharma

@krishnsec

APPLICATION SECURITY & RECON | All time top 20 @bugcrowd

Earth 🌏 Katılım Mart 2021
723 Takip Edilen19.5K Takipçiler
Kanhaiya Sharma
Kanhaiya Sharma@krishnsec·
another program, another P1 with video poc marked N/A 👏 ofcourse, if you check the bug late, it’ll already be patched .
English
8
1
72
3.5K
Kanhaiya Sharma
Kanhaiya Sharma@krishnsec·
I dropped 5x RCEs in a single report, it got triaged, then after 16 days the customer patched everything and rewarded it as P3? So a potential $10k–15k critical report suddenly became a $500 payout in one comment - this severity decision genuinely makes no sense . These kinds of decisions genuinely discourage researchers from hunting on platforms/programs. Spending days finding impactful vulnerabilities, writing detailed reports, and helping secure production systems only to see the severity heavily downgraded afterward is extremely demotivating. In this case, the issues were valid, triaged, and even patched by the customer, which clearly proves the impact was real. Yet the final outcome made it feel like all the effort put into the research had little value. Researchers invest huge amounts of time and energy into finding critical vulnerabilities responsibly, and inconsistent severity decisions like this make people lose trust in the process. Honestly, one comment was enough to completely kill the motivation and energy I had for #bugbounty
English
18
7
179
10.9K
Alex Birsan
Alex Birsan@alxbrsn·
hey @Bugcrowd can we please make this checkbox do something thanks
Alex Birsan tweet media
English
29
27
387
17.1K
Kanhaiya Sharma
Kanhaiya Sharma@krishnsec·
Just dropped a P1 and it took me 4 hrs to write a single report Honestly I’m done for today.
English
10
0
98
13.5K
i7z00
i7z00@i7z00_·
i treid to verify my identity for chatgpt cyber access, while the verification process is completed i keep getting this page after completion any idea why is that the cas?
i7z00 tweet media
English
2
0
6
1.1K
Kanhaiya Sharma
Kanhaiya Sharma@krishnsec·
suggest top paying bb programs on bgcrd & h1
English
11
0
56
6.6K
Kanhaiya Sharma
Kanhaiya Sharma@krishnsec·
@OreoB1scuit demo testing :) plus experience was not good enough, only 1 program pays ok bounty
English
2
0
9
1.6K
Biscuit
Biscuit@OreoB1scuit·
lmao i saw krishnsec on indian bug bounty platform
English
1
0
30
3.8K
Reeboot_to_init5
Reeboot_to_init5@ReebootToInit5·
Program finally marking my 2 years old reports to resolved Meanwhile me Waiting to report the bypass from last 1.11 years 💀💀🤣
Reeboot_to_init5 tweet media
English
3
0
18
984
Smilehacker
Smilehacker@_smile_hacker_·
I reported two ATOs, both critical, and one SSRF, but they marked all of them as OOS. One of the programs asked me to report it to their VDP. Sadly, they set bounty ranges up to €20,000 and wanted me to report that bug through the VDP. I totally stopped hunting on @yeswehack .
Kanhaiya Sharma@krishnsec

Dropped a critical idor bug on main api of a @yeswehack program, but it got marked as info with a strange justification - api is ours but bug is not.
what’s more surprising: the issue was quietly patched, and there’s been zero response to the support ticket I raised 👏

English
2
0
65
6.1K
Kanhaiya Sharma
Kanhaiya Sharma@krishnsec·
AI is creating more attack surface instead of reducing it , just check the VRT & search for LLM issues. everyone keeps predicting the future, but the reality is that non technical people r now pushing code, security teams are struggling to keep up with rapid reports , and new easy 0days are coming. Meanwhile, AI keeps advancing without slowing down 💯 so instead of overthinking , focus on present day problems & hunt for all bugs 🐞
English
3
1
10
301
DAMTAP
DAMTAP@Damtap12·
@krishnsec I’ve been doing bug hunting for the past 4 months and recently found a P1 vulnerability on a public Bugcrowd program. With AI rapidly advancing, I’m uncertain about the future of bug hunting and how it will impact cybersecurity. I want to understand where bug hunting is headed.
English
1
0
3
302