sumgr0

24.8K posts

sumgr0 banner
sumgr0

sumgr0

@sumgr0

Pentester | Bug Bounty Hunter | #hackerone | #intigriti | #bugcrowd @[email protected]

Katılım Mayıs 2009
4.9K Takip Edilen5.4K Takipçiler
sumgr0 retweetledi
encodedguy - jsmon.sh
encodedguy - jsmon.sh@3nc0d3dGuY·
Here's something every bug bounty hunter should be checking on their targets 👇 AWS assets leaking through HTTP responses and headers. Cognito Pool IDs. S3 buckets. Lambda runtime URLs. Auth domains. Just shipped this detection on Jsmon - 20+ AWS asset types. One domain scan, average ~10 seconds. Go run it on your current target. Live at jsmon.sh #bugbounty #bugbountytip #ethicalhacking #cybersecurity #awssecurity #aws
English
0
1
9
842
sumgr0 retweetledi
encodedguy - jsmon.sh
encodedguy - jsmon.sh@3nc0d3dGuY·
Cloudflare won't save you. Jsmon now bypasses WAFs to scan what's actually exposed behind your firewall: Cloudflare, Akamai, and more. Watch the 30-sec demo over Cloudflare-protected domain 👇 Live at jsmon.sh
English
0
3
15
1.6K
sumgr0 retweetledi
Jsmon | AI-Powered Attack Surface Management
We just dropped Jsmon's prices by 85% Recon: $15/mo (was $100) Recon Pro: $50/mo (was $100) + completely rebuilt UI + enhanced search & filters + light/dark mode + better scan controls Hacker-Grade Security Scans for every security researcher in 1-click. jsmon.sh
Jsmon | AI-Powered Attack Surface Management tweet media
English
1
5
10
1.2K
sumgr0
sumgr0@sumgr0·
Heading for the first @defcon at #Singapore If you are also there and see me ( Bald and Long Bearded guy) come say Hi! 👋
English
0
0
15
401
sumgr0
sumgr0@sumgr0·
Traffic Rules > money/vehicle category/social status If only people understood this equation 🤦‍♂️
encodedguy - jsmon.sh@3nc0d3dGuY

Writing this to Indian government authorities - @IndianGov @NHAI_Official @noidapolice @Uppolice @nitin_gadkari @Noidatraffic @uptrafficpolice. I've no clue why is no one writing about this. This is going to be very raw tweet and people can comment their views below. Rules are made or fine tuned when someone questions wrongdoing. Locations: Sec 62 Roundabout, Electronic City, Diverging and Merging roads near these locations. I travel from Ghaziabad to Noida Sec 62 daily. The road that takes 15 mins when traffic is very low, same road takes around 40 mins on weekdays. Even if it takes 30 mins, it's bearable, but what's not bearable is people not doing lane driving, honking unnecessarily, changing lanes like it's their private roads, opening gates (when driving at 60) to spit out guthkas, using mobile phones and scrolling reels when driving on highways and in traffic. Are traffic police folks untrained, corrupt or unseeing the situation on roads in UP, Noida, Gurgaon? When VIPs come on roads, they get good treatment, traffic police folks close the roads, and you see good roads, zero traffic, 70-100 km/hr speeds. When 99.99% of other normal lower-class, middle-class, upper-class folks are on the same roads, they're facing auto drivers who're stopping on the first lane, second lane. Bus drivers who stop their buses anywhere on roads even sometimes in the middle of roads to get 2 more passangers onboard. I've seen incidents of 2 passangers getting into an auto (who stopped it in the 2nd lane), and 2 people on bike getting into an accident because of sudden stop by auto guy. I've seen a bike guy floating in the air and falling from flyover to the service lane (3-5 metres in height) (no clue if he's alive or able to walk) in the air because of a bus doing sudden lane change. Things which I'm seeing wrong are on UP, Noida, Gurgaon roads: 1. No lane driving (almost 50% of the people are not doing lane driving) 2. People don't follow the traffic lights 3. People don't stop before the zebra line (at traffic light) 4. People honking when all the cars are in continuous traffic Who's giving them Driving License in India? Babus? Dalals? For 3000 Rs? For 1000 Rs? And, who's responsible for injuries, accidents and deaths on these roads? Dalas or the driver (who got the license because of that Dalal) who's not doing lane driving or driving on NE3 with a bike where bikes are not even allowed. There are boards on the road with signs of "No Stopping", "No Parking". People are parking right there, traffic police is also there. But, no one is fining them. Traffic police people should be trained to show no mercy based on the status of someone, just fine them 1000 Rs, 5000 Rs, or whatever the fine is. Put the wrongdoers behind bars. This once in a lifetime punishment will keep them regulated not just on roads but they'll start reading rules and regulations in restaurants, in flights, airports, etc. too. Not sure if the DL givers (dalals), or the traffic police folks are on X (Twitter), but the social media accounts whom I've tagged above must be reading this. If you're please take some action.

English
0
1
2
390
Pushpak Pawar
Pushpak Pawar@PushpakPawar_11·
Hey @sumgr0 👀 is that you in the background of this scene or am I seeing things? 😅
English
1
0
0
111
sumgr0 retweetledi
Jsmon | AI-Powered Attack Surface Management
We just open-sourced xnew — a blazing fast CLI for appending unique lines to files 🚀 Built in Go for security researchers working with massive datasets. Streams efficiently with minimal memory footprint. 📊 Benchmarks (vs anew): - 100M lines: 30s vs 1m38s - 10M lines: 2.8s vs 12.4s - Scales cleanly from 1K to 100M+ lines Perfect for: → Subdomain deduplication → Endpoint lists → Wordlist management → Any large-scale data pipeline ⭐ github.com/jsmonhq/xnew Uses XXH3 hashing + buffered I/O. Minimal memory, maximum speed. #infosec #bugbounty #golang #opensource
English
0
3
19
2K
sumgr0 retweetledi
Jsmon | AI-Powered Attack Surface Management
We've been heads-down shipping some major upgrades to Jsmon. Here’s what’s new 👇 ⚡ 6.2× Faster Scans: We migrated our infrastructure from NoSQL → SQL and refactored core backend components. Result: scans are 6.2× faster. 🔎 Configurable Scan Depth (1–4) • Depth 1 - Target page only • Depth 2 - Target + linked pages • Depth 3 - Recursive crawl (1 level deeper) • Depth 4 - Full deep recursive crawl 🛡 WAF Bypass Support: Jsmon now simulates a browser-like environment, allowing scans on assets that were previously unreachable. More improvements coming soon. Feedback welcome👇 Happy hacking 🎯
Jsmon | AI-Powered Attack Surface Management tweet media
English
0
6
6
670
sumgr0 retweetledi
sw33tLie
sw33tLie@sw33tLie·
bbscope v2 is out & bbscope.com is live! A free #bugbounty tool to pull scope from HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi. Store it all in PostgreSQL, track changes, query it, pipe it into your tools Thread on what's new👇
sw33tLie tweet mediasw33tLie tweet mediasw33tLie tweet mediasw33tLie tweet media
English
12
87
401
51.5K
Manas
Manas@ManasH4rsh·
We are launching a Hacker House in Noida. If you are in Delhi NCR, feel free to join us. We will have one target and multiple hackers working on it together. It will be a full night of hacking, brainstorming, and sharing ideas. #hacking
English
63
2
213
16.5K
sumgr0 retweetledi
Manas
Manas@ManasH4rsh·
Hi everyone, Fill this form to participate in hacker house. Once we have exact no. Of people who can participate, we will invite 10 of you, in the first of many weekends. forms.gle/GFy11G16dDc3mb…
Manas@ManasH4rsh

We are launching a Hacker House in Noida. If you are in Delhi NCR, feel free to join us. We will have one target and multiple hackers working on it together. It will be a full night of hacking, brainstorming, and sharing ideas. #hacking

English
1
2
8
1.9K
sumgr0
sumgr0@sumgr0·
I’ll be at @seasides_conf from 19-21 February 2026. If you see the Bald and Long Bearded Guy come say Hi 👋 See ya ✌️
English
0
1
6
776
sumgr0 retweetledi
Sunil Yedla
Sunil Yedla@sunilyedla2·
I wasn’t active in Bugbounty since very long time but the amount of love and support the bug bounty community is showing towards the live hacking event is overwhelming ❤️ As I always say stay kind with each other 😇 @BugTroopers #lhe #bugbounty #iitr #bugtrooper #security
Sunil Yedla tweet media
English
0
4
29
1.4K
sumgr0 retweetledi
H4x0r.DZ 🇰🇵
H4x0r.DZ 🇰🇵@h4x0r_dz·
Let’s be clear: @Hacker0x01 is using researchers’ work to train their AI and profit from it without consent. That’s not “innovation” — that’s exploitation. Our reports, our research, our time — turned into their product, while we get nothing. This violates client agreements. Vulnerabilities belong to the companies and the researchers — not HackerOne. Yet they’re monetizing it anyway. Layoffs, shrinking bounties, and now this? The platform is collapsing, and instead of fixing it, they’re squeezing the community that built it. Researchers made HackerOne. Programs trusted HackerOne. And now both are being treated like disposable data sources. If you’re a company, review your contracts immediately. If you’re a researcher, stop feeding them your work. HackerOne isn’t supporting the community anymore it’s exploiting it. And people are finally waking up. Many programs have already shifted to self-hosted , such as Salesforce. #BugBounty
BugBountyHQ@BugBountyHQ

Thread - My own opinion & this is to the Bug Hunters, What @Hacker0x01 is doing re AI, is essentially stealing “our work” “our research” for their own profitability. They are for sure breaking client agreements, wherein a clients data / vulns belong to the client. Not H1!!

English
12
30
231
15.3K
sumgr0 retweetledi
Ben Sadeghipour
Ben Sadeghipour@NahamSec·
n case you missed it, all of the talks from both conferences last year are posted on our website for free. Watch all 20+ talks here 👉🏼 nahamcon.com
Ben Sadeghipour tweet media
English
4
17
158
8.1K