Kanishk Dadhich

212 posts

Kanishk Dadhich banner
Kanishk Dadhich

Kanishk Dadhich

@whotfbunny

confidential!!

India Katılım Ağustos 2022
114 Takip Edilen623 Takipçiler
Kanishk Dadhich
Kanishk Dadhich@whotfbunny·
Hello x, posting after a longtime cause I was sick 🤕 But I am back baby
English
0
0
1
86
Kanishk Dadhich
Kanishk Dadhich@whotfbunny·
Many beginners skip the windows exploitation. And that a real issue
English
0
1
6
488
Kanishk Dadhich
Kanishk Dadhich@whotfbunny·
I usually don't show my payouts, but sometimes you have to appreciate the journey. Every bounty is proof that consistency beats luck.
Kanishk Dadhich tweet mediaKanishk Dadhich tweet media
English
0
0
7
194
Kanishk Dadhich
Kanishk Dadhich@whotfbunny·
4/4 💡 Don't focus only on code execution. Unsafe deserialization can also lead to: • Authentication bypass • Privilege escalation • Session tampering • Business logic abuse • Object injection Learning how serialization works is a valuable skill for every bug bounty hunter.
English
0
0
3
151
Kanishk Dadhich
Kanishk Dadhich@whotfbunny·
3/4 🧪 Quick triage: → Find the serialized blob → Decode it (Base64/Hex) → Identify the serialization format → Fingerprint the framework/libraries → Trace whether user input reaches the deserializer Understanding the data flow is the key.
English
1
0
3
202
Kanishk Dadhich
Kanishk Dadhich@whotfbunny·
1/4 🎯 Insecure Deserialization — the bug that turns "just data" into critical impact. If an app deserializes user-controlled input (cookies, hidden fields, API payloads) without proper validation, attackers may manipulate application objects, leading to severe security issues.
English
1
4
23
2.2K
Kanishk Dadhich
Kanishk Dadhich@whotfbunny·
Trading is so fuck man I made a big loss. How can I learn? is there any free material you guys know
English
1
0
6
434
Kanishk Dadhich
Kanishk Dadhich@whotfbunny·
I am working with my last brain cells now I need a break. I need vacation.... 😤
English
0
0
4
263
Kanishk Dadhich
Kanishk Dadhich@whotfbunny·
Today I look back to my tryhackme account. And it doesn't give me nostalgia. I want my old thm UI 😭
English
0
0
6
556
Sachin Saud
Sachin Saud@Sachinsaud777·
@whotfbunny By manipulating the response, I was able to see the admin function only and to use that function. I need the valid session of admin. Only able to see the function is a big or not? (Noo PII or other leakage)
English
1
0
0
10
Kanishk Dadhich
Kanishk Dadhich@whotfbunny·
Advance bug bounty tip 1/9 🧵 Most bug bounty hunters stop at: "I can access this endpoint." Advanced hunters ask: "What happens if I chain three legitimate actions in an illegitimate sequence?" ↓
English
1
6
55
3K
Kanishk Dadhich
Kanishk Dadhich@whotfbunny·
8/9 When testing, stop looking at endpoints in isolation. Map: • Objects • Roles • State transitions • Cross-service interactions • Trust boundaries That's where high-impact reports usually emerge.
English
1
0
1
181