Deev Pal

359 posts

Deev Pal banner
Deev Pal

Deev Pal

@techycodec08

Security Engineer @ Meta | Ex - SAP | Trying to be a full time Bug Bounty Hunter

Присоединился Eylül 2024
104 Подписки5.5K Подписчики
Jawad Al Hashmi
Jawad Al Hashmi@kindnessuae·
@techycodec08 Impressive work uncovering the Trello-Slack flaw. Your thorough approach in reporting vulnerabilities drives progress in platform security and sets high standards for responsible disclosure. Congratulations on the impact.
English
1
0
1
220
Deev Pal
Deev Pal@techycodec08·
I received a lot of DMs, Mentions and Comments as to why I left Bug-Bounty, where did I vanish, when would I continue with my 100k challenge and so on. So here is the answer. I have joined @Meta — London, UK as a Product Security Engineer which I still can't believe just happened. I was extremely busy with the interview preparation, the interview itself and Visa Requirements afterwards for this huge change in my life. I am extremely grateful for this opportunity and ready for the challenges ahead. Here’s to new beginnings! Regarding bug-bounty, I will soon resume on the 100k challenge, but this time, with more energy, power, focus determination and hardwork. #Meta #SecurityEngineer #DreamJob
Deev Pal tweet mediaDeev Pal tweet mediaDeev Pal tweet media
English
69
31
1.4K
102K
Deev Pal
Deev Pal@techycodec08·
@theodorezra @Meta I have a bachelor's and a master's degree in computer science and software engineer apart from the two certificates you mentioned.
English
1
0
6
1.3K
Naas
Naas@ShortNaas·
@techycodec08 @Meta Congrats on your next adventure. Do you mind if I ask you what kind of certs or college degree you held besides proving your skill for this kind of positions? I have seen you get your CRTP and Security+ from your last posts.
English
1
0
1
1.6K
s
s@hshagshsu·
@techycodec08 @Meta How do you transition to product security engineer I think you were a devops engineer ?
English
1
0
6
3.5K
Deev Pal
Deev Pal@techycodec08·
@Gh05t4s1 Full time Mtech offered by my company
English
0
0
2
629
Vedant Roy
Vedant Roy@Gh05t4s1·
@techycodec08 Are you doing a part time MBA? Or anything similar?
English
1
0
2
788
Deev Pal
Deev Pal@techycodec08·
Day 80-81: 0-100k in Bug Bounty with a 9-5 Job With everything going on in my life, be it Work Load or Final Year Major Project Submission or Family Medical Problems, its becoming difficult for me to consistently give time to bug-bounty or even creating posts and blogs. I am trying my best to give every little time I get to hunting, but its getting extremely difficult. Nevertheless, I wont give up. Regarding Bug bounty: I have started to hunt for CSRF and CSPT on the vulnerable application, with lots of code review to find the vulnerable Sources and Sinks. While doing that I found a few Web-Socket requests which might be vulnerable to IDOR leading to a High Impact Priv Esc, but I am not very experienced with Web-Sockets, which is why it is getting difficult to show Impact. @Rhynorater
Deev Pal tweet media
English
8
5
152
14.8K
Deev Pal
Deev Pal@techycodec08·
@ssdd934 I generally just go through the application first understanding all the world flows and functionalities, after which I check my burp for the different requests it captured and understand them.
English
1
0
1
242
excexcffcds 🦴
excexcffcds 🦴@ssdd934·
@techycodec08 hi bro, kindly ask how did you do the first step in the bug bounty program, I mean the information gathering. There are some general methodologies, but I still wanna know how to do it in real program. Thank you in advance.
English
1
0
3
352
Deev Pal
Deev Pal@techycodec08·
Day 79: 0-100k in Bug Bounty with a 9-5 Job Continued with my research on CSPT and CSRF bug classes. I read around 100 Reports, from the day I started and I never imagined Client Side could be this Interesting. Probably from tomorrow I will start my hunt for them. @Rhynorater
Deev Pal tweet media
English
4
1
93
9.6K
Salty Bun
Salty Bun@benhij96·
@techycodec08 ah damn would've been p2,p1 sucks it wasn't in scope
English
1
0
3
322
Deev Pal
Deev Pal@techycodec08·
I also thought of sharing my stats on every day posts for you guys to have a look. So here it goes: Total Bugs Reported: 11 Accepted: 4 (P3 -3, P4-1) Duplicate: 2 NA: 5 Bounty Earned: $4000 Total Time Spent on Hunting: 223:22:06
Deev Pal tweet media
English
4
1
27
5.1K