AshenOne

1.4K posts

AshenOne banner
AshenOne

AshenOne

@RedwanurG

Security researcher? 🇵🇸 🇧🇩

เข้าร่วม Ağustos 2023
813 กำลังติดตาม40 ผู้ติดตาม
Magn4
Magn4@Magn4_·
First and hopefully not last Testimony on @Hacker0x01, This really made my day 😁😁😁
Magn4 tweet media
English
7
1
49
1.2K
Harsh D Ranjan
Harsh D Ranjan@HarshDRanjan1·
Thinking of trying @yeswehack Have you used it? How’s the experience compared to HackerOne or Intigriti? Worth getting into, or should I stick to the usual platforms? Would really appreciate some honest feedback
English
8
0
16
2.2K
AshenOne
AshenOne@RedwanurG·
@4osp3l what subscription model do you use?
English
0
0
0
577
Gospel
Gospel@4osp3l·
I found and reported 2 DOM-XSS + SSRF using cluade sonnet 4.6! It's not about the model. It's about how you use it.
English
9
4
195
19.5K
AshenOne
AshenOne@RedwanurG·
@0xw2w where did you get "we are so back"? I only see "we are cooked" in every announcement
English
1
0
1
35
AshenOne รีทวีตแล้ว
meg ✮
meg ✮@unicrnsoft·
USE YOUR FUCKIN VOICE FOR THIS HOLY FUCKKKK. THEY ARE GOING TO KILL 10,000 PALESTINIAN HOSTAGES
English
58
43.6K
86.7K
1.2M
AshenOne
AshenOne@RedwanurG·
@xssdoctor @Jhaddix hi I would like to ask how did you learn and be good at client side hacking I was thinking of starting to learn client side hacking a little guide line will be appreciated
English
1
0
4
2.7K
xssdoctor
xssdoctor@xssdoctor·
About a year and a half into my hacking journey, I was pretty bummed out. I had done so much work and learned so much, but I wasn’t finding any bugs. I decided to do something drastic, and I sent a discord message to a hacking legend, @Jhaddix
English
19
17
348
36.6K
AshenOne
AshenOne@RedwanurG·
Hi I have found a SSRF in a pdf render functionality, when I try to hit the meta data endpoint with iframe it gives error that meta data header is required, but when I host script on my server with meta data header hitting the meta data endpoint then the response is empty
English
0
0
0
22
AshenOne
AshenOne@RedwanurG·
@saur1n I don't need it but can you write a blog post of how you look for ssrf?
English
0
0
0
84
manuel valdez⛩️
manuel valdez⛩️@saur1n·
Alright guys, because we're in the holy week and I want to give back just like our father taught us. I have a 3 month Burp Suite pro license I want to give away to someone that needs it, reply down below whatever you wanna say to earn it and I'll choose the winner tonight No DMs
manuel valdez⛩️ tweet media
English
15
0
50
3.2K
Franc Vian
Franc Vian@fr4vian·
crits...
Franc Vian tweet media
English
5
0
153
4.2K
Sahin
Sahin@sahinyes·
After many duplicates, I finally reached my goal of submitting one valid bug report this month on the last day. I’m so happy. Thank you for making this possible @intigriti #bugbounty
Sahin tweet media
English
6
1
73
1.7K
AshenOne
AshenOne@RedwanurG·
@Shabosec but how the hack you got that password tho?
English
1
0
2
315
Koupon
Koupon@Shabosec·
I found this Admin portal using Y-Dork site:Target.com inurl:login | inurl:admin | inurl:login | inurl:logon | inurl:sign-in | inurl:signin | inurl:signup | inurl:sign-up | inurl:dash | inurl:portal | inurl:panel | inurl:register | inurl:administrator 🔥🔥🔥🔥🔥
Koupon@Shabosec

F**CK Admin Account Takeover 😲😲😋 Tips Username:Admin Password:QWERTY1234$ 🔥🔥🔥 Big up @GodfatherOrwa @badcrack3r @4osp3ll Patient is Virtue 🚀🚀🚀🚀

English
4
19
172
12.1K
AshenOne
AshenOne@RedwanurG·
@hackrkid congrats which platform is this?
English
1
0
2
198
Hike
Hike@hackrkid·
Just got assigned my second bounty although I disagree with them for it being low let's see, I did make an appeal
Hike tweet media
English
2
0
27
3.7K
Biscuit
Biscuit@OreoB1scuit·
Claude Love Digging JS files 😂
Biscuit tweet media
English
10
5
247
10.7K
Shreyas Chavhan
Shreyas Chavhan@shreyas_chavhan·
one more triaged and paid, yayyyy!! 😍 coming back stronger.
Shreyas Chavhan tweet media
English
12
0
185
3.7K
AshenOne
AshenOne@RedwanurG·
@z0ksh_ @zerocopter Hi brother how do you get invited to zerocoptore bugbounty platform? I mean I know by dorking you can get some programs but does it secure your place in bugbounty platform? i'm meaning to say that after submitting few vulns on those programs can i get invited on other programs?
English
1
0
0
84
the_IDORminator
the_IDORminator@the_IDORminator·
I maintain that adding a trailing slash to random pages and APIs remains the stupidest albeit perhaps most effective and prevalent authorization and/or WAF bypass there is. Go slay #bugbounty, the world depends on your proper insertion of the slash. When you get your first bounty doing this, go on a vacation and when your wife says "No no, it's too expensive." You say: "Its OK, the slash is paying for it." Because in what other field can you add a backslash somewhere and make enough money to take the family on a vacation 🤣 /place/thing/page.aspx --> /place/thing/page.aspx/ some/v1/api/users --> some/v1/api/users/ Other common wins are: /, //, %2f, %3f, #, and so forth. Just tack stuff lack that on the end. Maybe combine it with method changes. OK BYE
English
8
44
320
10.6K