Today I turn 18 and as of till now I have been able to hack some of the biggest companies ethically like Google, Microsoft, Oracle, Salesforce, Dutch Government and much more making 💸💸💸
ॐ श्री सद्गुरुवे नमः 🙇🏻🌸
Here is a triage of the day at @BMW#bugbounty#bugbountytips
I started bug bounty when I was 15. It gave me a place to explore my passion, learn by doing, and help secure companies I had looked up to for years. By the time I was 18, I had earned thousands of dollars but most importantly, I was able to make real difference in the world(1/2)
‼️ BREAKING: HackerOne will require a verified government ID to submit to any bug bounty program on its platform. Every account, new and existing, managed or unmanaged.
Its docs, updated today, cite "regulatory requirements." Verification runs through Veriff and must be renewed yearly; sessions over a VPN or on a jailbroken device are rejected, and under-18s can't verify at all.
Their vulnerability disclosure program stays open with no ID.
https://t.co/0cV0yGXiFG
Bug bounty used to be about talent, curiosity, and the impact of your work, not where you were born, whether you have government-issued documents, or if you're old enough to pass a verification check.
How many young researchers will never get that same opportunity now?
I’m thrilled to share that a critical bug I reported has been officially resolved by the @USDOD 🦅🇺🇸
Where, just for PoC I was able to exfiltrate 72+ users sensitive information including address and payment info!🚨
🔍Bug: Broken Access Control (BAC)
#BugBounty#CyberSecurity
I was recently awarded $600 from one of the largest e-commerce site in the world. 🎯
ॐ श्री सद्गुरुवे नमः 🙇🏻🌸
The bug allowed an attacker to potentially manipulate search results and get his listing as most suggested. 🚨💥
#bugbountytips#bugbounty
Ethically Hacked @UNESCO!🔥
Bug: Broken Access Control(BAC)
Tip: One thing that helped me in this particular case is reading page source to enumerate services being used by the application.
ॐ श्री सद्गुरुवे नमः 🙇🏻🌸
#bugbountytips#bugbounty#Hacking#CyberSecurity
@ethicxlhuman Waybackurls gives you thousands of endpoints to start on. So, I suggest sorting results separately by their pattern and subdomain. After that, you can do some manual testing or run automation overnight. I haven’t had much luck with automation so I prefer a the manual approach
3x Vulnerabilities discovered on Apple!🔥
ॐ श्री सद्गुरुवे नमः 🙇🏻🌸
I am delighted to announce that I have been inducted into the Apple Hall Of Fame (HoF) for yet another time and got awarded $$$$ bounty.
Tip: Use Waybackurls for endpoint discovery
#BugBounty#bugbountytips
I discovered a high severity bug in one of the most widely used products of Adobe. I was able to access it’s partners sensitive information including personal phone numbers and email addresses⚠️
Tip: Focus on Authentication related bugs🤌
#BugBounty#bugbountytips