Got the first bounty for 2026 where I make AI editor to execute the XSS which in turn lead to full access by elevating the privileges.
#BugBounty@Hacker0x01
Sharing my Burp Extension that earned me $200k in 2025 while API testing heavy JS-rich targets.
https://t.co/2ttRurgoPh
The tool helps find endpoints, files, internal emails, and some secrets from minified JS.
Its goal is to achieve maximum efficiency with reduced noise in results. Contributions and feedbacks are welcome.
Most JWT vulnerabilities go unnoticed as they're notoriously tricky to test for 😬
Yet, when present, they can allow for account takeovers, SQL injections and in-app privilege escalations 🤠
In our latest article, we break down every common JWT attack vector with practical exploitation techniques to help you find more JWT vulnerabilities.
Read the article today! 👇
https://t.co/dlPZuHIlEm
JShunter
JShunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive data, such as API endpoints and potential security vulnerabilities, making it an essential resource for developers, bug bounty and security researchers.
https://t.co/Wdhk76wkVB
When we decompile an APK and see an unreadable https://t.co/BbQf3H943H.bundle, it could be Hermes bytecode. Using https://t.co/DBonMwpUBM we can make it readable and look for interesting endpoints, keys, or app flows.
#bugbounty
@Bugcrowd Sometimes this noises led for P1s
such as some calls happening to 3rd party’s , secrets / tokens in js files on other domains affect directly on the scope target as well