Joined January 2020
123 Photos and videos
Pinned Tweet

31 Oct 2024
Replying to @NahamSec
Pick a niche, become an expert, find bugs maybe even 0days or reverse n-days, and write blogs. Even if you don’t hit those $100k bounties, it’ll be a stepping stone toward a $100k job. What niche? How to pick? Examples? infosec being so vast from web3 sec to web2, mobile, desktop, recon, client-side, server-side, cryptography and so on. These are umbrella terms, but if we zoom in, there are specific areas where spending a lot of focused time will make you a top 20 expert -- 100% sure. The key thing is, that the current top 20 experts in any niche will eventually be replaced as they get bored or burned out. This leaves room for you, and the easiest way to pick a niche is to learn from an existing expert in the niche, take inspiration, and grind to build on top of it. 1. For instance, I got into the client-side JS niche by following @terjanq’s work. From there, I went down even further to focus specifically on ElectronJS. 2. Another example: @rootxharsh and @iamnoooob their niche is in reversing n-days and finding new ones based on that knowledge. I don’t think anyone in India can compete with them on reversing n-days, writing blogs, and submitting findings to bounty programs. 3. And off the top of my head, @ajxchapman, from his tweets, seems to have a specific niche in V8 n-day exploits. I don’t think there’s anyone else in the web security scene who can write V8 exploits 😅. 4. Like @orange_8361 , pick a complex target and grind on it for months eventually uncovering mind-blowing findings. 5. Or, like @albinowax, choose a complex specification, such as HTTP, and find bugs from every aspect of it from top to bottom (Sorry for tags xD) I could list so many more people, but my point is this: if you look at the top bug bounty hunters or experts, there’s a pattern. Their blogs or tweets consistently focus on a specific niche (or two) for years and years. No one ever becomes a pro in a night. How to Become an Expert in a Specific Niche? Spend a lot of time. There’s no shortcut. Follow the work of the expert you picked for inspiration, read their blogs, dive into the blogs they learned from, and explore everyone else in that specific niche. Solve CTFs and write about them. For example, not to make it all about myself, but just as an example. I’ve read every blog from the people I listed as inspirations(blog.s1r1us.ninja/inspiratio…) while learning client-side security. If it’s taking time to understand, you’re likely on the right path. That’s where most people give up, so keep pushing. Just dedicating days to it will put you ahead of at least 100 others. It’s that simple. Expert = Spent Time × IQ Find Bugs or 0days, Reverse n-days, and "Write Blogs Once you’re an expert, finding bugs will start to feel natural. But let’s be real, sometimes you might not get lucky. When that happens, reverse other n-days and write about it. I mean write about anything. Nothing gives you as much exposure as writing blogs: you’re helping others, plus you’re building a network that will eventually help you land a $100k job or $100k bounties.
18
5,056
bugoverflow retweeted
made a tool that maps every HackerOne bug bounty program to its github repos (116 programs). github.com/actuallyclover/so… #bugbounty #tools #opensource
15
106
6,541
bugoverflow retweeted
* Create your own AI scanner * Create website for that AI * Offer it for Sale/Subscription * create a X profile for the AI * Start Posting Old bounty’s photos with posts like (found this by this @AI, I spend 10$ and I got rewarded 10K$) Story Of This Days 😤 Not #bugbouny 🫣
30
43
446
16,824
bugoverflow retweeted
If you use Nuclei for bug bounty or recon, this repo is a goldmine. Source: github.com/emadshanab/Nuclei… It aggregates hundreds of public/custom Nuclei template repos in one place: • CVEs • SSRF • SSTI • XSS • Takeovers • WAF detections • Fuzzing templates • API checks • and much more. A very useful resource for expanding your custom scanning workflow and discovering community templates you probably missed. 🔥 #bugbounty #cybersecurity #appsec #infosec #nuclei #hacking
4
94
396
15,899
bugoverflow retweeted
May 14
SQL Injection without these special chars [' "()\/%*&\`] possible? Yep, me and @or4nge16hehe did it. Using only: [ a-z, 0-9, dot, @ - ] Write-up soon #BugBounty #infosec
13
57
700
49,708
bugoverflow retweeted
i'm taking a pause from hacking to resume building bugbountyhunter.com. i regret closing it down and I shouldn't of done it. everything will be back online EXACTLY as it was very soon and i've got some big plans for the future. and yes, that includes zseano methodology v2 ;)

44
52
642
24,896
In April, I submitted 42 vulnerabilities to 1 program on @Hacker0x01. #TogetherWeHitHarder hackerone.com/last-month

1
40
1,033
bugoverflow retweeted
Decided to do a write up after a very long time if anyone’s interested let me know 👀👀 Will Drop in sometimes, the issue is still open so probably will wait sometime. All the endpoint, Param and Backend details are not real for the security reasons 🥸
6
18
175
17,060
bugoverflow retweeted
ًWrite-up is now available you can read it here medium.com/@youssefmohamedsa… Follow Me to Stay updated with more Findings
Alhamdulillah This my Last Activity in Bug Hunting First Critical = First Accepted 🔥 I have been rewarded with $$$$ from AT&T and $$$ From Yahoo Write-up Coming soon stay tuned
10
27
244
14,746
haha
1
1
229
bugoverflow retweeted
Just dropped Part 1 of my Recon series on Medium 🚀 I’ll be sharing my methodology tips & tricks that helped me find real bugs and earn $$$$$ link: medium.com/@NeM0x00/the-art-… More parts coming. #bugbountytips #bugbounty #bughunting
1
14
103
4,317
bugoverflow retweeted

5
48
307
22,225
In March, I submitted 25 vulnerabilities to 2 programs on @Hacker0x01.
2
23
1,068
bugoverflow retweeted
Mar 26
Replying to @yeswehack
Spending so much time on a single program ( 3 months, 1-2yrs, name it e.t.c ), will teach you far more techniques than focusing on random programs... How has this helped me ? I've been on a program for 6 months now, the couple of weeks I realized that some assets are running behind a known CMS ( called "Directus" ), which is vulnerable to info leak & arbitrary file overwrite, I sent all reports in and they'll got accepted... the interesting part of this is that every assets of the target, with the prefix "cms.", is vulnerable.. The more time you spend on your target or understanding your target, the more the attack surfaces, the more the vulnerabilities.
4
8
95
3,062
bugoverflow retweeted
Collection of all our cheat sheets & methodology cards for exploiting BAC, XSS, CORS, CSRF, etc.! 😎 A thread! 🧵👇
1
69
366
18,142
Just scored a reward @intigriti #HackWithIntigriti
1
16
685
6k club 🪲🪲🪲
2
48
1,192
bugoverflow retweeted
Aura. 🤷‍♂️ @B_Fernandes8
432
6,091
38,909
682,671