Hacker | Bug bounty hunter

Joined January 2022
35 Photos and videos
redbot๐Ÿ‘ฉโ€๐Ÿ’ป๐Ÿš€๐Ÿš€ retweeted
Password reset vulnerabilities and how to prevent them. Made this using @higgsfield_ai Vibe Motion from a few lines of intent, then refined the motion live to explain the security flaws clearly. Tools that improve clarity actually matter in security >>>>>>>
1
17
89
3,051
redbot๐Ÿ‘ฉโ€๐Ÿ’ป๐Ÿš€๐Ÿš€ retweeted
Absolute Insane Value! Go and Learn Bug Bounty from legend himself for free
Jan 22
Introducing my Bug Bounty Masterclass. 100% free. I've made $2,000,000 finding security bugs. I spent the last year turning my methodology into a complete blueprint. 4 hours of video - foundations, reconnaissance, web proxies, hands-on challenges, and certification. Finish it in a weekend and start hacking real-world applications ๐Ÿž
6
68
8,251
redbot๐Ÿ‘ฉโ€๐Ÿ’ป๐Ÿš€๐Ÿš€ retweeted
Great work @GodfatherOrwa This is a solid bypass. I recently wrote a write-up on a similar Stored XSS via PDF I found in Sep 2025: medium.com/@mrdesoky0/storedโ€ฆ Keep it up ๐Ÿ”ฅ
Iโ€™ve added here github.com/orwagodfather/XSSโ€ฆ PDF file for XSS, it can bypass any waf for who looking for Stored XSS , and it can be changed to blind if you want to Simply I encoded the payload as ASCII hex You can edit the payload over notepad #bugbountytips #bugbountytip #bugbounty
2
30
268
17,825
redbot๐Ÿ‘ฉโ€๐Ÿ’ป๐Ÿš€๐Ÿš€ retweeted
๐Ÿฆƒ ๐Ÿงก๐ŸคŽThanksgiving Giveaway๐ŸคŽ๐Ÿงก๐Ÿฆƒ Iโ€™m teaming up with @certtap to give away 1 CCNA Voucher! Ways to enter: โ€ข Like & Repost this โ€ข Comment or tag a friend Good Luck and Happy Thanksgiving ๐Ÿ™๐Ÿฝ
346
443
995
77,366
redbot๐Ÿ‘ฉโ€๐Ÿ’ป๐Ÿš€๐Ÿš€ retweeted
Meetup 2 done.
3
7
477
redbot๐Ÿ‘ฉโ€๐Ÿ’ป๐Ÿš€๐Ÿš€ retweeted
โฐ ๐—ข๐—ป๐—น๐˜† ๐Ÿฎ๐Ÿฐ ๐—›๐—ผ๐˜‚๐—ฟ๐˜€ ๐—Ÿ๐—ฒ๐—ณ๐˜ ๐˜๐—ผ ๐—–๐—น๐—ฎ๐—ถ๐—บ ๐Ÿณ๐Ÿฑ% ๐——๐—ถ๐˜€๐—ฐ๐—ผ๐˜‚๐—ป๐˜ ๐—ฎ ๐—–๐—ต๐—ฎ๐—ป๐—ฐ๐—ฒ ๐˜๐—ผ ๐—ช๐—ถ๐—ป ๐—™๐—ฟ๐—ฒ๐—ฒ ๐—˜๐˜…๐—ฎ๐—บ ๐—ฉ๐—ผ๐˜‚๐—ฐ๐—ต๐—ฒ๐—ฟ๐˜€ ๐ŸŽ Weโ€™re giving away FREE exam access to 2 lucky winners! โค๏ธ ๐—Ÿ๐—ถ๐—ธ๐—ฒ, ๐Ÿ” ๐—ฅ๐—ฒ๐—ฝ๐—ผ๐˜€๐˜,ย andย ๐Ÿ‘ฅ ๐—ง๐—ฎ๐—ด ๐˜†๐—ผ๐˜‚๐—ฟ ๐—ณ๐—ฟ๐—ถ๐—ฒ๐—ป๐—ฑ๐˜€ย to enter the giveaway. Allย ๐—”๐—ฝ๐—ฝ๐—น๐—ถ๐—ฐ๐—ฎ๐˜๐—ถ๐—ผ๐—ป ๐—ฃ๐—ฒ๐—ป๐˜๐—ฒ๐˜€๐˜๐—ถ๐—ป๐—ด ๐—˜๐˜…๐—ฎ๐—บ๐˜€ย are now available at aย ๐—บ๐—ฎ๐˜€๐˜€๐—ถ๐˜ƒ๐—ฒ ๐Ÿณ๐Ÿฑ% ๐—ฑ๐—ถ๐˜€๐—ฐ๐—ผ๐˜‚๐—ป๐˜: ๐Ÿ”ธ๐—–๐—”๐—ฃย โ€“ Certified AppSec Pratitioner ๐Ÿ”ธ๐—–๐—”๐—ฃ๐—ฒ๐—ปย โ€“ Certified AppSec Pentester ๐Ÿ”ธ๐—–๐—”๐—ฃ๐—ฒ๐—ป๐—ซย โ€“ Certified AppSec Pentesting eXpert Built to replicateย ๐—ฟ๐—ฒ๐—ฎ๐—น-๐˜„๐—ผ๐—ฟ๐—น๐—ฑ ๐—ฝ๐—ฒ๐—ป๐˜๐—ฒ๐˜€๐˜๐—ถ๐—ป๐—ด ๐—ฒ๐—ป๐˜ƒ๐—ถ๐—ฟ๐—ผ๐—ป๐—บ๐—ฒ๐—ป๐˜๐˜€, these exams help you validate and showcase your practical AppSec skills from fundamentals to expert-level challenges. No luck as the winner? No problem! ๐Ÿ’ก ๐—จ๐˜€๐—ฒ ๐—ฑ๐—ถ๐˜€๐—ฐ๐—ผ๐˜‚๐—ป๐˜ ๐—ฐ๐—ผ๐—ฑ๐—ฒ:ย APP-75ย at checkout, and get ๐Ÿณ๐Ÿฑ% ๐—ฑ๐—ถ๐˜€๐—ฐ๐—ผ๐˜‚๐—ป๐˜. ๐Ÿ‘‰ Secure your spot now:ย pentestingexams.com/offer/ #AppSec #CyberSecurity #Pentesting #Infosec #SecurityTesting #CyberSkills #CareerGrowth #HackingCommunity
22
20
49
4,143
redbot๐Ÿ‘ฉโ€๐Ÿ’ป๐Ÿš€๐Ÿš€ retweeted
๐Ÿšจ๐Ÿ‡บ๐Ÿ‡ธ Labor Day Giveaway ๐Ÿ‡บ๐Ÿ‡ธ๐Ÿšจ Iโ€™m giving away a CompTIA Security voucher! ๐ŸŽ‰๐ŸŽ‰ How to enter: โ€ข Like & RT this post โ€ข Comment or tag a friend Winners announced this Friday! Good Luck!
813
997
1,930
131,011
redbot๐Ÿ‘ฉโ€๐Ÿ’ป๐Ÿš€๐Ÿš€ retweeted
Giveaway brought to you by @hackinghub_io: 5x Blind XSS vouchers 5x Web Exploitation vouchers How to enter: 1โƒฃ Follow @BugBountyDEFCON subscribe to our YouTube channel 2โƒฃFollow @hackinghub_io 3โƒฃ โค๏ธ ๐Ÿ”ƒ this post 4โƒฃComment this post Winners will be picked on Friday 8/29 Youtube channel: youtube.com/@BugBountyVillagโ€ฆ And if you made it this far, you might as well join our other social media channels and subscribe to our mailing list! it only takes a minute, and It helps us a lot, and makes possible to bring these giveaways to you. Mailing list: bugbountydefcon.com/mail TikTok: tiktok.com/@bugbountydefcon LinkedIn: linkedin.com/company/bugbounโ€ฆ Instagram: instagram.com/bugbountydefcoโ€ฆ
140
140
277
30,166
redbot๐Ÿ‘ฉโ€๐Ÿ’ป๐Ÿš€๐Ÿš€ retweeted
I am giving away 1 @tryhackme voucher for a month All you have to do is share this: thexssrat.podia.com/voucher-โ€ฆ @_Freakyclown_ and @BRuteLogic are my heroes <3 @stokfredrik you rock <3 massive inspiration Much love dudes! Will pick a random winner in 24 hours
13
30
80
8,046
redbot๐Ÿ‘ฉโ€๐Ÿ’ป๐Ÿš€๐Ÿš€ retweeted
Heyy @grok, in celebration of my 10k followers, pick 5 people after 24 hours that liked and reposted this tweet. Gonna Mentor them in Digital Forensics and Investigations for free and theyโ€™ll also have access to all my tools and resources for free.
94
230
436
32,651
redbot๐Ÿ‘ฉโ€๐Ÿ’ป๐Ÿš€๐Ÿš€ retweeted
10 Aug 2025
Had an amazing time at @BugBountyDEFCON :) I met some awesome people! Many thanks to the organizers who gave their all to make this event as cool as possible! btw Iโ€™m going to try using @CaidoIO, so to celebrate the end of this edition, I'm giving away 20 one-month licenses to the first person who wants one in the comments! See you next year ๐Ÿ™Œ
36
13
186
18,721
redbot๐Ÿ‘ฉโ€๐Ÿ’ป๐Ÿš€๐Ÿš€ retweeted
Uncle Ratโ€™s 50 Web App Exploits (Easy โ†’ Hard) a CNWPP Voucher: thexssrat.podia.com/cnwpp-exโ€ฆ Reflected XSS (basic) Stored XSS (basic) DOM XSS (simple sink) HTML injection Open redirect Missing SPF/DMARC (email spoofing) Clickjacking (basic UI redress) Directory listing exposure Security misconfiguration (verbose errors, debug on) Sensitive data in JS files XSS filter bypasses (event handlers, encodings) IDOR (Insecure Direct Object Reference) Broken Access Control (functional) Broken Access Control (object/property level) Rate-limiting bypass Weak password policy exploitation File path traversal (LFI) SSRF (no authentication) Parameter pollution Cookie manipulation CSRF (state-changing requests) CSRF token bypass techniques JWT attacks (none alg, key confusion) Cache poisoning HTTP request smuggling (basic) SSTI (Server-Side Template Injection) SQLi (error-based) SQLi (blind boolean/time) GraphQL introspection leaks WebSocket hijacking Chaining SSRF โ†’ RCE Second-order SQLi Stored XSS via file upload โ†’ HTML parsing Business logic bypasses (multi-step flows) Race conditions (order logic flaws) Advanced JWT attacks (JWK key injection, KID abuse) Prototype pollution (client-side) Prototype pollution โ†’ RCE (server-side) HTTP desync attacks (request smuggling variants) Multi-tenant breakout CSP bypasses in hardened environments Chaining multiple low-severity issues into critical OAuth misconfigurations (token stealing, scope escalation) SAML misconfigurations (signature stripping) Advanced SQLi in JSON / XML RCE through file parsing libraries Blind SSRF โ†’ cloud metadata abuse โ†’ pivot Deserialization exploits (PHP/Java/.NET) Template injection โ†’ sandbox escape Full supply-chain compromise via dependency poisoning

1
9
40
2,992
redbot๐Ÿ‘ฉโ€๐Ÿ’ป๐Ÿš€๐Ÿš€ retweeted
10 Aug 2025
Hack The Box is hosting their first all Blue CTF next month! Holmes CTF 2025 Dates: September 22nd - 26th Form a team and compete for prizes ๐Ÿ† Challenges Include: - DFIR - SOC - Malware Reversing - Threat Intelligence Link: ctf.hackthebox.com/event/detโ€ฆ #DFIR #IncidentResponse #MalwareAnalysis
2
33
113
5,055
redbot๐Ÿ‘ฉโ€๐Ÿ’ป๐Ÿš€๐Ÿš€ retweeted
๐Ÿšจ๐Ÿ’ฃ BREAKING: Benjamin ล eลกko to Manchester United, here we go! ๐Ÿ”ด Agreement club to club reached with RB Leipzig for โ‚ฌ76.5m plus โ‚ฌ8.5m add-ons. ล eลกko agreed terms until 2030. ล eลกko made clear on Tuesday that he wanted #MUFC, deal now reality. New striker for Amorim ๐Ÿ‡ธ๐Ÿ‡ฎ
10,250
44,663
275,768
28,143,014
redbot๐Ÿ‘ฉโ€๐Ÿ’ป๐Ÿš€๐Ÿš€ retweeted
๐Ÿ”ฅ Hackers, itโ€™s officially GO TIME (and giveaway time!) The Endless Bundle is back โ€” and itโ€™s more stacked than ever. thexssrat.podia.com/full-houโ€ฆ ๐Ÿš€ Lifetime access to ALL current, past & future courses ๐ŸŽฅ Weekly live sessions full archive ๐Ÿ›ก๏ธ Certifications: CAPIE, CNWPP & more ๐Ÿ€ Private Discord with merch at cost ๐ŸŽ This week: 1 Endless member wins a โ‚ฌ50 HTB or THM voucher ๐Ÿงจ โ‚ฌ599 โ†’ now just โ‚ฌ89.85 ๐Ÿ’€ Only 4 seats remain ๐Ÿ’ฅ When all 4 are gone (or in 1 week): I'll pick 4 GIVEAWAY WINNERS โ€” each must: โœ… Like โœ… Share โœ… Tag a buddy (anyone!) โณ Seats are vanishing fast โ†’ thexssrat.podia.com/full-houโ€ฆ #bugbounty #infosec #cybersecurity #xss #api #hacking #learn2hack

37
33
90
10,275
redbot๐Ÿ‘ฉโ€๐Ÿ’ป๐Ÿš€๐Ÿš€ retweeted
GIVEAWAY TIMEEEEE And now is the perfect time to go participate - 50EUR HTB or THM voucher will be given to 1 endless holder this week -005: Uncle Rat's Bug Hunterโ€™s Blueprint is coming out soon - Merch packing being thrown in a giveaway for EU participants See my original tweet on details on how to participate
๐Ÿ”ฅ Hackers, itโ€™s officially GO TIME (and giveaway time!) The Endless Bundle is back โ€” and itโ€™s more stacked than ever. thexssrat.podia.com/full-houโ€ฆ ๐Ÿš€ Lifetime access to ALL current, past & future courses ๐ŸŽฅ Weekly live sessions full archive ๐Ÿ›ก๏ธ Certifications: CAPIE, CNWPP & more ๐Ÿ€ Private Discord with merch at cost ๐ŸŽ This week: 1 Endless member wins a โ‚ฌ50 HTB or THM voucher ๐Ÿงจ โ‚ฌ599 โ†’ now just โ‚ฌ89.85 ๐Ÿ’€ Only 4 seats remain ๐Ÿ’ฅ When all 4 are gone (or in 1 week): I'll pick 4 GIVEAWAY WINNERS โ€” each must: โœ… Like โœ… Share โœ… Tag a buddy (anyone!) โณ Seats are vanishing fast โ†’ thexssrat.podia.com/full-houโ€ฆ #bugbounty #infosec #cybersecurity #xss #api #hacking #learn2hack
2
3
20
2,409
redbot๐Ÿ‘ฉโ€๐Ÿ’ป๐Ÿš€๐Ÿš€ retweeted
๐ŸŽ‰ Weโ€™re partnering with @theXSSrat for a special giveaway! Once we hit 5,000 followers, 1 lucky winner will get access to $600 worth of cybersecurity courses โ€” for FREE! To enter the giveaway: โœ… Follow ๐Ÿ” Retweet this post ๐Ÿ’ฌ Leave a comment ๐Ÿ“š Course thexssrat.podia.com/full-houโ€ฆ
74
77
139
15,649