Bug Bounty Hunter

Joined January 2025
5 Photos and videos
Pinned Tweet
Thank you @intigriti for choosing me as the 2024 Champion! I know it’s been a while, but I’m finally posting this :D
3
32
2,102
1000 Valid Submissions! 🎉 Thank you @intigriti for the recognition and the gift.
20
5
236
8,863
Tip: Open Redirect ⚠️ - Use invalid URL-encoded bytes ( , ) to bypass validation; they decode to (?) evil[.]com?@ target[.]com ❌ evil[.]com@target[.]com ✅ #bugbountytips #bugbounty
2
28
190
6,370
Pro tip: 2FA Bypass 🔥 1/1 - Look for old login pages in web.archive.org , Sometimes they are not protected. - This can also lead to finding some XSS, Open Redirects. #bugbountytips #bugbounty

3
4
80
3,829
1/2 Has the old login page been removed? No worries, go a step further and try the login form endpoint: example.com/old_login => 404 => copy/send the login form from web.archive.org => example.com/api/v1/old_login => 200

2
14
650
Tip: Always double-check fixed vulnerabilities and try to bypass them. Sometimes you get interesting results. Happy Hunting⚡️ #bugbountytips #bugbounty
2
6
88
3,335
30 Jan 2025
Hello World. @intigriti
9
23
1,881