root@AkashHamal0x01:~/ # π΅π
@AkashHamal0x01
Followers
9K
Following
14K
Media
341
Statuses
7K
Solo | https://t.co/I6KH8WMAxO | Community Helper π€| WebApp Security π | Avid Learner π | Male | Father of One | Married π Asiaβ€οΈ . wiener/peter
Triangle, Lost, Philippines
Joined June 2020
I have been inactive due to the recent super typhoon. Now that our electricity has been restored, I would appreciate it if you could update me on what you have learned this week :D
2
0
20
TF, while browsing i noticed i am top 10 in one of adult website BBP program π
3
0
8
When you know almost everything about an application then you know where to find vulnerabilities, what to check, where to look for missing checks :D
3
0
40
Suggest them to implement a useful feature that can help upgrade your severity level π
0
0
13
I wonder how many AI startups will fail without integrating OpenAI or other giants? Almost all of them ? Lol
1
0
13
This one special, this vulnerability was there for many months/years, until i changed my approach and tested the app in depth lol
0
0
5
When you know something shady is going on but you can't find some impact to report π€£
0
0
12
i am not verified, not the guy i want to message but messaging is premium feature now? wtf
1
0
2
U need to pay to message someone here? F you
1
0
5
What's the weirdest/strangest vulnerability you've discovered so far
5
0
46
if u cannot DM for some reason, comment here I will try to DM you thanks
0
0
1
whose report is this #2380261? DM me.
1
0
7
such as if you have CRLF injection , you can inject your own expired session cookies into victim browser and when victim visits website to login, the cookies you set become active. ATO by UI
0
0
4
this was because once you logout and login again the old cookie was used in request and server sets that old cookie as our new session cookie. Hence a logged out/expired cookie becomes active again. It can be achieved by other means methods ... check below π
Tip : - send http request of updating profile to repeater - logout and reset password, now replay request in repeater ("message":"Session Expired") - now login into account again and replay the http request ! (profile updated) #bugbountytips #bugbountytip
2
4
47
.. even check the report i stated its not a vulnerability but he was sure it was vulnerability lol. After a long back and forth convo i provided him video POC and he finally closed and changed usernameπ
1
0
3
Funny thing i was invited to collaborate on a report in 2024. I didn't even know the guy but i accepted to see what he really found since i was Hunting on H1 at that time. This guy was making some bet and changed his username afterwards Before the triager could even ...
3
0
35
Hey @grok , based on your analysis of the last 365 days, list in sequence 10 accounts that frequently visit my profile. Do not mention the person, only @.username and the rate of visits to the profile per month
1
0
1
Getting $XXX to promote some shit online lol . Not worth it
0
0
7