
Alam
@Alamz0
Followers
280
Following
319
Media
23
Statuses
142
Full-Stack Developer | DevOps Engineer | JR. Security Researcher | DMs Open...
India
Joined June 2022
Career update:.Started my journey as a Software Engineer, based somewhere in Western India. Putting bug hunting on pause until I am all settled. Letβs go! .#BugBounty.#SoftwareEngineering.
0
0
1
Update:.From P3 -> None -> Not Applicable.Reason: Managed by a third party. It's disappointing, but it's part of the journey. #BugBounty
From thinking it would be my first Critical, to getting triaged with P3 priority. I requested an RAR, mentioning the critical impact β but it still stayed at P3. Later on, even the P3 severity got cleared. π.What's going on? π @4non_Hunter @codingo_ .#bugbounty
0
0
0
From thinking it would be my first Critical, to getting triaged with P3 priority. I requested an RAR, mentioning the critical impact β but it still stayed at P3. Later on, even the P3 severity got cleared. π.What's going on? π @4non_Hunter @codingo_ .#bugbounty
Any help would be appreciated!.I found a vulnerable endpoint from an error that (error) was later resolved -- luckily, I had saved it in Notepad before it disappeared. The endpoint (which I got from that error) is still exploitable and reproducible. @4non_Hunter @tabaahi_.
4
0
39
I contacted @BugcrowdSupport but they said only an ASE can confirm. Is this a valid submission? Will it be triaged? ID: {efbfe696-12ab-4a61-82c1-8e44b26b22db} I tried looking for Bugcrowd's policy on this but found nothing. @codingo_ @Bugcrowd . Waiting curiously.
0
0
0
Any help would be appreciated!.I found a vulnerable endpoint from an error that (error) was later resolved -- luckily, I had saved it in Notepad before it disappeared. The endpoint (which I got from that error) is still exploitable and reproducible. @4non_Hunter @tabaahi_.
2
0
1
I can send messages to any number on their behalf. The system uses the same endpoint to send OTPs for verification purposes. I even confirmed it using a real mobile number and successfully received the customized messages. My first critical? Waiting eagerly!!!.#bugbounty
5
4
58
Alhamdulillah guys .Just got $400 for an IDOR vulnerability that exposed customer PII. Feeling good and learning new things every day. What an incredible learning experience and a great start to this journey! .#BugBounty
2
5
169
Alhamdulillah guys .here is another one, I was rewarded 250$ for weak Security Configuration. #BugBounty .
3
1
85
Alhamdulillah.My first reward on H1. Thought it was medium severity, but they rewarded it as informative. All good, Lets goo!.#BugBounty
5
0
98
How is this OK?.I was sure that priority P1/P2 will be assigned to it, but P3 is not making any sense. In the same report I chained it with Bruteforce,Idor via Id,Idor via phone number instead of making a new submission with full impact exposing PII at large scale. @Bugcrowd
3
0
53