
Jerry
@Mdhsan19
Followers
2K
Following
8K
Media
220
Statuses
4K
Cybersecurity Researcher 18yo bug hunter | blue Teamer | OSINT Analyst | Threat intelligence Researcher | IR 👨💻👨💻
Nepal
Joined November 2021
Alhumdolillha ♥️ 2nd report on Google also got accepted, . Tip : always try to monitor your target for fresh leaks 😁 . #bugbounty #bugbountytips #jerry1319
First report on @google got accepted, . I chained 3 bugs together among one of them got duplicates otherwise it will be P3 .#bugbounty #jerry1319
12
2
69
RT @0xAsm0d3us: Some good news!! OpenID Connect (OIDC) Support for npm Registry is coming soon. Which means, the attack surface for supply….
0
2
0
I Used your extension ( @sl4x0 ) and it's working like a charm. I suggest everyone to use it.
🔥 New Chrome extension: BB-Reformater! Rewrite text on any webpage, directly in your browser. A must-have for bug bounty hunters needing pro reports fast. Ditch the tab-switching between ChatGPT and reports—start rewriting now! ➡️ #bugbounty.
0
0
9
Saw some tools on X claiming to find leaks in minutes with “private scanners.” Don’t fall for the hype — they’re just basic open-source tools with fancy UIs. Invest your time, pipeline the tools yourself. Same results, no BS. #bugbounty #bugbountytips.
3
1
28
Getting a lot of DMs asking how to get more subdomains using perm. One common mistake: running the permutation wordlist and PureDNS resolver in parallel. This often leads to DNS resolution issues or hitting rate limits. Run them sequentially for better results.
This is not the right way to permutation and resolve the dns , you are gonna miss a lot of sub's bcz of race issues here.
2
2
19
This is not the right way to permutation and resolve the dns , you are gonna miss a lot of sub's bcz of race issues here.
Deep Subdomain discovery through alterations and permutations :. cat subdomainlist.txt | dnsgen -w wordlist.txt - | puredns -r resolvers.txt . @Assass1nmarcos @ADITYASHENDE17 @sudhanshur705 @Alra3ees
4
0
14
Heyy @YShahinzadeh ,. Can you please open your dm , need to talk about few escalation of html injections to xss , I would love to know if you would like to help me in it's escalation via a collab ,. Thank you.
1
0
3
Hey @4non_Hunter ,. Any update on this ???.
Hey @4non_Hunter ,. Is there any update regarding the slides you promised to publish of seasides ,. Just curious to know.
0
0
7
RT @shellbreaker_: This life is yours. Live for yourself. Take risks. Build. Fall. Get back up. Repeat.
0
2
0
RT @Jayesh25_: I've often hesitated to participate in public bug bounty programs, mistakenly believing that if a program is public, it's li��.
0
50
0
Hey @4non_Hunter ,. Is there any update regarding the slides you promised to publish of seasides ,. Just curious to know.
1
0
3
is it still possible to takeover a github subdomain or github fixes the takeover issue via implementing dns verification for custom domains ?? #bugbounty #bugbountytips.
0
0
2
if you ever encounter a internal salesforce instance which is restricted for external user and allowed /sfsites/aura. just change the endpoint to /aura and use random descriptor with a wrong aura.token will leads to internal configuration file leakage #bugbountytips #bugbounty
5
12
149