Mdhsan19 Profile Banner
Jerry Profile
Jerry

@Mdhsan19

Followers
2K
Following
8K
Media
220
Statuses
4K

Cybersecurity Researcher 18yo bug hunter | blue Teamer | OSINT Analyst | Threat intelligence Researcher | IR 👨‍💻👨‍💻

Nepal
Joined November 2021
Don't wanna be here? Send us removal request.
@Mdhsan19
Jerry
2 years
Alhumdolillha ♥️ 2nd report on Google also got accepted, . Tip : always try to monitor your target for fresh leaks 😁 . #bugbounty #bugbountytips #jerry1319
Tweet media one
@Mdhsan19
Jerry
2 years
First report on @google got accepted, . I chained 3 bugs together among one of them got duplicates otherwise it will be P3 .#bugbounty #jerry1319
Tweet media one
12
2
69
@Mdhsan19
Jerry
1 month
RT @0xAsm0d3us: Some good news!! OpenID Connect (OIDC) Support for npm Registry is coming soon. Which means, the attack surface for supply….
0
2
0
@Mdhsan19
Jerry
2 months
I Used your extension ( @sl4x0 ) and it's working like a charm. I suggest everyone to use it.
@sl4x0
Abdelrhman Allam 🇵🇸
2 months
🔥 New Chrome extension: BB-Reformater! Rewrite text on any webpage, directly in your browser. A must-have for bug bounty hunters needing pro reports fast. Ditch the tab-switching between ChatGPT and reports—start rewriting now! ➡️ #bugbounty.
0
0
9
@Mdhsan19
Jerry
2 months
I was awarded $5,000 after discovering a hidden endpoint using this extension:
Tweet media one
22
39
397
@Mdhsan19
Jerry
2 months
Saw some tools on X claiming to find leaks in minutes with “private scanners.” Don’t fall for the hype — they’re just basic open-source tools with fancy UIs. Invest your time, pipeline the tools yourself. Same results, no BS. #bugbounty #bugbountytips.
3
1
28
@Mdhsan19
Jerry
2 months
RT @hakluke: The #1 RULE before you collaborate! ⚠️
0
5
0
@Mdhsan19
Jerry
3 months
did anyone faced noise issue in the AIO Liquid cooling caused by the air bubble trap , Kindly let me know if anyone faced or how they solved this annoying issue in there pc .
0
1
0
@Mdhsan19
Jerry
3 months
There are alot of things to do while resolving subs to get more subs and ASM which are ignored by other hunters dont just run tools with lazyness. It's impossible for me to share everything in tweets, that's why not talking about it much ,. Know well before running randm 1 liner.
0
0
0
@Mdhsan19
Jerry
3 months
it's better to monitor your resolvers and sending dns list to analyze and get more subs or else resolve same perm wordlist multiple few times to get more subs without hitting the limiting of resolvers.
1
0
0
@Mdhsan19
Jerry
3 months
Getting a lot of DMs asking how to get more subdomains using perm. One common mistake: running the permutation wordlist and PureDNS resolver in parallel. This often leads to DNS resolution issues or hitting rate limits. Run them sequentially for better results.
@Mdhsan19
Jerry
3 months
This is not the right way to permutation and resolve the dns , you are gonna miss a lot of sub's bcz of race issues here.
2
2
19
@Mdhsan19
Jerry
3 months
This is not the right way to permutation and resolve the dns , you are gonna miss a lot of sub's bcz of race issues here.
@sratarun
Tarun mahour
3 months
Deep Subdomain discovery through alterations and permutations :. cat subdomainlist.txt | dnsgen -w wordlist.txt - | puredns -r resolvers.txt . @Assass1nmarcos @ADITYASHENDE17 @sudhanshur705 @Alra3ees
Tweet media one
4
0
14
@Mdhsan19
Jerry
3 months
Heyy @YShahinzadeh ,. Can you please open your dm , need to talk about few escalation of html injections to xss , I would love to know if you would like to help me in it's escalation via a collab ,. Thank you.
1
0
3
@Mdhsan19
Jerry
3 months
Hey @4non_Hunter ,. Any update on this ???.
@Mdhsan19
Jerry
4 months
Hey @4non_Hunter ,. Is there any update regarding the slides you promised to publish of seasides ,. Just curious to know.
0
0
7
@Mdhsan19
Jerry
3 months
RT @shellbreaker_: This life is yours. Live for yourself. Take risks. Build. Fall. Get back up. Repeat.
0
2
0
@Mdhsan19
Jerry
3 months
RT @Jayesh25_: I've often hesitated to participate in public bug bounty programs, mistakenly believing that if a program is public, it's li��.
0
50
0
@Mdhsan19
Jerry
3 months
RT @jeetbhdr: Last year, my mother got diagnosed with leukemia. Thanks to bug bounty, I was able to pay all her medical bills and take care….
0
4
0
@Mdhsan19
Jerry
4 months
Hey @4non_Hunter ,. Is there any update regarding the slides you promised to publish of seasides ,. Just curious to know.
1
0
3
@Mdhsan19
Jerry
5 months
Thanks Bhai ❤.
@v1nusharma
🦅
5 months
Happy Birthday Brother ♥️🧑‍💻@mdhsan19.
0
0
3
@Mdhsan19
Jerry
5 months
is it still possible to takeover a github subdomain or github fixes the takeover issue via implementing dns verification for custom domains ?? #bugbounty #bugbountytips.
0
0
2
@Mdhsan19
Jerry
5 months
Currently its main source of income , but hope so this year it will be 2nd or 3th source ,. Just wanna to drop it to do I part time instead of full time hunting ,. Full time trauma = full time hunting.
@HackenProof
HackenProof
5 months
Is bug hunting your main source of income, or do you also have another job?.
0
0
10
@Mdhsan19
Jerry
6 months
if you ever encounter a internal salesforce instance which is restricted for external user and allowed /sfsites/aura. just change the endpoint to /aura and use random descriptor with a wrong aura.token will leads to internal configuration file leakage #bugbountytips #bugbounty
Tweet media one
5
12
149