Paaastha Profile Banner
Aastha Profile
Aastha

@Paaastha

Followers
1K
Following
1K
Media
17
Statuses
408

BugBounty, Travel & Physics.

France 🇫🇷
Joined July 2015
Don't wanna be here? Send us removal request.
@Paaastha
Aastha
13 hours
Yay, I was awarded a $4632 bounty on @Hacker0x01! #TogetherWeHitHarder.
Tweet card summary image
hackerone.com
she/her -
7
0
33
@Paaastha
Aastha
9 days
RT @efaav: I found another vulnerability to leak Microsoft Employee PII ($7500 Bounty) and 700M+ Microsoft partner records. Here's the writ….
blog.faav.top
How I hacked the Microsoft Device Pricing Program to leak Microsoft Employee PII and 700M+ Microsoft partner records.
0
71
0
@Paaastha
Aastha
10 days
RT @GithubProjects: Open-source Free Domain For Everyone.
Tweet media one
0
3K
0
@Paaastha
Aastha
10 days
Burpsuite subscription renewal coming up, any first hand feedback if @CaidoIO Individual is worth switching over to?.
0
0
2
@Paaastha
Aastha
12 days
RT @albinowax: When I condense nine months of research discoveries into a 40-min talk, it can make it seem easy. For a taster of the true e….
0
44
0
@Paaastha
Aastha
13 days
RT @albinowax: This is some really nice research! It's definitely worth trying these techniques against cryptocurrency extensions! https://….
Tweet card summary image
marektoth.com
I described a new attack technique that I used against 11 password managers. The result was that stored data of tens of millions of users could be at risk.
0
53
0
@Paaastha
Aastha
13 days
RT @albinowax: Sometimes people think they've found HTTP request smuggling, when they're actually just observing HTTP keep-alive or pipeli….
Tweet card summary image
portswigger.net
Sometimes people think they've found HTTP request smuggling, when they're actually just observing HTTP keep-alive or pipelining. This is usually a false positive, but sometimes there's actually a real
0
24
0
@Paaastha
Aastha
14 days
Found my first RCE . I was able to update an API path using target's own environment variables store resulting in full control of API endpoint.
Tweet media one
4
4
79
@Paaastha
Aastha
15 days
Why there are some days when you absolutely hate doing bug bounty while on other day you loving it?.
1
0
14
@Paaastha
Aastha
21 days
RT @rikeshbaniya: if the target uses zendesk to handle support emails. you could send an email with payload. `{{ticket.ccs[0].name}}a{{tick….
0
89
0
@Paaastha
Aastha
22 days
Received an invite hack crypto web app, what kind of bugs that I can look for?.
4
0
9
@Paaastha
Aastha
26 days
RT @mbrg0: we hijacked microsoft's copilot studio agents and got them to spill out their private knowledge, reveal their tools and let us u….
0
906
0
@Paaastha
Aastha
29 days
RT @gegul_: 1/ Hi everyone! I’d like to share a few smart contract vulnerabilities I recently discovered using a s….
0
15
0
@Paaastha
Aastha
1 month
RT @rauchg: Focus on the things you can control. Work hard, eat well, stay fit, help others, and crucially: be ruthlessly truth-seeking.
0
259
0
@Paaastha
Aastha
1 month
RT @galnagli: I hacked a popular vibe coding platform with a simple, straight-forward logic flaw - allowing access to private applications….
0
242
0
@Paaastha
Aastha
1 month
A month since I started doing bug bounties full time on @Hacker0x01 , picked an average paying program and made $10,195 this month.
Tweet media one
11
2
101
@Paaastha
Aastha
1 month
Hey, @grok, who was the most famous person to visit my profile? It doesn't need to be a mutual, don't tag them, just say who it was. Also list top 20 persons to visit my profile in last 3 months. Don’t tag them.
2
0
4
@Paaastha
Aastha
1 month
RT @zhero___: happy to release my new article entitled:. Next.js and cache poisoning: a quest for the black hole. .
0
179
0
@Paaastha
Aastha
2 months
Triaged and resolved!.
@_jensec
Jenish Sojitra
2 months
With @Paaastha, just hacked into a one of the most used coding AI agent and was able to access millions of chats for a few hours that included environments variables as well.
Tweet media one
1
0
18
@Paaastha
Aastha
2 months
While we eventually finds the high/criticals, mediums are what pays the bills. #bugbounty.
2
1
26