YourFinalSin Profile Banner
3NVZ Profile
3NVZ

@YourFinalSin

Followers
3K
Following
948
Media
36
Statuses
622

Dark Artist in the Making.

California
Joined August 2024
Don't wanna be here? Send us removal request.
@YourFinalSin
3NVZ
1 day
Day 136 - Bug Bounty. - Full MFA bypass came back as “Works as intended” today lol.- Focused mainly on logic bugs.- Kept working on my source code lead automation, to save on time and manual work. Total earned so far: $5425.
6
1
94
@YourFinalSin
3NVZ
2 days
Day 135 - Bug Bounty. - Received some Swag from @AVROTROS for finding a vuln on their infrastructure .- Thought it was payout at first - turned out they send Swag only 😅 Still liked it, thanks!.- Another report on Bugcrowd came back as duplicate . Total earned so far: $5425
Tweet media one
3
4
101
@YourFinalSin
3NVZ
4 days
Day 134 - Bug Bounty. - Another day of deep manual hacking.- Went through different types of reports on 2FA bypasses, using Hacktivity, pentesterland, etc. - Worked on some custom automation with the goal to detect leads which I can manually exploit. Total earned so far: $5425.
1
3
119
@YourFinalSin
3NVZ
5 days
Day 133 - Bug Bounty. - Was hunting on the same app.- Focused on single features and went deep on them by going through the docs and every request .- Was able to identify some interesting behavior . Total earned so far: $5425.
3
3
123
@YourFinalSin
3NVZ
6 days
Day 132 - Bug Bounty. - Did a deep dive into an app I was hunting on in the past.- Reported 2 issues, but seemed pretty low hanging, so probably duplicate .- If you are one of those asking for a roadmap, this is a good one:. Total earned so far: $5425.
4
6
104
@YourFinalSin
3NVZ
10 days
Day 131 - Bug Bounty. - Did a full day of manual hunting, focusing on critical features.- Was able to find one interesting issue.- Started looking more into GitHub Dorking and this was a nice introduction:. Total earned so far: $5425.
3
5
123
@YourFinalSin
3NVZ
12 days
2/2.
0
2
16
@YourFinalSin
3NVZ
12 days
Day 130 - Bug Bounty. - One report came back as duplicate.- Was this 🤏 close to 2 ATOs on different programs, but wasn't able to exploit both because of only 1 missing gadget - That was painful.- Went deep into OAuth and found this helpful:👇. Total earned so far: $5425. 1/2.
3
4
88
@YourFinalSin
3NVZ
12 days
Day 129 - Bug Bounty . - Focused on logic bugs today and found some interesting behavior.- Went deep manually into single flows.- Continued reviewing code on an open-source PHP application . Total earned so far: $5425.
3
0
127
@YourFinalSin
3NVZ
13 days
Day 128 - Bug Bounty. - Found multiple issues in an open-source project with over 50k installations .- Also went hunting and focused mainly on auth.- So far code reviews have been hard to monetize . Total earned so far: $5425.
4
0
139
@YourFinalSin
3NVZ
17 days
Day 127 - Bug Bounty. - Did full day of code review today.- Focused on an open-source project with over 200k installations.- Played around with taint-analysis and was able to find 2 interesting gadgets. Total earned so far: $5425.
7
3
140
@YourFinalSin
3NVZ
18 days
Day 126 - Bug Bounty . - Another bounty came in 🎉🎉.- Went deep today in regex and code review.- The bounty was a logic issue in the main application on a public program. Total earned so far: $5425
Tweet media one
21
6
383
@YourFinalSin
3NVZ
19 days
Tweet media one
0
0
28
@YourFinalSin
3NVZ
19 days
Day 125 - Bug Bounty. - Hit finally that juicy P1/Crit - It paid off focusing only on impactful vulns🎉🥳.- This is a huge milestone for me and I was able to hit all my goals for my 1st year bug bounty hunting, I set myself.- It was a 0-Click ATO. Total earned so far: $4525
Tweet media one
48
12
406
@YourFinalSin
3NVZ
20 days
Day 124 - Bug Bounty. - Kept hunting on a target today and played around with CodeQL.- Learned about Server-Side Prototype Pollution .- Found these resources to be a nice introduction to SSPP:. Total earned so far: $2525.
2
8
83
@YourFinalSin
3NVZ
21 days
Day 123 - Bug Bounty. - Kept focusing on higher impact vulnerabilities only.- Went deeper into all types of parsing issues.- While researching email parsing I found this talk which I think is extremely underrated:. Total earned so far: $2525.
2
6
112
@YourFinalSin
3NVZ
22 days
Day 122 - Bug Bounty. - One report came back as duplicate.- Focused on authentication .- Went through ~30 H1 Hacktivity reports and found this blog post:. Total earned so far: $2525.
2
5
90
@YourFinalSin
3NVZ
24 days
Day 121 - Bug Bounty . - Wasted 9 hours on CodeQL today. Pain.- Tomorrow will be better hopefully.- If someone is dealing with some issues, this might help:. Total earned so far: $2525.
0
14
118
@YourFinalSin
3NVZ
25 days
Day 120 - Bug Bounty . - Got 2 duplicates today and 1 triaged .- Started a new target which I will focus on the next 30 days.- Decided I will go very deep feature by feature. Total earned so far: $2525.
7
2
101
@YourFinalSin
3NVZ
28 days
Day 119 - Bug Bounty . - Today again 2 reports came back as duplicate .- I duplicated on the initial submitter by ~8h.- Will start focusing on high/crit only and see how it'll go . Total earned so far: $2525.
3
0
67