Erick Fernando Profile
Erick Fernando

@erickfernandox

Followers
852
Following
112
Media
14
Statuses
54

https://t.co/qju40dBXtK

Brazil
Joined May 2011
Don't wanna be here? Send us removal request.
@erickfernandox
Erick Fernando
24 seconds
Yay, I was awarded a $10,000 bounty on @Hacker0x01! . My First Five Digits on @Hacker0x01 . #TogetherWeHitHarder
Tweet media one
0
0
0
@erickfernandox
Erick Fernando
2 days
Host Header Injection🤝Cache Poisoning 🤝 Path Traversal = Stored XSS via Path Confusion❤️. #bugbounty #intigriti
Tweet media one
4
9
157
@erickfernandox
Erick Fernando
2 days
RT @H4ckmanac: 🚨Chrome Zero-day Alert: PATCH NOW‼️. Google released an emergency security update for Chrome to patch CVE-2025-6558, a high-….
0
46
0
@erickfernandox
Erick Fernando
2 days
RT @NahamSec: This Tiny JWT Mistake = Massive Bug Bounty (with a real world example!) . watch here 👉🏼 https://t.co/….
0
49
0
@erickfernandox
Erick Fernando
1 month
Yay, I was awarded a $2,000 bounty on @Hacker0x01! .High Impact on Amazon!.#TogetherWeHitHarder
Tweet media one
1
4
128
@erickfernandox
Erick Fernando
1 month
Always try to escalate an XSS to ATO. The program did not accept XSS but with 1-Click ATO it went to critical. #bugbounty #hackerone
Tweet media one
6
9
203
@erickfernandox
Erick Fernando
2 months
Full Account Takeover via Open Redirect in the Authentication Flow using an OOS Open Redirect I had found 1 year ago. #Hackerone #BugBounty
Tweet media one
4
5
112
@erickfernandox
Erick Fernando
5 months
In January, I submitted 40 vulnerabilities to 35 programs on @Hacker0x01. #TogetherWeHitHarder
1
0
41
@erickfernandox
Erick Fernando
6 months
Another contribution to the security of the global open-source community:.CVE-2025-0557 - Vulnerability identified in Alfresco.
Tweet media one
0
0
27
@erickfernandox
Erick Fernando
7 months
RT @CVEnew: CVE-2024-49505 A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in openSUSE….
0
1
0
@erickfernandox
Erick Fernando
8 months
Today I received a bounty from @intigriti with the most random vulnerability I've ever found, an SSRF Request Stored via Cache Poisoning. #bugbounty #intigriti
Tweet media one
6
10
142
@erickfernandox
Erick Fernando
9 months
If the WAF doesn't allow the creation of a JavaScript term like 'alert' or 'confirm' in any way, write it inverted and then use reverse() with self[]. Payload:. <a%20href=%0dj&Tab;avascript&colon;x='trela'.split('').reverse().join('');self[x](origin)>. #Bugbounty #AkamaiBypass
Tweet media one
13
161
672
@erickfernandox
Erick Fernando
1 year
Just got a reward for a high vulnerability submitted on @yeswehack -- Cross-site Scripting (XSS) - Stored (CWE-79). #YesWeRHackers
Tweet media one
1
1
57
@erickfernandox
Erick Fernando
1 year
According to the CVE-2024-4956 - Path Traversal in Nexus Repository is the most discussed in the world in the last 48 hours!
Tweet media one
0
6
39
@erickfernandox
Erick Fernando
1 year
RT @CVEShield: Top 5 Trending CVEs:. 1 - CVE-2024-4985. 2 - CVE-2024-21683. 3 - CVE-2020-17519. 4 - CVE-2024-4956. 5 - CVE-2….
0
5
0
@erickfernandox
Erick Fernando
1 year
Since the exploit for CVE-2024-4956 has already been leaked on Twitter, I have written a detailed explanation of the CVE payload on my GitHub, including the PoC and the Nuclei template.
Tweet media one
8
67
322
@erickfernandox
Erick Fernando
1 year
RT @HunterMapping: 🚨Alert🚨CVE-2024-4956:Nexus Repository Flaw Exposed, Software Supply Chains Threatened.⚠This vulnerability, discovered an….
0
28
0
@erickfernandox
Erick Fernando
1 year
I found my CVE-2024-4956 - Unauthenticated Path Traversal in Nexus Repository 3 in several Bug Bounty programs!. #bugbounty #cve #pathtraversal #hackerone #bugcrowd #intigriti
Tweet media one
Tweet media two
10
19
255
@erickfernandox
Erick Fernando
1 year
RT @CVEnew: CVE-2024-4956 Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. Fixed in v….
0
2
0
@erickfernandox
Erick Fernando
1 year
Yay, I was awarded a $6000 bounty on.@Hacker0x01.! #togetherwehitharder #bugbounty #hackerone
Tweet media one
0
0
17