Th4m1 Profile Banner
Th4m1 Profile
Th4m1

@justcacheme

Followers
904
Following
3
Media
30
Statuses
466

hacker.

Joined November 2022
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
Pinned Tweet
@justcacheme
Th4m1
2 months
My methodology: (after re-watching naffy & m.litchefield's interviews so many times) 1. Click every button 2. Go to History and look for interesting request 3. Send it to the playground (REPEATER) [Golden Tool] 4. Fuck up the request, give it your all!!! #bugbountytips
2
13
56
@justcacheme
Th4m1
5 months
As soon as its triaged I am doing my first writeup, bookmark this. #bugbountytips #BugBounty
Tweet media one
11
9
162
@justcacheme
Th4m1
5 months
Now I am working for real #bugbountytip #bugbounty
Tweet media one
10
3
122
@justcacheme
Th4m1
5 months
Another one, a very interesting SSRF allowed me to port scan internal host. #bugbounty #bugbountytip
Tweet media one
4
3
114
@justcacheme
Th4m1
4 months
If you don't feel like doing manual hacking, fuzz until you get something.
Tweet media one
9
5
110
@justcacheme
Th4m1
4 months
I started Bug Bounty in 2019, had no luck until late last when I started realizing I wasn't taking hacking seriously. Now I know, the more you show up, start Burp / ZAP and hunt... you will def WIN if you put in the work!!! #bugbountytip #bugbounty
6
5
107
@justcacheme
Th4m1
4 months
Tweet media one
2
2
107
@justcacheme
Th4m1
7 months
3 hours in 👨🏿‍💻 #BugBounty
Tweet media one
6
4
93
@justcacheme
Th4m1
10 months
Found a token leak via an IDOR but I cannot find its purpose (endpoint: /checkPaymentStatus), anyone who is willing to collab? #BugBounty #bugbountytips
Tweet media one
18
7
75
@justcacheme
Th4m1
7 months
Let's change this! 💪 ⚒
Tweet media one
4
1
60
@justcacheme
Th4m1
6 months
Tweet media one
Tweet media two
Tweet media three
6
1
58
@justcacheme
Th4m1
5 months
Dropped out of Varsity to do this shit full time. Its a risk I am willing to take and I know it requires HARD WORK! #bugbounty #bugbountytip
Tweet media one
2
3
60
@justcacheme
Th4m1
5 months
The Secret is Consistency, Now I see! #bugbounty #bugbountytip
Tweet media one
4
2
60
@justcacheme
Th4m1
7 months
#bugbounty Just found an account takeover using this Information. Just add this smart man to your follower's list. Thank you @Jayesh25_ for insightful knowledge🫡
@Jayesh25_
Jayesh Madnani
8 months
Since I'm receiving a lot of questions; Here's how you can disallow sharing email when using Login with Facebook: (1) Login with Facebook to any app (2) Click "Edit Access" (3) Uncheck email address checkbox (4) `Continue`
Tweet media one
5
25
141
5
5
50
@justcacheme
Th4m1
11 months
Some bug bounty programs are not serious🫥
Tweet media one
1
2
49
@justcacheme
Th4m1
11 months
Beginners, lets practice sending in those reports!💪🏿 #bugbountytips
Tweet media one
4
0
47
@justcacheme
Th4m1
7 months
bro, dirsearch is the best tool ever created. #BugBounty
7
1
38
@justcacheme
Th4m1
4 months
Working 💻 #bugbounty
Tweet media one
1
0
31
@justcacheme
Th4m1
2 months
just got kicked out of at home because this "bug bounty" thing of money doesn't work🥲. its sad to have unsupportive parents😭 #BugBounty
5
2
30
@justcacheme
Th4m1
3 months
If there's one man that changed my life, It would be @NahamSec . I appreciate you so much man. Things you have done for this community will never be forgotten 🙏🏾
1
0
26
@justcacheme
Th4m1
1 year
Thank you God 🙏🏾 #bugbounty @Bugcrowd
Tweet media one
1
0
26
@justcacheme
Th4m1
2 months
My best friend ♥️ #bugbounty
Tweet media one
3
1
27
@justcacheme
Th4m1
6 months
Tweet media one
2
0
26
@justcacheme
Th4m1
5 months
if I find a time-based SQLi but cannot exploit it on SQLMap, does that make it "Not-Applicable"? #BugBounty
13
0
27
@justcacheme
Th4m1
3 months
One of the best writeups I've read this year🤞🏼
0
4
21
@justcacheme
Th4m1
3 months
gents u not doing anything if you don't have so many tabs open! 🤞🏾 #BugBounty
@HusseiN98D
Hussein Daher
11 months
Successfully bypassed a SSRF WAF by using a combination of IPV6 + Unicode. Payload for Metadata instances: http://[::ⓕⓕⓕⓕ:①⑥⑨。②⑤④。⑯⑨。②⑤④]:80 Check images for response difference between 169.254.169.254 and the above payload I shared 🔥 #bugbounty #infosec #waf
Tweet media one
Tweet media two
56
524
2K
0
1
17
@justcacheme
Th4m1
8 months
Night owl 🦉 . Hacking web apps. #bugbounty
Tweet media one
0
2
14
@justcacheme
Th4m1
4 months
who hunts successfully without a proxy tool? I am asking for myself, i think I am less productive with them🥲 #bugbounty #bugbountytip
1
0
12
@justcacheme
Th4m1
2 months
Does Weed slow down your productivity hunters? #bugbounty
12
0
12
@justcacheme
Th4m1
3 months
the more you hack, the more you refine your hacking process and eventually discover your own hacking methodology. #bugbountytips #bugbounty
1
0
11
@justcacheme
Th4m1
5 months
@bug4you Spotted a ?url= parameter the tried my burp collab link Tested again with local IP and fuzzed the ports for the IP then you check response length and the response itself Sometimes this can land you on an internal admin portal
2
0
11
@justcacheme
Th4m1
3 months
After years of confusion and wasting time. I am really starting to enjoy testing apps. Tip: Open Burp and try to manipulate an application EVERY FU*KN DAY!!! #bugbountytips #bugbounty
2
3
10
@justcacheme
Th4m1
5 months
The way I see it, everyone has their own kind of style of hacking, that's why you always have to approach an application as if its new. With the same request I just looked at and found an IDOR you might find a bug I never thought of. #bugbountytip #bugbounty
1
0
10
@justcacheme
Th4m1
4 months
@uMdaliWethu I use intruder bro, I know ffuf is fast but I like to stay inside burpsuite.
2
0
8
@justcacheme
Th4m1
3 months
I hack better with Burp Intercept feature and Repeater. I usually do look at History unless there's a specific request I am looking for. I just like to rip off the application in real time. #BugBounty #bugbountytip
0
0
8
@justcacheme
Th4m1
3 months
Hacking can be lonely, watch a podcast while deep diving 😉 #bugbounty #bugbountytips
Tweet media one
2
0
7
@justcacheme
Th4m1
3 months
This is one of the reasons why I'll forever support Burpsuite, is the best. #BugBounty
@XCTrypt
Frey
3 months
Thank you for all the free resources @WebSecAcademy I am always grateful to all the platforms/people for giving knowledge for FREE. That's why I also share what I learn for Free it's like I give back what I have taken from the Internet.
Tweet media one
2
5
48
0
0
6
@justcacheme
Th4m1
7 months
big tip:
@zack0x01
Zack
7 months
@th4m1_hacker @a4hamkhan I started finding bugs when i stopped focusing on recon , and focus instead on app functions
1
1
5
0
1
6
@justcacheme
Th4m1
9 months
Read every post / writeup/ video with appreciation. You will learn 📙 effectively when you appreciate every bit of information 🧠 that's been provided to you. Let's appreciate those who share their experiences to teach us as a community ♥ #bugbountytip #bugbounty
0
0
5
@justcacheme
Th4m1
3 months
🥲its part of the game. #bugbounty
Tweet media one
0
0
5
@justcacheme
Th4m1
6 months
Do u use a checklist when looking for bugs? #bugbounty #bugbountytips
yes
28
no
48
1
0
4
@justcacheme
Th4m1
1 year
@Bugcrowd This time I won't give up. With the effort I am putting, I will make it in Bug Bounty🤞🏾
0
0
4
@justcacheme
Th4m1
4 months
@hbenja_m congrats bro! 🍾
0
0
4
@justcacheme
Th4m1
1 year
Here I used Forced Browsing to bypass JavaScript Authentication. A Simple bug got me a $100 bounty. Thank you @Bugcrowd for the great platform🫡
Tweet media one
Tweet media two
0
1
4
@justcacheme
Th4m1
2 years
🏝 First Day being a Bug Bounty Hunter🧩, I’m ready, let’s 👨🏾‍💻HACK together DM me #bugbountytips #BugBounty
Tweet media one
1
1
4
@justcacheme
Th4m1
6 months
@_public_void Thank you so much bro 🙏🏾
1
0
1
@justcacheme
Th4m1
8 months
@code_carol you can also learn it to make money as a bug bounty hunter.
0
0
1
@justcacheme
Th4m1
3 months
Hmmm never thought about this🤔
@DanaEpp
@ddǝɐuɐp
3 months
@AlanBailward @Jhaddix Nmap hard forces a close on its stealth / half scan, and performs faster than Naabu does in that regard, at least in my tests. But it’s moot. I don’t want to use raw sockets and require root privs just to do a scan. Naabu seems faster when doing the full CONNECT. So when
0
0
3
0
0
3
@justcacheme
Th4m1
5 months
@Debug44759572 i didn't even notice i closed DMs, dm me bro
0
0
3
@justcacheme
Th4m1
9 months
Secret To Win in #BugBounty
@elldeeboo2
Ahmed ElDeeb
9 months
Work on a program for 9 months , The result is a good understanding of the site, despite the number of 9,000 vulnerabilities reported I am still able to report critical reports happy hunting $$$$$ 🔥
Tweet media one
Tweet media two
Tweet media three
14
9
170
0
0
3
@justcacheme
Th4m1
3 months
@R007_BR34K3R @Bugcrowd Great idea bro, We need to add report examples now for each Vuln type.
0
0
3
@justcacheme
Th4m1
7 months
We see less of these, I am super inspired!🤞🏿
@Fabrikat0r
$mit
7 months
Got new Car 😘😁 Thanks #bugbounty
Tweet media one
39
1
263
1
0
3
@justcacheme
Th4m1
7 months
This thing is classic!🤞🏿
0
0
2
@justcacheme
Th4m1
3 months
@Neo__Hq @Cobratate YOU TAUGHT ME A LOT BROTHERS, I AM AWAKE BECAUSE OF YOU. NOW I SEE WHAT IS HAPPENING IN THIS CRAZY WORLD. THANK YOU🙏🏿🙏🏿🙏🏿
0
0
2
@justcacheme
Th4m1
7 months
Tweet media one
0
0
2
@justcacheme
Th4m1
6 months
1
0
2
@justcacheme
Th4m1
5 months
@haryanaala302 😂 I get them too my friend, I really suggest looking for bugs that most people are scared to look for.
1
0
2
@justcacheme
Th4m1
7 months
@zack0x01 @a4hamkhan i agree with you bro, focusing on functionality really yields bugs🤞🏿
0
0
2
@justcacheme
Th4m1
5 months
0
0
1
@justcacheme
Th4m1
9 months
🌩️ZAP will be part of my arsenal, forever and ever Amen!
3
0
2
@justcacheme
Th4m1
4 months
@AhmedMa07846126 use an external browser such as FireFox (don't delay your work)
0
0
1
@justcacheme
Th4m1
10 months
ZAP or Burp?🤔
2
0
2
@justcacheme
Th4m1
1 year
@Bugcrowd Recon hacker
0
0
2
@justcacheme
Th4m1
9 months
@naglinagli beautiful bro😍
0
0
0
@justcacheme
Th4m1
1 year
1st bug in a while😭🙏🏿 #BugBounty #bugbountytip
Tweet media one
0
0
2
@justcacheme
Th4m1
3 months
@patelbhavin_ @Jhaddix did u eventually manage to crack this?
0
0
0
@justcacheme
Th4m1
3 months
0
0
2
@justcacheme
Th4m1
2 months
@Sazouki_ Very true my friend
0
0
2
@justcacheme
Th4m1
1 year
0
0
2
@justcacheme
Th4m1
3 months
@MrSharmax_ Me 2 brother
0
0
1
@justcacheme
Th4m1
1 year
@fattselimi True bro, and i find the most juicy endpoints from using google dorking
0
0
1
@justcacheme
Th4m1
10 months
0
0
1
@justcacheme
Th4m1
6 months
@swehtpantz they were on Bugcrowd earlier this year
1
0
1
@justcacheme
Th4m1
7 months
@GokTest FFUF is fast but requires carefully curated wordlists, with dirsearch you find juicy endpoints with its default worldist. ffuf is great but I love dirsearch.
0
0
1
@justcacheme
Th4m1
5 months
@uMdaliWethu Gauteng my G
1
0
1
@justcacheme
Th4m1
5 months
its down on my side too😥
@shreyas_chavhan
Shreyas Chavhan
5 months
Is hackerone down today? @Hacker0x01 Have been trying for the past few hours. #BugBounty
Tweet media one
Tweet media two
12
0
30
1
0
1
@justcacheme
Th4m1
6 months
@AkashHamal0x01 P1 In 5 sec
0
0
1
@justcacheme
Th4m1
7 months
@0xRh1d0Y @Hacker0x01 Congrats bro 👌
1
0
1
@justcacheme
Th4m1
7 months
@mamunwhh Trust me it's better than nothing 🤞
1
0
1
@justcacheme
Th4m1
11 months
Reinstalling Parrot as my main OS👨🏿‍💻 It keeps me FOCUSED
0
0
1
@justcacheme
Th4m1
4 months
How many Hunters use ZAP⚡️? #bugbountytip #bugbounty
0
0
1
@justcacheme
Th4m1
8 months
Grim 1. You were born in a cold prison, it is your country, your state. 2. You have to pay for the prison stay, they call the prison fees taxes. 3. You have no say what will be done with the money, but you have to pay. 4. To pay the money you have to work.
6
0
1
@justcacheme
Th4m1
5 months
@cesc0sec @intigriti You are really good brother, what type of bugs are you looking for?
1
0
1
@justcacheme
Th4m1
3 months
@Moblig_ its better they were fair and paid equal bounties
0
0
1
@justcacheme
Th4m1
1 year
0
0
1
@justcacheme
Th4m1
2 months
@zseano Thank you so much for this Sean 🙏🏾. I think I'm going to leave weed for a moment. It's been 2 days sober and I feel energetic. Even went for a long run today.
1
0
1
@justcacheme
Th4m1
8 months
@Jayesh25_ I love u bro!
0
0
1
@justcacheme
Th4m1
1 year
@3nc0d3dGuY this is good bro, hackers often forget to fuzz backwards (especially us new hackers). Congrats on this dope brother!
0
1
1
@justcacheme
Th4m1
4 months
@GokTest thank you bro you really helped me, I was addicted to these proxy tools and was lacking productivity these past weeks. Thank again mate!, I am already fuzzing as we speak😁
0
0
1
@justcacheme
Th4m1
9 months
morning hunters, lets secure the 🌍 #bugbountytips #BugBounty #CyberSecurity
0
1
1
@justcacheme
Th4m1
7 months
@Jhaddix @Masonhck3571 @owasp How to use Hunt on OWASP ZAP?
0
0
0