charan Profile
charan

@0xcharan

Followers
1,400
Following
317
Media
47
Statuses
3,761

bug bounty hunter | Bsc(Hons) science graduate | CEHv12 certified | eCPPTv2 certified |

Rajahmundry, India
Joined November 2020
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
Pinned Tweet
@0xcharan
charan
3 months
Thrilled to announce that I've achieved a milestone of 1000 reputation points on @Hacker0x01 Grateful for the journey and excited for what's next. #HackerOne #bugbounty
Tweet media one
5
0
44
@0xcharan
charan
2 years
In June, I submitted 8 vulnerabilities to 5 programs on @Hacker0x01 .Earned more than 5000 dollars able to pay my college fees 🥺 thanks @Hacker0x01 #TogetherWeHitHarder #bugbounty
Tweet media one
15
19
323
@0xcharan
charan
2 months
Smashed it with @0xdln and @0xmarvelmaniac ! 🚀 $24K for 8 SQLi bugs at @Hacker0x01 . #TogetherWeHitHarder 💪
@0xmarvelmaniac
Ashutosh
2 months
Yay, @0xcharan @0xdln and I earned a total of $24,000 on @Hacker0x01 for submitting 8 SQL injection issues to a private program! Few SQLis were found by burp scan😅and we had to create a custom burp extension to find the rest on the program. WriteUp soon! #TogetherWeHitHarder
Tweet media one
23
17
353
12
3
157
@0xcharan
charan
2 years
Thanks @Bugcrowd tshirt is so cool
Tweet media one
1
1
109
@0xcharan
charan
2 months
Yay, Me and @0xmarvelmaniac earned $7000 in just one week by collaborating on a private program at @HackerOne #TogetherWeHitHarder
10
2
94
@0xcharan
charan
2 months
In April, I submitted 74 vulnerabilities to 37 programs on @Hacker0x01 . #TogetherWeHitHarder
11
2
63
@0xcharan
charan
3 years
@ADITYASHENDE17 Use this python script loop in bash for scanning multiple domains
0
14
49
@0xcharan
charan
2 years
Received sony swag Thanks @ADITYASHENDE17
Tweet media one
Tweet media two
2
0
29
@0xcharan
charan
1 year
@intigriti taxi driver
2
1
23
@0xcharan
charan
7 months
In November, I submitted 32 vulnerabilities to 21 programs on @Hacker0x01 . #TogetherWeHitHarder
1
0
21
@0xcharan
charan
3 years
There are lot of people but I mostly inspired from this persons thanks to @sunilyedla2 @4z1zu @ADITYASHENDE17 @0xMstar @_jensec @remonsec @sillydadddy @GodfatherOrwa @GochaOqradze @_justYnot for sharing your knowledge to community I found myself on @Hacker0x01 leaderboard
Tweet media one
Tweet media two
Tweet media three
5
0
19
@0xcharan
charan
1 year
Had some awesome bug bounty chitchat with @0xdln ! 🐛💻
Tweet media one
3
3
18
@0xcharan
charan
6 months
@intigriti intigriti support portal
0
0
12
@0xcharan
charan
2 years
@disnhau @ADITYASHENDE17 @Ahmad_Halabi_ :"" ssl:"" these dorks i use regularly apart from that you can use net:103.36.5.64/27 for cidr
0
2
10
@0xcharan
charan
2 months
@sk1dd13 better, CTF Player in bug bounties
1
0
12
@0xcharan
charan
2 years
@h4x0r_dz How many vuln you got with this ?
3
0
11
@0xcharan
charan
9 months
In September, I submitted 15 vulnerabilities to 12 programs on @Hacker0x01 . #TogetherWeHitHarder
0
1
9
@0xcharan
charan
2 years
@sillydadddy Use dirsearch to it's fullest example use suffix and prefix in dirsearch like adding *,@,; to bypass 403 or 401 errors and it can be used for path traversal too 😉
0
1
9
@0xcharan
charan
8 months
@0x_rood as long as companies are paying, anyone can report anything :)
0
0
9
@0xcharan
charan
2 years
0
0
8
@0xcharan
charan
3 years
@sherlocksecure @PentesterLab Always check for race condition vulnerability on web hooks many test for ssrf on web hooks but not race condition got my first bounty on bugcrowd for this
2
0
7
@0xcharan
charan
3 years
@PrettyRecon Custom templates for scanning for cves like that
2
0
7
@0xcharan
charan
8 months
@IamRenganathan i deleted Linkedin because of these if i see something like that i will lose myself 😤
2
0
7
@0xcharan
charan
3 years
Yay, I was awarded a $150 bounty on @Hacker0x01 ! #TogetherWeHitHarder
0
0
7
@0xcharan
charan
3 months
@Bugcrowd request smuggling
0
0
6
@0xcharan
charan
3 years
@intigriti 🌀 HYPNOSIS ATTEMPT 🌀 😵‍💫 😵‍💫 😵‍💫 😵‍💫 you will 😵‍💫 Give me a bounty 😵‍💫 😵‍💫 😵‍💫 😵‍💫 😵💫
1
0
5
@0xcharan
charan
10 months
@ITSecurityguard after the 8th month back to again 1st month 🥲
0
0
5
@0xcharan
charan
2 years
@ADITYASHENDE17 @Ahmad_Halabi_ Shodan gave cool bugs for me from time to time worth it
1
1
6
@0xcharan
charan
2 years
0
0
6
@0xcharan
charan
2 years
@akincibor1 He should be award with bonus and you should get actually bounty
0
0
6
@0xcharan
charan
5 months
In January, I submitted 8 vulnerabilities to 8 programs on @Hacker0x01 . #TogetherWeHitHarder
0
0
6
@0xcharan
charan
2 years
@infosec_au @assetnote Yesterday got bounty with your wordlist only 😊
0
0
6
@0xcharan
charan
3 years
@AkshayKerkar13 @coder_rc Use xssvalidator for better results
0
0
5
@0xcharan
charan
3 years
@cyph3r_asr @huntrdev Black hat 🤣😂
2
0
4
@0xcharan
charan
2 years
@GodfatherOrwa How you manage time and how many hours you spend hunting and learn new things
0
0
4
@0xcharan
charan
2 years
In May, I submitted 6 vulnerabilities to 4 programs on @Hacker0x01 . #TogetherWeHitHarder
0
0
5
@0xcharan
charan
1 year
@HackenProof burp suite pro
0
0
5
@0xcharan
charan
2 years
@MoizSid09 @Hacker0x01 In india it is so costly bro as i am studying professional degree🥲😥
0
0
5
@0xcharan
charan
1 year
@HackenProof Just don't do it for bounties have fun and enjoy the process and remember this will take time ;)
0
1
5
@0xcharan
charan
1 year
@manash036 try hackscale
1
0
5
@0xcharan
charan
2 months
@NahamSec Manual hacking is more fun for sure
0
0
5
@0xcharan
charan
3 years
@sunilyedla2 Telugu hackers 💪💪
1
0
5
@0xcharan
charan
2 months
@Mdhsan19 i know about it, it is public info bth :)
3
0
5
@0xcharan
charan
3 months
@0x_rood arjun has a lot of bugs, use x8 it is perfect
0
0
4
@0xcharan
charan
2 months
@0xdln @0xmarvelmaniac let's not forget we have 10 more issues to be paid out 🎉🎉
1
0
4
@0xcharan
charan
4 years
@noob3xploiter I think you're an Indian
1
0
3
@0xcharan
charan
2 years
@AkashHamal0x01 Funny 😂😂 send to bugcrowd meme challenge it will be nice meme
0
0
4
@0xcharan
charan
2 years
@ADITYASHENDE17 Whenever i try to hunt for ssrf i will find some other issues instead of ssrf i don't why 😅
0
0
4
@0xcharan
charan
2 months
@bugoverfl0w @Hacker0x01 Thanks bro, daily i spent 3 hours only except sat and sun and only half of that submission were manual rest are automated only
1
0
4
@0xcharan
charan
2 months
@krishnsec Bug bounty is scam 🙃
0
0
4
@0xcharan
charan
2 years
@rez0__ @Jhaddix Which language do you suggest for recon scripts ?
1
0
4
@0xcharan
charan
10 months
@brutelogic looking for a sql cheatsheet
1
0
3
@0xcharan
charan
1 year
@harshbothra_ @Hacker0x01 , quick payouts, faster responses and great support
0
0
4
@0xcharan
charan
9 months
@GodfatherOrwa @bsidesahmedabad really informative 🔥🔥
0
0
3
@0xcharan
charan
1 year
@payloadartist all of my reports are 30 words long only 😅
0
0
4
@0xcharan
charan
2 years
@NahamSec Giveaway 1000 pentesterlab subs
0
0
4
@0xcharan
charan
1 year
@NahamSec notamalware.exe
0
0
4
@0xcharan
charan
3 years
@IamRenganathan Shodan and github always leads to interesting results
1
0
4
@0xcharan
charan
10 months
@HusseiN98D forgot about the shared environment imagine you got admin panel access and you noticed many blind xss payloads 🥲
2
0
4
@0xcharan
charan
2 years
@Br0k3n_1337 @Hacker0x01 Hi bro which bug ? I too hunted on mongodb i am somewhere in that leaderboard 😅
1
0
4
@0xcharan
charan
8 months
@bxmbn they should provide a different environment similar to sensitive assets in case our testing may cause harm it is a program fault for sure
0
0
4
@0xcharan
charan
1 year
@Bugcrowd and you N/A them 😤
0
0
4
@0xcharan
charan
1 year
@krishnsec please share all your poc's sir 😬
0
0
4
@0xcharan
charan
8 months
@bug_vs_me These ones do the job better, echo 17.0.0.0/16 | mapcidr -silent | dnsx -ptr -resp-only -o output.txt
0
2
4
@0xcharan
charan
8 months
@Jayesh25_ hi, do you have anything to share for rce issues ?
1
0
4
@0xcharan
charan
4 months
@RootxRavi @recon_sage good tool and UI looks pretty cool :)
1
0
4
@0xcharan
charan
2 years
@GodfatherOrwa @Masonhck3571 AT&T good for practice not for bounties 😅
0
0
3
@0xcharan
charan
2 years
@Bugcrowd Learning Bounty
0
0
4
@0xcharan
charan
3 years
@Bugcrowd Blind ssrf -because sometimes it is very hard and challenging it is hard to know the IP address really belong to target asset or it is out of scope And bussiness logic bugs-it required deep understanding of how target works And other blind based bugs too. 😨
1
0
3
@0xcharan
charan
1 year
@gowtham_ponnana data breach face chese dhaka elage untaru
1
0
4
@0xcharan
charan
1 year
@bug_vs_me great for students
0
0
4
@0xcharan
charan
10 months
@Masonhck3571 Are you planning to enter into UFC ?
0
0
0
@0xcharan
charan
2 years
@R29k_ @NeolexSecurity You can't find bugs in stress first get out of the stress and then start again with hunter instinct
0
0
4
@0xcharan
charan
9 months
@errorsec_ burp pro
1
0
3
@0xcharan
charan
2 years
@PrettyRecon Subdomain permutation
1
0
3
@0xcharan
charan
17 days
@errorsec_ @HarshDRanjan1 What about your challenge? 👀
2
0
2
@0xcharan
charan
2 years
@Virdoex_hunter @e11i0t_4lders0n Baki hanma is underrated yujiro character was 🔥
1
0
3
@0xcharan
charan
9 months
@zseano check dm
0
0
0
@0xcharan
charan
1 year
@Masonhck3571 switch to Caido
0
0
3
@0xcharan
charan
8 months
@Jayesh25_ hi @Jayesh25_ but these http hits do not mean ssrf right ? what are the best ways to show impact to triagers ?
1
0
3
@0xcharan
charan
2 years
@tabaahi_ Due to stress now i am using medicines for that we should always prioritize our health first learned in hard way 😓
1
0
3
@0xcharan
charan
1 year
@bxmbn mate i heard it is currently not a good platform due to the fact their target websites take minutes to load due to vpn's 💩
0
0
3
@0xcharan
charan
1 year
@sw33tLie his all tweets are like that only @sw33tLie 😂
0
0
3
@0xcharan
charan
2 years
@NahamSec @shodanhq Ssl:"" http.title:admin
0
0
3
@0xcharan
charan
11 months
@devangsolankii @intidc @intigriti mine was triaged as crit and least was high why it is medium ?
1
0
3
@0xcharan
charan
28 days
@hetmehtaa Common sense
1
0
3
@0xcharan
charan
2 years
@GodfatherOrwa @Bugcrowd @Mohamed87Khayat Dom xss required understanding for js how you managed t get dom xss ?
0
0
2
@0xcharan
charan
3 years
@sillydadddy @sunilyedla2 1) what are the most common bugs that you encounter 2)tips for csrf and most common csrf bypass that you use 3)tips for ssrf and idor Thanks in advance
2
0
3
@0xcharan
charan
22 days
@deadvolvo @Bugcrowd True, they generally have a hard time reproducing cache or request smuggling issues.
0
0
3
@0xcharan
charan
1 year
@krishnsec even with active subdomain enumeration and permutation it will take less than 3 hours in our 5 dollars vps :(
0
0
3