Ashutosh Profile Banner
Ashutosh Profile
Ashutosh

@0xmarvelmaniac

Followers
1,100
Following
193
Media
13
Statuses
471
Explore trending content on Musk Viewer
Pinned Tweet
@0xmarvelmaniac
Ashutosh
25 days
Just got the UK visa! Will be attending #h10131 in-person at Edinburgh, Scotland! So excited to meet the amazing hackers and see their work live!!! Thanks for the invite @Hacker0x01
Tweet media one
7
1
80
@0xmarvelmaniac
Ashutosh
5 months
Yay, @0xcharan @0xdln and I earned a total of $24,000 on @Hacker0x01 for submitting 8 SQL injection issues to a private program! Few SQLis were found by burp scan😅and we had to create a custom burp extension to find the rest on the program. WriteUp soon! #TogetherWeHitHarder
Tweet media one
23
19
349
@0xmarvelmaniac
Ashutosh
1 year
Yay I found a critical on Reddit and got my highest bounty so far in 2 years :) #BugBounty #Bounty #togetherwehitharder
Tweet media one
21
3
248
@0xmarvelmaniac
Ashutosh
9 months
Finally received my 100th bounty on @Hacker0x01 ! My current bounty average to date is $924.96 :) #bugbounty #bugcrowd #hackerone
Tweet media one
Tweet media two
14
2
114
@0xmarvelmaniac
Ashutosh
9 months
@disclosedh1
publiclyDisclosed
9 months
HackerOne disclosed a bug submitted by @maniacmarvel_ : - Bounty: $2,500 #hackerone #bugbounty
Tweet media one
1
8
62
3
10
70
@0xmarvelmaniac
Ashutosh
5 months
Stats of the issues submitted and the respective bounties: 1 x critical = $3k 2 x high = 2 x $1.5k 2 x medium = 2 x $500 #BugBounty #hacking #bounty
@0xcharan
charan
5 months
Yay, Me and @0xmarvelmaniac earned $7000 in just one week by collaborating on a private program at @HackerOne #TogetherWeHitHarder
10
3
96
7
2
67
@0xmarvelmaniac
Ashutosh
7 months
I have disclosed an IDOR report submitted to Linkedin on @Hacker0x01 . The bounty paid was $2500 which is a good amount I do agree but according to their bounty table it is the lowest high severity bounty they pay. The CVSS score of the issue was 8.2 :)
@disclosedh1
publiclyDisclosed
7 months
LinkedIn disclosed a bug submitted by @0xmarvelmaniac : #hackerone #bugbounty
Tweet media one
1
7
44
3
5
59
@0xmarvelmaniac
Ashutosh
1 year
I have finally crossed 2000 reputation points on @Hacker0x01 #TogetherWeHitHarder #BugBounty #hacker
Tweet media one
4
2
51
@0xmarvelmaniac
Ashutosh
10 months
Tweet media one
5
0
51
@0xmarvelmaniac
Ashutosh
2 months
Making your first $100k is tough. After that making your first $1M is tough I guess. #BugBounty
0
0
41
@0xmarvelmaniac
Ashutosh
2 years
Hi everyone ! I wrote about this old finding of mine on medium. It was an interesting find and my first critical bug :) Do give it a read 😄
1
3
38
@0xmarvelmaniac
Ashutosh
6 months
Finally got h1 clear!!! Thanks a lot @H1LeoW 💪
4
0
34
@0xmarvelmaniac
Ashutosh
2 months
In July, I submitted 21 vulnerabilities to 4 programs on @Hacker0x01 . #TogetherWeHitHarder
0
0
24
@0xmarvelmaniac
Ashutosh
8 months
Hacking on a single program for a long time is great for bounties but not so great for fast reputation gains. Agree or Disagree ?🤔
3
1
19
@0xmarvelmaniac
Ashutosh
2 years
Hey folks! I wrote about a recent finding of mine - Reflected Xss. It was a very peculiar xss and had to bypass lots weird checks to takeover accounts. I hope you find it interesting:
0
5
18
@0xmarvelmaniac
Ashutosh
2 months
I've been getting constant vdp invites nowadays. It's actually fun writing reject invite feedbacks like - "Sorry I don't work for free..." or "It's concerning to see being asked for free labour like this..." or "Oh so the folks managing this program work for free? Sorry..." 😂
1
0
15
@0xmarvelmaniac
Ashutosh
3 months
Chasing leaderboards is the most annoying thing to do in hacking honestly. Once you start on this journey you can't back off easily 😮‍💨
2
0
14
@0xmarvelmaniac
Ashutosh
6 months
@galnagli In today's world I don't think it's fair for any company to expect free labour from the people. It's really concerning seeing how big companies shamelessly launches vdps on bug bounty platforms.
0
0
13
@0xmarvelmaniac
Ashutosh
3 months
Apparently there is a limit to how much you can loose but there is no limit to how much you can gain. It is too easy to get super overwhelmed with the gains and loose track of how much you actually need to gain.
0
1
9
@0xmarvelmaniac
Ashutosh
2 years
Finally crossed 1000 reputation points on @Hacker0x01 A small personal achievement worth sharing : ) #TogetherWeHitHarder
2
0
10
@0xmarvelmaniac
Ashutosh
2 years
@rene_kroka @martenmickos ...unless the product team decides they'll not address the bug 👀
0
0
7
@0xmarvelmaniac
Ashutosh
1 year
Explained everything to the program triager regarding why the issue is a high not medium and in the end I get a reply saying they will keep it medium because they feel like it's medium. Just fuck CVSS3.0 or the impact hacker is showing right?
1
0
7
@0xmarvelmaniac
Ashutosh
2 years
@Sahil_Saxena21 @tabaahi_ Lol he is a good triager. What happened ?
0
0
7
@0xmarvelmaniac
Ashutosh
7 months
Personally speaking I don't think the bounty paid justifies the severity score of the report( which again was calculated by an internal team member only). The feature that was compromised is a core feature of linkedin and many users use it to provide/receive services. #BugBounty
1
1
7
@0xmarvelmaniac
Ashutosh
8 months
bug bounty is not fun when teams just do whatever the hell they want...
2
0
7
@0xmarvelmaniac
Ashutosh
3 months
You gotta do what you gotta do **period**
0
0
7
@0xmarvelmaniac
Ashutosh
1 year
@ROSHANKUDAVE3 Authorization related issue. Can't disclose much not resolved yet
0
0
6
@0xmarvelmaniac
Ashutosh
1 year
India should take Cyber Sec seriously. Almost 99% of the companies and gov sites have crazy simple exploitable Crits and god knows how many times they got hacked and the citizens' data was dumped and sold in the black market. Cyber security scene in India is horrible seriously
2
0
6
@0xmarvelmaniac
Ashutosh
10 months
All is well until a program analyst lowers the severity of a good impact issue without any explanation and it's the weekend time + holidays season🤡
2
0
6
@0xmarvelmaniac
Ashutosh
3 months
Making money should always be the top priority!
0
0
7
@0xmarvelmaniac
Ashutosh
1 year
@Hammad7361 @Hacker0x01 @bug_vs_me There can be one of these two things happening here - 1) this was a mistake and they need to correct it and triage your report 2) triager mentioned the wrong report ID in the comment. Talk it through they'll understand and respond. Good luck 🤞
0
0
0
@0xmarvelmaniac
Ashutosh
5 months
@noob_labs @0xcharan @0xdln @Hacker0x01 php...no sqli was not everywhere. Out of say 30-45 endpoints we found it on 8, that too on specific parameters. Not all parameters were vulnerable
0
0
2
@0xmarvelmaniac
Ashutosh
2 years
@Abhishe11755518 @Marvel_India lol it was in comics that way . Except for jane who lifted the hammer? But yeah I agree that there was unnecessary comedy in the movie and the story wasn't that great . But it didn't have much impact impact in mcu as a whole so we can think of this movie as a casual thor movie :)
1
0
5
@0xmarvelmaniac
Ashutosh
2 years
@marcos_iaf @h4x0r_dz @samm0uda Wow you dont check your notifications or what damn ?
1
0
4
@0xmarvelmaniac
Ashutosh
2 years
@dccybersec @Bugcrowd @intigriti @Hacker0x01 I have accounts on all three but have been hacking on hackerone for a while now : )
1
0
4
@0xmarvelmaniac
Ashutosh
7 months
@h4x0r_dz @Bugcrowd bc triage is not that good.
0
0
4
@0xmarvelmaniac
Ashutosh
2 years
@thecyberzeel Operating systems
0
0
5
@0xmarvelmaniac
Ashutosh
1 year
@0xbara not resolved yet
1
0
5
@0xmarvelmaniac
Ashutosh
2 years
@harris0ft @Hacker0x01 reputation milestone or live hacking event swag ??? If rep milestone then how much rep needed??
2
0
4
@0xmarvelmaniac
Ashutosh
2 years
Hey @k4k4r07 , I would really like to have a small chat regarding a private program we both are in . Mind checking my twitter dm : ) Sorry for the unexpected mention , I assure you there will be no annoying questions just a 2-3 min chat should do : )
2
0
3
@0xmarvelmaniac
Ashutosh
4 months
@hetmehtaa People who know cyber security for real should get paid at least above 12LPA( in India). And for those you fake it on social media and resume should get paid nothing IMO( they just set a bad example of the hard working people in the cyber security industry)
1
0
4
@0xmarvelmaniac
Ashutosh
1 year
0
0
4
@0xmarvelmaniac
Ashutosh
2 years
@Ishansharma7390 Failure comes more often than success and its totally okay and we should know how to deal with them. That was never taught in schools, infact it was more like if you fail you are committing a crime.
0
0
3
@0xmarvelmaniac
Ashutosh
1 year
@zseano classic
0
0
0
@0xmarvelmaniac
Ashutosh
9 months
1
0
3
@0xmarvelmaniac
Ashutosh
5 months
@eagle_0408 @0xcharan @0xdln @Hacker0x01 We used simply SQLi detection techniques and implemented those technique in the custom extension too to find the rest. Burp Scanner generates too much traffic and it was missing some endpoints initially.
1
0
3
@0xmarvelmaniac
Ashutosh
1 year
confidence < over-confidence < Adipurush < VDPs run by multi-billion dollar companies 💩
0
0
4
@0xmarvelmaniac
Ashutosh
2 years
I don't understand the concept of assigning stored xss bugs (with no user interaction) leading to straight account takeover MEDIUM SEVERITY !! JUST WHY ?? #bugbounties
1
0
4
@0xmarvelmaniac
Ashutosh
2 years
I wrote a mini blog with 4 basic points on how to find #securitybugs more often in live targets or mainly what is the correct approch (from what I have learnt so far in my bug bounty journey) . Its a 3-4 mins read : ) #bugbountytips #bugbounty
1
0
4
@0xmarvelmaniac
Ashutosh
2 years
What do you guys do to save taxes on your bug bounty money? Any tips ?? #BugBounty
1
0
4
@0xmarvelmaniac
Ashutosh
5 months
@shakti_sec @0xcharan @0xdln @Hacker0x01 luckily no wafs were present when we found these issues. After reporting these findings program implemented waf 😂
2
0
4
@0xmarvelmaniac
Ashutosh
8 months
@krishnsec Duplicates always make me rethink about my life decisions. 😂
0
0
4
@0xmarvelmaniac
Ashutosh
5 months
@SuyashS91823422 @0xcharan @0xdln @Hacker0x01 I personally don't rely much on burp scanner. However in this case burp's initial discovery helped us find the rest sqlis in this target. Basically if you system has a lot of ram( >16 gb) then it will not hang but it could harm a production site in many ways too. Be careful!
1
0
3
@0xmarvelmaniac
Ashutosh
7 months
@AkashHamal0x01 People want everything to be served to them on a golden plate. They never google basic stuff and ask basic things. Because of this trend many companies/people scam them easily by providing the basic things already available for free in a sweet subscription model or course lol
0
0
3
@0xmarvelmaniac
Ashutosh
7 months
@NahamSec Totally making a good living out of bug bounty. Cheers!
0
0
3
@0xmarvelmaniac
Ashutosh
5 months
@0xTib3rius @0xLupin @alicanact60 physical address of a customer is considered PII and the hacker was able to disclose them at scale by iterating the id. Confidentiality impact is definitely high if I'm not missing anything and it is definitely a critical issue from bug bounty standpoint. Overall its a critical.
1
0
2
@0xmarvelmaniac
Ashutosh
2 years
@renniepak @Hacker0x01 You don't hack much on hackerone?
1
0
3
@0xmarvelmaniac
Ashutosh
2 years
I discovered a github account which has all the answers in it after failing the test twice (couldn't score in top 30%) 👀
0
0
3
@0xmarvelmaniac
Ashutosh
2 months
@Suryesh_92 @zomato Zomato team is right here. This is a N/A.
3
0
3
@0xmarvelmaniac
Ashutosh
1 year
life meh settle hona he yaar....
1
0
2
@0xmarvelmaniac
Ashutosh
2 years
@BountyOverflow If you have an xss and the cookies have samesite attribute *lax* , then you can perform cors attacks and steal sensitive information.
1
0
3
@0xmarvelmaniac
Ashutosh
2 years
Created a #LinkedIn account and took a "cybersecurity" skill test and failed to get a badge twice lmao . I thought I knew these basic theoretical things after doing #bugbounty for more than a year and a half but apparently not . ps: now I need to wait for 6 months to give it .
1
0
3
@0xmarvelmaniac
Ashutosh
2 years
@IamRenganathan made money from bug bounties and lost money in crypto and stocks 🙂
2
0
2
@0xmarvelmaniac
Ashutosh
2 years
@ZydTech @tabaahi_ @rana__khalil @stokfredrik @thedawgyg @ajxchapman @impratikdabhi @Farah_Hawaa @shahrukhiqbal24 I would recommend checking out portswigger xss labs for better understanding of what xss is : )
1
0
2
@0xmarvelmaniac
Ashutosh
3 months
@Darshan_Cyber @Bugcrowd There isn't much impact here tbh. Some programs accept it as low/p4 but mostly platform triagers close it as informative.
1
0
2
@0xmarvelmaniac
Ashutosh
9 months
@AkashHamal0x01 I have come across cases where the API instantly doesn't show deleted: true but after sometime it does show...probably happens due to refresh delays internally if that's a thing 😅
0
0
2
@0xmarvelmaniac
Ashutosh
8 months
@HusseiN98D Do you think going towards freelance pentesting on platforms like h1/cobalt etc. along with bug bounties is a good backup to tackle unpredictability? I'm young(but hardly any responsibilities for now) but the unpredictability always worries me...
2
0
2
@0xmarvelmaniac
Ashutosh
2 years
@tbbhunter @0ktavandi Thanks for sharing :)
0
0
2
@0xmarvelmaniac
Ashutosh
5 months
@HarshDRanjan1 @Hacker0x01 Congrats bro 👏🏻
1
0
2
@0xmarvelmaniac
Ashutosh
6 months
@nnwakelam yes true! That's a good reason actually 💪😂
0
0
2
@0xmarvelmaniac
Ashutosh
1 year
Just imagine a country with no borders or military forces. How weak and vulnerable it will be from outside attacks? That's exactly the case with Indian's 99% of IT infrastructure. Very few are taking baby steps but that's not even enough at today's date.
1
0
2
@0xmarvelmaniac
Ashutosh
5 months
@ott3rly @0xcharan @0xdln @Hacker0x01 Thanks! Check dm once, I want to ask something regarding this.
1
0
2
@0xmarvelmaniac
Ashutosh
8 months
@AnupamAS01 Good work man!!
1
0
2
@0xmarvelmaniac
Ashutosh
5 months
@0xTib3rius @0xLupin @alicanact60 CVSS doesn't cover the impact in all situations. Even HackerOne standards say that disclosure of any form of PII in mass scale is critical - And here the integrity was also affected. Definitely a critical IMO. 🙌🏻
1
0
2
@0xmarvelmaniac
Ashutosh
2 years
@dewcode91 I like the quote written there : )
0
0
2
@0xmarvelmaniac
Ashutosh
2 years
@renniepak happens on monthly basis mostly when I am least productive or procrastinate a lot on hacking or learning new stuff
0
0
2
@0xmarvelmaniac
Ashutosh
1 year
- interested in foreign clients because comparatively they take security way seriously than us and also pays good amounts for reporting them.
1
0
2
@0xmarvelmaniac
Ashutosh
1 year
literally in a position where if I test any further, I will get banned from the program completely for going against the policy. Pinging the internal team to look into the issue and waiting for it to get triaged ;p
1
0
2
@0xmarvelmaniac
Ashutosh
2 years
@marcos_iaf Yo! Got a minute to spare? Sent you a dm pls check :)
1
0
2
@0xmarvelmaniac
Ashutosh
2 years
1
0
2
@0xmarvelmaniac
Ashutosh
2 years
@tabaahi_ Better he could have used the developer tools and write down alert(document.cookie) in the console lol
1
0
1
@0xmarvelmaniac
Ashutosh
1 year
0
0
2
@0xmarvelmaniac
Ashutosh
2 years
@marcos_iaf @theXSSrat Nice good to hear man !
1
0
2
@0xmarvelmaniac
Ashutosh
9 months
0
0
2
@0xmarvelmaniac
Ashutosh
1 year
@Itumeleng_Les @Hacker0x01 @jobertabma trust the process. The bounty is coming 😆
1
0
1
@0xmarvelmaniac
Ashutosh
8 months
@rohsec Good work mate! This is inspiring me to hack on bugcrowd too 😁💪
1
0
2
@0xmarvelmaniac
Ashutosh
2 years
@bug_vs_me Send them a poc video of a mobile browser and also add the version of it(mention that its the latest). They'll reopen your report :)
1
0
2
@0xmarvelmaniac
Ashutosh
6 months
@lohigowda_in @NotionHQ Yeah I've noticed they have all these business logic issues but can't report because they have listed it OOS 😂
1
0
2
@0xmarvelmaniac
Ashutosh
1 year
@bug_vs_me @imranHudaA We need this. But this will never happen because programs(run by companies) are the main source of income for h1 I guess
1
0
2
@0xmarvelmaniac
Ashutosh
2 years
@praveenstatuzz @h4x0r_dz @Alra3ees @GodfatherOrwa @ADITYASHENDE17 Read reddit's policy page on h1 lol (if its on reddit )
0
0
2
@0xmarvelmaniac
Ashutosh
5 months
@roohaa_n idor, priv esc, business logic, csrfs
0
0
2
@0xmarvelmaniac
Ashutosh
3 months
@Neuuen__ Well said 👏🏻
0
0
1
@0xmarvelmaniac
Ashutosh
5 months
@HarshDRanjan1 @Hacker0x01 Congratulations bhai 🙌🏻🎉
0
0
2
@0xmarvelmaniac
Ashutosh
1 year
Le Indians: Paying for both 😂
@PicturesFoIder
non aesthetic things
1 year
Tweet media one
3K
24K
422K
0
0
2
@0xmarvelmaniac
Ashutosh
2 years
While learning something (from basics/intermediate/advance whatever) never expect that you'll learn it in one day. It involves multiple days, just know that ! Helps you mentain the peace of mind while learning : )
0
1
3
@0xmarvelmaniac
Ashutosh
3 months
0
0
2
@0xmarvelmaniac
Ashutosh
2 years
meme of the day 😂😂 #bugbounty #memes
Tweet media one
0
2
2