Debangshu 🇮🇳🥷 Profile Banner
Debangshu 🇮🇳🥷 Profile
Debangshu 🇮🇳🥷

@ThisIsDK999

Followers
6,003
Following
942
Media
974
Statuses
10,231

default BURP user. loves to pwn AEMs and other CMSes. Top 200 @bugcrowd . Captain @Str4awHats 🥷. Opinions are personal.

Joined August 2016
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
Pinned Tweet
@ThisIsDK999
Debangshu 🇮🇳🥷
1 month
100k$ on @Bugcrowd finally :) Big thank you to everyone who contributed to this journey. @_rajesh_ranjan_ @Assass1nmarcos @ArmanSameer95 and all my other friends <3 (might not be as big of a number but it's a total milestone for me 🌟 :)
Tweet media one
67
16
395
@ThisIsDK999
Debangshu 🇮🇳🥷
4 years
Its my birthday 🎉! So Imma post a quick little #bugbountytip 1) Recruitment site, had option to upload pdfs (CV, Resume, certs and other docs) 2) Saw the upload functionality, files uploaded to s3 bucket i.e. (1/n)
41
70
315
@ThisIsDK999
Debangshu 🇮🇳🥷
4 years
site:monitoring.*.com "dashboard" Super simple, yet effective #bugbountytips #bugbountytip #cybersecurity
0
80
295
@ThisIsDK999
Debangshu 🇮🇳🥷
4 years
I earned $2,300 for my submission on @bugcrowd #ItTakesACrowd #bugbounty Small PoC: 1) Used dork: inurl: 2) Searched through first 10 pages manually. 3) Came across a site having some example code snippets (1/2)
8
53
245
@ThisIsDK999
Debangshu 🇮🇳🥷
3 years
Hey all! A quick AEM #bugbountytip for you guys! Appending the query "?tidy=true" to the JSON output of any endpoint prettifies it for you. (Check pics 1&2) Also, certain times it might help you to break the caching behaviour of AEMs too! Have fun with this. (Pic 1/2)
Tweet media one
3
78
233
@ThisIsDK999
Debangshu 🇮🇳🥷
2 months
Here's how I was awarded 1k$ for an Open Redirect👇
10
31
197
@ThisIsDK999
Debangshu 🇮🇳🥷
4 years
I earned $2,700 for my submissions on @bugcrowd #ItTakesACrowd 1) Access to spring boot endpoints leading to multiple vulns(2100$) 2) Ability to send email from anybody @company .com by abusing their fax functionality (600$)
19
13
168
@ThisIsDK999
Debangshu 🇮🇳🥷
11 months
: the intentionally open redirect #bugbountytip
Tweet media one
1
44
170
@ThisIsDK999
Debangshu 🇮🇳🥷
3 years
Using Firefox? Small tip: Hit about:config and type general.useragent.override Now, select the String option and hit + and then, paste in your Blind XSS Payload. Useful, in case you're too lazy to open burp, just right in your browser itself. (1/3) #cybersec #hacking #bugbounty
Tweet media one
5
54
162
@ThisIsDK999
Debangshu 🇮🇳🥷
4 years
Let's make this a thread: List atleast one technique you learned from CTFs that you used/can be used IRL Mine: Prepending GIF magic bytes to a malicious php shell led to File-Upload Bypass and command execution. Comment! #bugbountytips #bugbountytip #cybersecurity
Tweet media one
5
46
160
@ThisIsDK999
Debangshu 🇮🇳🥷
4 years
3) simple google dork: site: ext:pdf 4) Guess what! Tonnes of PII🙈 5) Stepping it up, I noticed the docs being saved as 6) Brute force away! Even more PII! P1 -> $$$$ S3 access control issue -> IDOR -> PII (n/n) Enjoy Guys! 🎉❤️
6
31
162
@ThisIsDK999
Debangshu 🇮🇳🥷
4 years
Small dork to pull up list of Openfire Admin Console for CVE-2019-18394 Google intitle:"Openfire Admin Console" Shodan http.title:"Openfire Admin Console" #bugbountytip #bugbountytips
3
65
153
@ThisIsDK999
Debangshu 🇮🇳🥷
1 month
#bugbountytips For beginners getting started, stay away from accounts that only post about random tools and 'how to get started' tweets for engagement farming. They probably are not a subject matter expert and you either won't gain much from them :)
12
17
157
@ThisIsDK999
Debangshu 🇮🇳🥷
1 year
pls keep reporting those P4 email disclosures guys 😌
Tweet media one
14
3
152
@ThisIsDK999
Debangshu 🇮🇳🥷
3 years
Glad to announce that I'm finally a member of @SynackRedTeam after a year long wait! Many thanks @ArmanSameer95 !🥳🥳 #infosec #bugbounty
Tweet media one
21
2
143
@ThisIsDK999
Debangshu 🇮🇳🥷
6 months
Reminder: Never Give Up! 🔥 cc: @Assass1nmarcos
Tweet media one
9
3
118
@ThisIsDK999
Debangshu 🇮🇳🥷
4 years
While pentesting JIRA/Confluence webapps, if you ever come across this warning, simply add: X-Atlassian-Token: no-check in the request body and that would probably bypass this warning. #bugbountytip #bugbountytips
Tweet media one
6
50
113
@ThisIsDK999
Debangshu 🇮🇳🥷
4 years
I earned $1400 for my submissions on @bugcrowd Bug 1: Unauthenticated Access to Apache Example Servlet leading to multiple vulnerabilities (1200$) Bug 2: Access to client's test account via pastebin(200$) #ItTakesACrowd
14
8
105
@ThisIsDK999
Debangshu 🇮🇳🥷
4 years
#bugbountytip #bugbountytips Have a possible XSS on AEM target, but application renders it in JSON? Simply append the query to the url -> "?mimeType=text/html" to get it to render in HTML format. Note: Might not work for all instances.
2
29
104
@ThisIsDK999
Debangshu 🇮🇳🥷
4 years
Ending the night with a P1😎 #bugbounty
Tweet media one
17
2
103
@ThisIsDK999
Debangshu 🇮🇳🥷
4 years
Tweet media one
7
19
96
@ThisIsDK999
Debangshu 🇮🇳🥷
2 years
Something very wrong is up with @pdnuclei templating process. A thread :- 👇
Tweet media one
6
15
94
@ThisIsDK999
Debangshu 🇮🇳🥷
3 years
Sad to see senior infosec people having 0 knowledge of their own environment. 🤥 #infosec
10
4
89
@ThisIsDK999
Debangshu 🇮🇳🥷
2 years
Tweet media one
11
1
91
@ThisIsDK999
Debangshu 🇮🇳🥷
4 years
I earned $1,250 for my submission on @bugcrowd #ItTakesACrowd Bug: Semi internal sites accessible and editable publicly w/ limited code execution
6
3
87
@ThisIsDK999
Debangshu 🇮🇳🥷
1 year
Might be an average hacker but atleast I don't copy pasta posts/resources to gain followers 😂
10
7
87
@ThisIsDK999
Debangshu 🇮🇳🥷
2 years
Thanks @Bugcrowd !
Tweet media one
12
1
84
@ThisIsDK999
Debangshu 🇮🇳🥷
4 years
You won't get a bug until you hunt for it 😂. Simple.
4
2
85
@ThisIsDK999
Debangshu 🇮🇳🥷
4 years
@intigriti Took quite some effort to make😅Turn the volume up!🔊
17
15
81
@ThisIsDK999
Debangshu 🇮🇳🥷
4 years
They did mine an informative and sent me this. 🧐
Tweet media one
7
0
77
@ThisIsDK999
Debangshu 🇮🇳🥷
4 years
Hello folks! My friend @ArmanSameer95 Just published an awesome writeup on a really interesting finding here: @MilindPurswani Awesomee idea mate! @dominat0r98 😏Disclose yours ASAP too #bugbounty #bugbountytips #hacking #bugbountytip
4
19
77
@ThisIsDK999
Debangshu 🇮🇳🥷
4 years
@intigriti Thanks!
Tweet media one
9
1
74
@ThisIsDK999
Debangshu 🇮🇳🥷
3 years
Fun timesss @ @bsidesahmedabad 🤧💖 #infosec
Tweet media one
1
0
75
@ThisIsDK999
Debangshu 🇮🇳🥷
1 year
I just started reversing CVEs in WordPress Plugins a while back and found some new issues too! Would y'all be interested in writeups? #infosec
16
1
72
@ThisIsDK999
Debangshu 🇮🇳🥷
5 months
. @RockWithboAt should invest in a Bug Bounty Program with actual rewards. This attracts top-tier talent, who don't work for free While due attention to overall security posture is crucial atm, this would certainly, plug a lot of holes. It's high time now! @amangupta0303 #boat
Tweet media one
17
7
70
@ThisIsDK999
Debangshu 🇮🇳🥷
2 years
It just took a minute. Damn. #infosec #ChatGPT
Tweet media one
3
1
71
@ThisIsDK999
Debangshu 🇮🇳🥷
4 years
@Bugcrowd Coz...santa just doesn't give P1s ;_;
Tweet media one
5
13
69
@ThisIsDK999
Debangshu 🇮🇳🥷
3 years
Yo! Guess who's finally 18! 🥳
25
0
68
@ThisIsDK999
Debangshu 🇮🇳🥷
2 months
Just a random day with @0_0eth0
Tweet media one
4
1
68
@ThisIsDK999
Debangshu 🇮🇳🥷
4 years
Always try harder! #bugbounty Thanks to @AEMSecurity and @taulantbajramii for showing me the guiding light :)
Tweet media one
10
4
66
@ThisIsDK999
Debangshu 🇮🇳🥷
4 years
Inviting all the security researchers to register on India's First Crowdsourced Penetration Testing Platform... Visit: Go ahead & register yourself. Helping a friend out!
10
10
63
@ThisIsDK999
Debangshu 🇮🇳🥷
1 year
SSRF on GCP? Can't extract metadata? Can't set headers? No internal subdomains? Tried every SSRF resource on the internet? Still no success? Me and @RathiArpeet managed to find one such SSRF that led to a sweet bounty. Stay tuned, dropping it soon! #infosec #BugBounty
3
3
65
@ThisIsDK999
Debangshu 🇮🇳🥷
1 year
Been trying out @Netlas_io for a while and the results and filters on this are amazing! There's a lot of experimentation one can do with this. Surely underrated! #infosec #BugBounty #bugbountytips
Tweet media one
9
7
62
@ThisIsDK999
Debangshu 🇮🇳🥷
2 months
Tweet media one
3
1
65
@ThisIsDK999
Debangshu 🇮🇳🥷
3 years
I'm very happy to share that I'll be presenting my talk 'To The Docs And Beyond!' at @BarcelonaBsides which will take place from 30th September - 1st October, this year. See you all there! #bugbounty #hacking #cybersecurity
Tweet media one
8
7
62
@ThisIsDK999
Debangshu 🇮🇳🥷
3 years
Got done with @Hacker0x01 Ambassador CTF w/ Pune India H1 Club. Kudos to all team members for all their combined efforts!🎴 #infosec #ctf
Tweet media one
2
3
63
@ThisIsDK999
Debangshu 🇮🇳🥷
3 years
Ohhh...
Tweet media one
2
1
62
@ThisIsDK999
Debangshu 🇮🇳🥷
3 years
Using FireFox? But tired of that annoying request to detectportal(.) on startup? Go to about:config Search "captive" Switch network.captive-portal-service.enabled" to false #mozilla #web
Tweet media one
4
14
61
@ThisIsDK999
Debangshu 🇮🇳🥷
4 years
Wishing everyone a happy saraswati puja🥰
Tweet media one
4
2
62
@ThisIsDK999
Debangshu 🇮🇳🥷
3 years
A very sad truth of BB : People are happy with a med when you can possibly turn it into a crit with a little bit of digging, but they're just too naive or rather too lazy to make an effort. Ruins his/her and other's chances of getting a crit too! #infosec #BugBounty
7
1
59
@ThisIsDK999
Debangshu 🇮🇳🥷
4 years
When hard work pays off #bugbounty #ItTakesACrowd
Tweet media one
8
3
60
@ThisIsDK999
Debangshu 🇮🇳🥷
4 years
org: http.title:rocketmq-console A small shodan dork to pull up RocketMQ console which often has quite confidential production information disclosed. #bugbountytips #bugbountytip
0
21
57
@ThisIsDK999
Debangshu 🇮🇳🥷
5 months
Beat it ;) cc: @Assass1nmarcos
Tweet media one
11
0
59
@ThisIsDK999
Debangshu 🇮🇳🥷
2 years
It was a very small reward but the response meant a lot! Thanks! Donthu @Bugcrowd
Tweet media one
1
1
57
@ThisIsDK999
Debangshu 🇮🇳🥷
4 months
📍Somewhere in the hills
Tweet media one
10
0
59
@ThisIsDK999
Debangshu 🇮🇳🥷
1 month
India 5 🇮🇳lessgoooo
@Hacker0x01
HackerOne
1 month
The results are in!🥇 Congratulations to these 32 teams who will move on to the Group Round of the 2024 #AmbassadorWorldCup ! 🙌 The next round kicks off at the end of August! Stay tuned for the latest info, and read more about the AWC here.
Tweet media one
46
59
303
5
5
59
@ThisIsDK999
Debangshu 🇮🇳🥷
3 months
Hunters! Your domains pointed to AWS IP are getting indexed on Shodan! XD Link -
Tweet media one
2
3
57
@ThisIsDK999
Debangshu 🇮🇳🥷
3 years
OMG! My twitter feed is bursting with Log4j now 😹😹😹
4
2
52
@ThisIsDK999
Debangshu 🇮🇳🥷
4 years
Tweet media one
9
2
54
@ThisIsDK999
Debangshu 🇮🇳🥷
15 days
Phew! That was quite the pentest!
Tweet media one
2
2
55
@ThisIsDK999
Debangshu 🇮🇳🥷
1 year
some security teams can’t reproduce basic PoCs and want 5 yrs of experience in their candidates lmaoo
4
7
52
@ThisIsDK999
Debangshu 🇮🇳🥷
2 years
Bois, he's back in my DMs!!
Tweet media one
18
0
51
@ThisIsDK999
Debangshu 🇮🇳🥷
1 year
And with that my 1000+ kms road trip all over #Assam comes to an end! Till next time! <3
Tweet media one
3
0
53
@ThisIsDK999
Debangshu 🇮🇳🥷
7 months
My drafted talk deals with a similar situation i.e.: how to SSRF when AWS/GCP metadata access fails. (I wish some conferences accept it, instead of the regular jargon you see in infosec everyday) Severity is totally unjustified
@disclosedh1
publiclyDisclosed
7 months
HackerOne disclosed a bug submitted by madara_: - Bounty: $2,500 #hackerone #bugbounty
Tweet media one
6
18
127
7
2
53
@ThisIsDK999
Debangshu 🇮🇳🥷
4 years
4) Came across a PHP code snippet originally hosted on github but referenced there. 5) grepped for username and password in the code snippet. 6) Found Username, password and admin endpoint 7) Logged in and had access to full PII (2/2)
0
7
50
@ThisIsDK999
Debangshu 🇮🇳🥷
1 year
Feel free to DM me if you require escalating any #AEM security issues. I’ll try my best. However, please note :- a) I don’t encourage VDPs b) Not at all times its possible to bypass dispatcher filters/ find critical issues. Please bear with that. #BugBounty #infosec #hacking
2
1
50
@ThisIsDK999
Debangshu 🇮🇳🥷
2 years
It was nice playing #NahamCon2022 CTF w/ @Str4awHats Kudos to everyone! #infosec
Tweet media one
5
1
50
@ThisIsDK999
Debangshu 🇮🇳🥷
2 years
Lessgoo!!! Much appreciated @RelentlessT7 🫶
Tweet media one
8
0
51
@ThisIsDK999
Debangshu 🇮🇳🥷
2 years
Comedy: Comedy pro max: @HP security team: #infosec
Tweet media one
6
4
50
@ThisIsDK999
Debangshu 🇮🇳🥷
3 years
Missed l33t number by 1 point 😂 @Bugcrowd
Tweet media one
8
0
48
@ThisIsDK999
Debangshu 🇮🇳🥷
29 days
Dear all SSRF Lords, On a Backend running Ruby 5.0.2 & Squid Proxy and a Full Response SSRF. What all can we try? (Basic stuff already tried) #bugbounty #infosec
10
4
50
@ThisIsDK999
Debangshu 🇮🇳🥷
3 years
#bugbountytip #bugbountytips Anonymous Write Vulnerability in Adobe Experience Manager (AEM) may lead to multiple Stored XSS(s) (SVG+HTML Prop based) Details here: Bypasses are really random. E.g: /1.css | /.json/ahyejwkw.js | ?.html;%0aaaa.json |
@AEMSecurity
AEMSecurity
5 years
[+] #BugbountyTip : When testing for anonymous write access on Adobe AEM in "/content/usergenerated/*" If you get HTTP 404, try bypassing the dispatcher filter rules like this: "/ANYEXISTINGFOLDER/..../content/usergenerated/test" #Bugbounty #TogetherWeHitHarder #AdobeAEM
0
17
46
1
20
48
@ThisIsDK999
Debangshu 🇮🇳🥷
3 years
Hehe
Tweet media one
3
5
48
@ThisIsDK999
Debangshu 🇮🇳🥷
4 years
@HusseiN98D Haven't took a pic recently, this is just after I made it.
Tweet media one
4
0
47
@ThisIsDK999
Debangshu 🇮🇳🥷
4 years
Nibbas be like Ohh AI/ML's gonna takeover BB/Hacking. Lemme ask you something? Do you even code bro?
10
2
48
@ThisIsDK999
Debangshu 🇮🇳🥷
2 years
Ban @SaveToNotion users
16
0
48
@ThisIsDK999
Debangshu 🇮🇳🥷
5 months
Since this was resolved ✅ and was an interesting find, I'm thinking of sharing it with the community. What would you guys like? cc: @Assass1nmarcos
@ThisIsDK999
Debangshu 🇮🇳🥷
6 months
I earned $8,500 for my submissions on @bugcrowd #ItTakesACrowd cc: @Assass1nmarcos
24
6
171
4
1
49
@ThisIsDK999
Debangshu 🇮🇳🥷
3 years
Day out.
Tweet media one
7
0
48
@ThisIsDK999
Debangshu 🇮🇳🥷
4 years
Bas kar bhai humein nahi dekhna, kitne P1s triaged hay tere #bugbountymemes #bugbounty
Tweet media one
6
4
49
@ThisIsDK999
Debangshu 🇮🇳🥷
9 months
Top 6 - Mastercard BBP
Tweet media one
11
0
49
@ThisIsDK999
Debangshu 🇮🇳🥷
3 years
Tweet media one
1
2
49
@ThisIsDK999
Debangshu 🇮🇳🥷
4 years
DM me your password and I'll tell you if its secure.
31
4
48
@ThisIsDK999
Debangshu 🇮🇳🥷
4 years
Stop simping and get hacking. Brrrrrrr! #bugbounty
0
0
47