golu_369 Profile
golu_369

@golu_369

Followers
1,173
Following
191
Media
43
Statuses
635

Security researcher , Bachelor's in computer science engineering. car enthusiast.

India
Joined January 2022
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
@golu_369
golu_369
5 months
Achieved this beauty Volkswagen Virtus GT 1.5TSI ( car enthusiasts know this engine performance 🏎️😅) after lot of delays . All praise to God ❤️and thanks to @Bugcrowd @Hacker0x01 @yeswehack . #BugBounty #cybersecurity #ethicalhacking
Tweet media one
Tweet media two
Tweet media three
Tweet media four
50
5
192
@golu_369
golu_369
1 month
Fuck Snapchat Streak , we maintain @Hacker0x01 streak 💯💪 #BugBounty #cybersecurity
Tweet media one
8
6
151
@golu_369
golu_369
8 months
Thanks again @intigriti @redbull for drinks and the the bike 😜 #BugBounty #CyberSecurity
Tweet media one
16
3
147
@golu_369
golu_369
1 year
Hard to find bugs in single scope programs but anyhow did it , @Bugcrowd please send some wide scope invites 🙂. I earned $4,500 for my submission on @bugcrowd #ItTakesACrowd
7
7
117
@golu_369
golu_369
3 months
Finally Crossed 2500 Reputation on @Hacker0x01 , Hope to reach more levels . Thanks @Hacker0x01 for the hoodie 💯❤️. #bugbounty #cybersecurity #ethicalhacking
Tweet media one
Tweet media two
24
1
117
@golu_369
golu_369
1 year
Lucky Eid day 🌙😀 @Bugcrowd Bug : RCE due to dependency confusion. I earned $4,700 for my submission on @bugcrowd #ItTakesACrowd
8
1
114
@golu_369
golu_369
3 months
Recent finding on H1 : Found admin login page , default credentials not working. Checked JS files ,found endpoint “api/app/components/admin/components/create” Surprisingly due to no authentication I was able to create account and Perform admin actions . #bugbounty #hackerone
15
10
112
@golu_369
golu_369
4 months
Tweet media one
12
0
113
@golu_369
golu_369
6 months
Know The permissions of ALGOLIA API key using this curl request: Curl “ https://APPID.-dsn.algolia.net/1/keys/APIkeyhere?x-algolia-application-id=APPID&x-algolia-api-key=APIkeyhere” | jq You will get the permissions: 1/2
Tweet media one
8
16
73
@golu_369
golu_369
10 months
10 Months for Bounty 😶 , should I submit bug or not ! #bugbounty
Tweet media one
10
0
59
@golu_369
golu_369
11 months
Hope to find such bugs daily but it's hard nowadays. Server side template injection #BugBounty #CyberSecurity
Tweet media one
3
2
57
@golu_369
golu_369
11 months
Thanks @Bugcrowd , for P1 warrior.✌️💯🔥 #BugBounty
Tweet media one
1
2
53
@golu_369
golu_369
10 months
Few months ago someone shared a post about these firebase details usage to get some sensitive data , I am unable to find that post , if someone remember do share . Note: I am not asking about the misconfigured database that exposes data by using /.json #bugbountytip
Tweet media one
3
4
47
@golu_369
golu_369
10 months
Thanks @redbull @intigriti For this 🔥💯. #BugBounty
Tweet media one
Tweet media two
6
0
44
@golu_369
golu_369
6 months
Just got a reward for a vulnerability submitted on @yeswehack -- Improper Authentication - Generic (CWE-287). #YesWeRHackers #bugbounty
5
4
34
@golu_369
golu_369
13 days
“People behave so rude just because they are more successful than others , Time will humble them ✌🏻”
6
2
35
@golu_369
golu_369
2 years
Thanks @Bugcrowd @BugcrowdSupport for this swag ❤️💯 #BugBounty
Tweet media one
1
1
34
@golu_369
golu_369
1 month
Yoo ✌🏻qualified to next round . ✅ #bugbounty
@Hacker0x01
HackerOne
1 month
The results are in!🥇 Congratulations to these 32 teams who will move on to the Group Round of the 2024 #AmbassadorWorldCup ! 🙌 The next round kicks off at the end of August! Stay tuned for the latest info, and read more about the AWC here.
Tweet media one
46
58
303
4
3
26
@golu_369
golu_369
4 months
Some newly joined Triagers doing things that does not make any sense . #bugbounty
5
0
24
@golu_369
golu_369
1 year
$499 for this . They keep on increasing the price .
Tweet media one
3
1
22
@golu_369
golu_369
5 months
I am looking for remote job as a penetration tester / security engineer . Please let me know if someone can give referrals. #bugbounty #cybersecurity
8
1
20
@golu_369
golu_369
5 months
Does Microsoft pay for GitHub leaks or just hall of fame ? #BugBounty
2
1
18
@golu_369
golu_369
10 months
@bxmbn That's why @bug_vs_me gets invites from xvideos etc.
3
1
17
@golu_369
golu_369
11 months
@nav1n0x @Shopify Damn 🔥 Shopify is one of the hardest programs currently and this dude got 200K 🔥
0
0
15
@golu_369
golu_369
2 years
Thanks @yeswehack @firebounty . Please send invitations also 😅.
Tweet media one
3
0
16
@golu_369
golu_369
2 months
Looks like even bug bounty cannot make me exit from matrix , I need more money 💸. #bugbounty
2
0
15
@golu_369
golu_369
3 months
0
0
15
@golu_369
golu_369
4 months
“From the stars we came , To the stars we return”
3
1
13
@golu_369
golu_369
2 months
Whom to reach for help if even after using bugcrowd RAR the ASE still agreeing with wrong decision of the company about scope eligibility? @Bugcrowd #bugbounty #cybersecurity
6
0
12
@golu_369
golu_369
20 days
Billion dollars idea 💡 🫡🤝💯
Tweet media one
0
0
12
@golu_369
golu_369
2 years
I earned $2,100 for my submission on @bugcrowd #ItTakesACrowd @Bugcrowd . Bug type : improper authentication .
1
0
8
@golu_369
golu_369
4 months
@0xJin Who are you ? What are your achievements. Share your h1 and bugcrowd profile and then talk .
1
0
7
@golu_369
golu_369
1 month
Anyone getting VDP invites on hackerone from few days ? Even though in settings already selected for bounty only invites . #BugBounty @Hacker0x01
6
0
8
@golu_369
golu_369
2 years
Always run Waybackurls on subdomain giving 403 response to get all the JS files and check if any urls give 200 responses and check for API keys and tokens. This is my first tweet and i will share my findings and my learnings here from now . @Bugcrowd @zseano
0
2
7
@golu_369
golu_369
2 years
Recent finding on @Hacker0x01 , --> 401 response So used , --> 200 response , all products details exposed . @zseano @GodfatherOrwa @HackerGautam #bugbountytips #cybersecurity
0
3
7
@golu_369
golu_369
10 days
@harshleenchawl2 Whatever that guy earning , but you could not even earn a single dollar out of bug bounties .
1
0
6
@golu_369
golu_369
1 month
@fattselimi @PortSwigger You use community version only ?
1
0
6
@golu_369
golu_369
4 months
@hakluke Yeah , your Circadian rhythm is disturbed that’s why it’s happening. You need to fix it .
3
0
5
@golu_369
golu_369
4 months
@errorsec_ 150 ka Lele kanjoos
2
0
6
@golu_369
golu_369
8 months
@VashuVats @intigriti @redbull No bro 😂I was just joking, Redbull doesn’t give bounties nor bikes they gives drinks only. Bike is from hunting on bounty programs, I purchased it .
0
0
6
@golu_369
golu_369
6 months
If you get “list indexes “ “settings” in permissions you can go for further exploitation and report it . Don’t report if you get “search” permission only . 2/2 #bugbountytips #CyberSecurity #ethicalhacking #hackerone
1
0
6
@golu_369
golu_369
7 months
@Hacker0x01PD Fck I though it’s real 😂
1
0
5
@golu_369
golu_369
11 months
@InsiderPhD @GodfatherOrwa @bug_vs_me @Bugcrowd I never did that , I don't know why some of you are doubting and concluding without thinking twice. If 4-5 times asking for updates considered as spam then better to mention in that policy how many times it's considered spam. You are supporting bugcrowd for a reason I know.
2
0
5
@golu_369
golu_369
2 months
@hetmehtaa Mirzapur, Jaunpur , Sivaan .
2
0
5
@golu_369
golu_369
5 months
0
0
4
@golu_369
golu_369
2 months
@ArmanSameer95 Me after 5P1 triaged in my dreams .
1
0
5
@golu_369
golu_369
25 days
Life ain’t no rainbow and sunshine .
1
0
6
@golu_369
golu_369
2 months
@mysanismine @Bugcrowd I can understand your pain .
2
0
5
@golu_369
golu_369
9 months
@ReebootToInit5 @Bugcrowd Yes bro I am on h1 but major source of income is from bugcrowd , my rank was 340th there .
0
0
5
@golu_369
golu_369
2 months
India 🇮🇳 🇮🇳🇮🇳 ❤️ #WorldCup
0
0
5
@golu_369
golu_369
8 months
Happy new year to all . 🎊❤️
0
0
5
@golu_369
golu_369
1 year
There are some API keys found in JS files that are very tough to figure out which service they belong to . Does anyone know if there is any way to figure it out. These API keys have no hint or any other information in the js file so that we can know the service.
1
0
4
@golu_369
golu_369
5 months
Is astrology real ? .
4
0
4
@golu_369
golu_369
8 months
Wow whopping $100million 👏🏻congratulations @anandpraka_sh ❤️
@martenmickos
Mårten Mickos
8 months
Congrats to ethical hacker Anand Prakash on an amazing outcome for his startup PingSafe, acquired for over $100 million by SentinelOne
4
17
145
0
0
4
@golu_369
golu_369
3 months
@being__aman @Hacker0x01 More manual , less Recon
1
0
4
@golu_369
golu_369
2 months
@krishnsec Share some p1 … thanks 🙃
2
0
4
@golu_369
golu_369
1 year
@Hacker0x01 , next is the H1 hoodie that i love .
Tweet media one
1
0
3
@golu_369
golu_369
2 years
Just got a reward for a critical vulnerability submitted on @yeswehack -- Code Injection (CWE-94). #YesWeRHackers
0
0
4
@golu_369
golu_369
10 months
@Jayesh25_ Desi ghee kee Bundi sakkar-paare batvaaoonga ....jis din me xxe find kar paunga.
5
0
4
@golu_369
golu_369
8 months
@PhilippeDelteil Exactly bro your are 100% correct, bug hunters have no power in there hands . Programs and platforms can really give you a lot of mental stress .
0
0
4
@golu_369
golu_369
1 year
@gregxsunday @Hacker0x01 This mediation thing is getting worse day by day.
0
0
4
@golu_369
golu_369
12 days
@intigriti Lazy s3
1
0
3
@golu_369
golu_369
4 months
0
0
3
@golu_369
golu_369
4 months
@sheth_kavisha @Virdoex_hunter @Mdhsan19 @Yassineaboukir @SahilOj First you entered in between our conversation out of nowhere and now blaming us for no reason , don’t know why you so obsessed in getting the credit ,are you the inventor of this vulnerability.
1
0
2
@golu_369
golu_369
2 months
@krishnsec 💴💴
1
0
3
@golu_369
golu_369
2 years
Just got a reward for a critical vulnerability submitted on @yeswehack -- Code Injection (CWE-94). #YesWeRHackers
1
0
3
@golu_369
golu_369
3 months
0
0
2
@golu_369
golu_369
2 months
@Mdhsan19 Bhai Matlab tumne 1-2 crore Kama liye google se . Ab book krdo car
1
0
3
@golu_369
golu_369
19 days
@rohsec @volklub Ya anything related to vw or cars ask me , he knows me though .
0
0
2
@golu_369
golu_369
1 year
Never hunt on Chinese companies they are very clever, literally they awarded $39 dollars only for a medium bug😂 even though the company is very big.
0
0
3
@golu_369
golu_369
10 months
@Jayesh25_ Thanks for sharing 🔥💯
1
0
3
@golu_369
golu_369
5 months
@_smile_hacker_ @Hacker0x01 Wow congratulations. Tell us how you got this.
1
0
3
@golu_369
golu_369
30 days
@krishnsec @mertistaken Mere saath kab karega 🙃
1
0
2
@golu_369
golu_369
1 month
@AkashHamal0x01 Sorry but I disagree , we don’t know what is someone going through in their mind and what if they end their life ? Will now the statement ‘if someone is obese say so ‘ makes any sense . encouragement can do magic but bullying cannot do .
2
0
3
@golu_369
golu_369
26 days
@damian_89_ Program name start with se…
1
0
3
@golu_369
golu_369
2 months
What’s your Pentest rate hourly ? #bugbounty #cybersecurity #ethicalhacing
1
0
3
@golu_369
golu_369
2 months
@krishnsec Mast program mile Teri tarah to me 20hrs karu
0
0
3
@golu_369
golu_369
1 year
@krishnsec Thanks hacking 🗿
Tweet media one
0
0
3
@golu_369
golu_369
19 days
@ArmanSameer95 T-mobile added a subdomain of your name 🫡
2
0
3
@golu_369
golu_369
3 months
@roohaa_n @Bugcrowd Congrats bhai 🎊✌🏻
1
0
2
@golu_369
golu_369
1 month
@Caleepha_ms @Hacker0x01 Congratulations bro , amazing performance 🙌🏻🎉
1
0
3
@golu_369
golu_369
4 months
@0xfxiii @zseano Good work 👏🏻
2
0
3
@golu_369
golu_369
8 months
@krishnsec Aisi kismat muje nhi di Baghwan ne
0
0
2
@golu_369
golu_369
5 months
@tabaahi_ @Bugcrowd @Hacker0x01 @yeswehack Thanks bro 😊 it’s GT one 😅not simple Virtus .
2
0
2
@golu_369
golu_369
5 months
@errorsec_ Wtf 45k😂
1
0
3
@golu_369
golu_369
5 months
@krishnsec Bhai BJP vale aate honge tuje deshdrohi bolne 😂
1
0
3
@golu_369
golu_369
10 months
& converts to & tried everything all bypasses none of them working. Suggest bypass . #bugbounty
1
0
3
@golu_369
golu_369
1 year
@GodfatherOrwa @Bugcrowd @BugcrowdSupport , please check that program, they are doing this with a lot of people.
0
0
3