πš–πšŽπš›πš 🦧 Profile Banner
πš–πšŽπš›πš 🦧 Profile
πš–πšŽπš›πš 🦧

@mertistaken

Followers
6,736
Following
572
Media
52
Statuses
342

hacker / bug bounty hunter / all-time rank #2 on @bugcrowd ()

Joined January 2013
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
@mertistaken
πš–πšŽπš›πš 🦧
3 years
I got my biggest reward ever ($20k) for a single submission. also, includes the best bonus reward I've ever get on @bugcrowd . it's great to hear things like this from the clients. 🌝
Tweet media one
29
11
477
@mertistaken
πš–πšŽπš›πš 🦧
4 years
I blogged an interesting P1 vulnerability about SSTI. πŸ™ŒπŸ™Œ Limited FreeMarker SSTI to arbitrary LiQL query and manage Lithium CMS - #BugBounty
6
164
367
@mertistaken
πš–πšŽπš›πš 🦧
1 year
March πŸ”₯πŸ”₯ congrats to all hunters πŸ‘ P1s: SQLi x3 IDOR x2 RCE x2 Info (session) Leak x1 one of the RCEs: a website was blocking ASPX file uploads. bypassed it by uploading an ASHX file and triggering it to create an ASPX shell on same dir. ASHX shell:
Tweet media one
27
44
369
@mertistaken
πš–πšŽπš›πš 🦧
2 years
Such a nice ending! I have reported ~490 (non-duplicate) bugs and ~90 of them were critical vulnerabilities. Thanks to the @Bugcrowd team for all the opportunities it provided in 2022, 90% of these numbers come from them. ❀️
Tweet media one
22
5
274
@mertistaken
πš–πšŽπš›πš 🦧
4 years
Thanks for these cool MVP gifts! 😊 @Bugcrowd
Tweet media one
Tweet media two
13
8
256
@mertistaken
πš–πšŽπš›πš 🦧
2 years
Another great month was June. Statistics for accepted submissions -except dupes- on 13 different programs are as follows; x10 - SQLi x14 - Business Logic x3 - SSTI/RCE x1 - LFI x23 - XSS Congrats to all researchers, thanks @Bugcrowd 😊
Tweet media one
13
9
252
@mertistaken
πš–πšŽπš›πš 🦧
2 months
After competitive years for me, got the #1 position on the @Bugcrowd 's all-time P1 & P2 leaderboard. πŸ₯² having your hobby as a job is definitely one of the best things in the world! πŸ™ŒπŸ» I also wrapped up April with 980 points (820 points from 17xP1 and 6xP2 reports on 8 different
Tweet media one
Tweet media two
45
4
252
@mertistaken
πš–πšŽπš›πš 🦧
3 years
I have 413 (includes 63 criticals) vulnerabilities rewarded on @Bugcrowd in 2021. It was a very fun as well as busy year. Thanks to the whole team. 🌝
14
10
213
@mertistaken
πš–πšŽπš›πš 🦧
8 years
XSS attack vector for LESS: a{b:`function(){alert(1)}()`;}
Tweet media one
2
75
210
@mertistaken
πš–πšŽπš›πš 🦧
4 months
feb dump πŸ™‚ even though I was inactive for 2 weeks in February I ranked 1st in the monthly leaderboard thanks to subs waiting in triage from many different programs. πŸ™Œ 8x p1 - 4x SQLi - 2x RCE - 1x AuthBypass - 1x LFI 3x p2 18x p3 6x p4 the big bounties came
Tweet media one
Tweet media two
Tweet media three
22
4
212
@mertistaken
πš–πšŽπš›πš 🦧
4 years
10k+ points club on @Bugcrowd 's all-time leaderboard, finally. πŸ™‚
Tweet media one
9
3
196
@mertistaken
πš–πšŽπš›πš 🦧
4 years
August β™₯️
Tweet media one
Tweet media two
8
4
178
@mertistaken
πš–πšŽπš›πš 🦧
2 years
Reached 200+ on the @Bugcrowd P1 warrior leaderboard, the next mark is 250. πŸ”₯
Tweet media one
19
2
167
@mertistaken
πš–πšŽπš›πš 🦧
10 months
I think quality is more important than quantity, but I have achieved some numerical goals that are important to me. I passed 30k+ points on the all-time leaderboard, 3k+ valid vulnerabilities, and reached 300+ P1s. Thanks to @Bugcrowd for these great opportunities. πŸ™ŒπŸ»
Tweet media one
Tweet media two
31
2
164
@mertistaken
πš–πšŽπš›πš 🦧
2 years
Focused work brings success. Congrats to all researchers on the July leaderboard! 90% of my July submissions are business logic vulnerabilities. They are everywhere and require manual hunting mostly. I suggest everybody who wants to find something easily check them out. β™₯️
Tweet media one
Tweet media two
11
3
152
@mertistaken
πš–πšŽπš›πš 🦧
1 year
most impactful submission bonus! πŸ”₯
Tweet media one
8
3
137
@mertistaken
πš–πšŽπš›πš 🦧
6 years
1k accepted bugs. πŸŽ‰πŸŽ‰
Tweet media one
9
0
122
@mertistaken
πš–πšŽπš›πš 🦧
3 years
I guess this is my personal record in the @Bugcrowd monthly leaderboard, it was a tiring but fun month. Thanks to the whole team for the quick actions and congratulations to everyone on the list!
Tweet media one
Tweet media two
13
0
122
@mertistaken
πš–πšŽπš›πš 🦧
1 year
(1/4) I faced an interesting scenario about browser behaviors after discovering an unexploitable Reflected XSS. Since this HTTP response does not contain the Content-Type header, the browser will "MIME sniffing" by analyzing the content. #bugbounty #bugbountytips
Tweet media one
3
13
118
@mertistaken
πš–πšŽπš›πš 🦧
1 year
May πŸ”₯ congrats to all hunters! I'm grateful to @Bugcrowd for the amazing opportunities provided. ❀️ With 12 non-dupe P1s in May, I increased the count to ~290 on P1-warrior. The current P1-Warrior goal is 300! πŸ™ŒπŸ»
Tweet media one
Tweet media two
11
3
116
@mertistaken
πš–πšŽπš›πš 🦧
9 months
September and October, a monthly streaaaak! πŸ”₯ It was a great two months, I really love hacking. Most of this month came from the @FISGlobal team, thanks so much for the great rewards. Congrats to all the researchers! πŸ™ŒπŸ» @Bugcrowd 🧑
Tweet media one
Tweet media two
14
1
109
@mertistaken
πš–πšŽπš›πš 🦧
3 years
finally unlocked the Level 7 badge on the @Bugcrowd P1 Warrior leaderboard. 🌝
Tweet media one
5
0
95
@mertistaken
πš–πšŽπš›πš 🦧
2 years
I came to the end of a fun 5 years and left my job at the end of March. I'll continue as a full-time bug bounty hunter from now on. I've been planning to do it for a long time, I think it will be fun. 🌝 Thanks to @PicusSecurity for every opportunity provided. πŸ™πŸ»
15
1
95
@mertistaken
πš–πšŽπš›πš 🦧
3 years
it was a fun month. congrats to all researchers and thanks to the whole @Bugcrowd team. 🌝 #ItTakesACrowd
Tweet media one
Tweet media two
6
2
91
@mertistaken
πš–πšŽπš›πš 🦧
4 months
I want to share a small and nice example where I can quickly present the impact of the bug. in one of the SQLi submissions: I saw an error message starting with "org.hibernate.QueryException" in a request's response. then I realized that HQL injection is possible here, but since
5
9
89
@mertistaken
πš–πšŽπš›πš 🦧
4 years
good closing. 🌝 thanks to the whole @Bugcrowd team for this exciting year. happy *healthy* new year!
Tweet media one
1
2
84
@mertistaken
πš–πšŽπš›πš 🦧
7 years
My new payload: '/\mert%252eninja'. Open redirect is fun!
Tweet media one
3
23
75
@mertistaken
πš–πšŽπš›πš 🦧
6 years
I got my first UI bug reward on @Bugcrowd . πŸ˜„πŸ˜„
Tweet media one
3
0
57
@mertistaken
πš–πšŽπš›πš 🦧
3 years
sep1tember 🌝
Tweet media one
4
0
58
@mertistaken
πš–πšŽπš›πš 🦧
10 months
September was a great month in which I had the opportunity to discover critical vulnerabilities in many different @Bugcrowd programs. It's a great feeling when the effort pays off! πŸ™ŒπŸ»
@Bugcrowd
bugcrowd
10 months
September's Top 10 #Hackers ! 1️⃣ mert 2️⃣ Private user 3️⃣ camel 4️⃣ sws_jk 5️⃣ d0xing 6️⃣ m0chan 7️⃣ ZwinK 8️⃣ Private user 9️⃣ Private user πŸ”Ÿ vfial Leave a like to show your support! πŸ‘
8
8
107
7
0
51
@mertistaken
πš–πšŽπš›πš 🦧
7 years
Kudos ❀️ Thank you @Bugcrowd !
@Bugcrowd
bugcrowd
7 years
And the bug hunter with the most Kudos points in 2016 is @merttasci_ ! Congrats on your hard work on Kudos only programs! #ItTakesACrowd
Tweet media one
0
2
20
12
4
48
@mertistaken
πš–πšŽπš›πš 🦧
7 years
Again, unexpected bonus reward! Thanks! @Bugcrowd
Tweet media one
3
0
47
@mertistaken
πš–πšŽπš›πš 🦧
7 years
We wrote something about IDOR bugs w/ @evrnyalcin . Thanks for sharing @Bugcrowd ! πŸ˜ŠπŸ‘
@Bugcrowd
bugcrowd
7 years
Great guest post from @merttasci_ & @evrnyalcin on how to find IDOR bugs for large bounty rewards: #ItTakesACrowd
2
57
120
3
14
44
@mertistaken
πš–πšŽπš›πš 🦧
3 years
2021-Q1 MVP πŸ₯³
@Bugcrowd
bugcrowd
3 years
🎊 MVP's for Q1 are here 🎊 Congratulations to all of the Q1 MVP's! Thank you for putting in the hard work and making the internet a safer place 🧑
6
8
109
2
1
43
@mertistaken
πš–πšŽπš›πš 🦧
4 years
Thanks for these cool new year gifts, @PicusSecurity 🌝
Tweet media one
2
1
39
@mertistaken
πš–πšŽπš›πš 🦧
1 year
We (w/ @EmreOvunc ) finished the first round of the @Bugcrowd HackerCup event in 2nd place. Good luck to all participants! 🧐 #HackerCup2022 #BCTeamHunt
@Bugcrowd
bugcrowd
1 year
Spector
Tweet media one
0
1
9
1
1
33
@mertistaken
πš–πšŽπš›πš 🦧
8 years
I got it, thanks for all! πŸ‘Š @Bugcrowd
Tweet media one
2
5
32
@mertistaken
πš–πšŽπš›πš 🦧
8 years
Unexpected! They paid half of the value for a duplicate report. Best! @Bugcrowd
Tweet media one
2
6
29
@mertistaken
πš–πšŽπš›πš 🦧
8 years
I was placed 2nd on the Bugcrowd's June Leaderboard.
Tweet media one
6
2
29
@mertistaken
πš–πšŽπš›πš 🦧
8 years
I'm 7th on @Bugcrowd Top10 list in ~4 months. #BugBounty #HardWorking
Tweet media one
3
5
28
@mertistaken
πš–πšŽπš›πš 🦧
5 years
thank you πŸ‘
@Bugcrowd
bugcrowd
5 years
πŸ† Announcing our Q3 2019 Bounty Slayers! πŸ† We're constantly amazed by the awesome work from the #Crowd , keep crushing it! #ItTakesACrowd
Tweet media one
1
6
36
2
0
23
@mertistaken
πš–πšŽπš›πš 🦧
8 years
I'll share some posts that include my experiences usually related to web application security. #bugbounty
0
8
25
@mertistaken
πš–πšŽπš›πš 🦧
8 years
motivation++; Small things from the client can increase motivation for researcher.
Tweet media one
1
1
23
@mertistaken
πš–πšŽπš›πš 🦧
3 years
Bug counter 🌝🌝 Lametric is fun for those who like play with apis. 😁
2
0
22
@mertistaken
πš–πšŽπš›πš 🦧
1 year
I tried the existing ASHX shells but they failed, I edited one of them to get the C# exploit code as base64 and πŸ”₯. decoded base64: var shell = new ActiveXObject(""); var cmd = "cmd.exe /c dir"; var output = shell.Exec(cmd).StdOut.ReadAll(); output;
0
0
19
@mertistaken
πš–πšŽπš›πš 🦧
1 year
(4/4) It's worth noting that this technique only seems to work in Firefox, and the page was an error page so that any extension could be added to the end of the address. πŸ™Œ
0
0
16
@mertistaken
πš–πšŽπš›πš 🦧
2 months
@Bugcrowd @codecancare could I please borrow the chair for a little while? πŸ˜›
3
0
17
@mertistaken
πš–πšŽπš›πš 🦧
9 months
πŸ’―
0
0
15
@mertistaken
πš–πšŽπš›πš 🦧
8 years
Thanks @Bugcrowd πŸ‘
@Bugcrowd
bugcrowd
8 years
Congrats to our May 2016 Leaderboard winners! 1st place @merttasci_ w/ a whopping 786 points
Tweet media one
0
9
30
1
0
15
@mertistaken
πš–πšŽπš›πš 🦧
3 years
πŸ₯³πŸ₯³
@Bugcrowd
bugcrowd
3 years
Bugcrowd has no limit to the amount of amazing researchers, but every once in a while a researcher comes along and shows value, impact and skill above all others! Huge shout out and congrats to all of the Q4 Bugcrowd MVPs. Did you qualify?
Tweet media one
2
10
59
1
0
14
@mertistaken
πš–πšŽπš›πš 🦧
2 years
@_HappyHacker_ @nayeems3c @_2os5 If I have time I test many features of the app for idor, priv esc and unauth access bugs (if there is no time or the application is too large, I only test the most important features).
1
0
13
@mertistaken
πš–πšŽπš›πš 🦧
1 year
(3/4) However, I didn't have a chance to change the start of the content so I tried a different way and exploited the vulnerability by appending '.html' to the end of the URL, forcing the browser to interpret the content as HTML. πŸ”₯
1
0
13
@mertistaken
πš–πšŽπš›πš 🦧
4 years
week 3 failed :( but this was a good challenge, thanks @bugcrowd !! also, congrats to all winners!
@Bugcrowd
bugcrowd
4 years
We’re so excited to announce the winners for the Bugcrowd October Challenge month! With tons of spooky submissions from the Crowd, huge thanks for all of your hard work, tweets and messages about the #BugcrowdChallenge . Spooky swag incoming! πŸ’€ πŸŽƒ
0
5
41
0
0
13
@mertistaken
πš–πšŽπš›πš 🦧
6 years
πŸ•ΊπŸ•Ί
@Bugcrowd
bugcrowd
6 years
Congratulations to all our Researchers who have met and continue to maintain their 2018 #MVP qualifications! #ItTakesACrowd #OuthackThemAll
Tweet media one
0
0
11
4
0
13
@mertistaken
πš–πšŽπš›πš 🦧
7 years
Marked as duplicate #TellASadStoryInThreeWords
1
0
11
@mertistaken
πš–πšŽπš›πš 🦧
7 years
It was an exciting year, thanks @bugcrowd . See you at the end of 2017! 😊
@Bugcrowd
bugcrowd
7 years
Bugcrowd Celebrates Top Researchers with 2016 Bug Bounty Bonus Awards
Tweet media one
8
6
34
0
0
11
@mertistaken
πš–πšŽπš›πš 🦧
1 year
(2/4) Then I noticed that the browser interprets it as plain text because the content doesn't start with an HTML tag. If the content started directly as "<img src=x..." it would be interpreted as HTML even if the Content-Type header is not set.
1
0
10
@mertistaken
πš–πšŽπš›πš 🦧
8 years
-_-
Tweet media one
5
0
9
@mertistaken
πš–πšŽπš›πš 🦧
2 years
Also, thanks to the @synack team for the remaining 10%. Good luck to all researchers for 2023, I hope everyone reaches their goals. πŸ™Œ
0
0
8
@mertistaken
πš–πšŽπš›πš 🦧
2 years
@parkerzanta this was also in the β€œindeed” program. maybe it can help you to increase the impact
1
1
7
@mertistaken
πš–πšŽπš›πš 🦧
8 years
Looks great. :)
@Jhaddix
Jason Haddix
8 years
Congrats to our @Bugcrowd MVPs. Thanks for stopping by the epic happy hour party!
Tweet media one
4
1
31
1
1
8
@mertistaken
πš–πšŽπš›πš 🦧
2 months
@codecancare @GodfatherOrwa @Bugcrowd πŸ™β€οΈ thank you for allowing this Eric! πŸ˜‹
0
0
8
@mertistaken
πš–πšŽπš›πš 🦧
2 years
@Kanhaiya_sh4rma haha congrats mate! πŸ”₯😊
1
0
6
@mertistaken
πš–πšŽπš›πš 🦧
7 years
Yay! πŸ‘
@evrnyalcin
Evren
7 years
Hi from Turkey ^^ Me and @merttasci_ now finalist on 2nd annual @Bugcrowd 's Buggy Awards.
4
6
32
0
2
7
@mertistaken
πš–πšŽπš›πš 🦧
10 months
0
0
7
@mertistaken
πš–πšŽπš›πš 🦧
2 years
@EmreOvunc a great achievement, congrats mate. nicelerine πŸ™
0
0
6
@mertistaken
πš–πšŽπš›πš 🦧
2 years
@NahamSec Don't relax and drop the test if you find an important bug! Try to dig deeper, if you find one, you can find more than one.
0
0
5
@mertistaken
πš–πšŽπš›πš 🦧
4 months
@krishnsec glad to hear it mate, keep going!! πŸ”₯πŸ”₯
1
0
6
@mertistaken
πš–πšŽπš›πš 🦧
3 years
also, thanks to @hakluke and @vortexau for help on each edge case. 🌝
2
0
5
@mertistaken
πš–πšŽπš›πš 🦧
1 year
1
0
4
@mertistaken
πš–πšŽπš›πš 🦧
1 year
@krishnsec @Masonhck3571 @Bugcrowd it feels good to see hard work pay off but it'd be better to ask this question to @codecancare πŸ‘€
2
0
4
@mertistaken
πš–πšŽπš›πš 🦧
2 years
0
0
3
@mertistaken
πš–πšŽπš›πš 🦧
8 years
@iamnoooob @Bugcrowd huh! $337.07... Found the cause of my last dupe reports. :) Great job bro, congrats! ^_^
1
0
4
@mertistaken
πš–πšŽπš›πš 🦧
2 years
@Bugcrowd thanks to @EmreOvunc for the great collabs! πŸ‘Š
0
0
4
@mertistaken
πš–πšŽπš›πš 🦧
2 years
@_HappyHacker_ @nayeems3c @_2os5 I'm trying to understand how the app works and imagine what weird things might be. β™₯️
1
0
4
@mertistaken
πš–πšŽπš›πš 🦧
7 years
@samhouston Thanks! 😊 @Bugcrowd
0
0
4
@mertistaken
πš–πšŽπš›πš 🦧
1 year
@krishnsec @Bugcrowd congrats man! πŸ”₯ πŸ™Œ
1
0
3
@mertistaken
πš–πšŽπš›πš 🦧
7 months
@haxor31337 @Bugcrowd congrats mate!! πŸ’―πŸ™Œ
1
0
3
@mertistaken
πš–πšŽπš›πš 🦧
4 months
0
0
3
@mertistaken
πš–πšŽπš›πš 🦧
8 years
@Jhaddix yes, I'm sure of that. Researchers are really fast in priv8 programs.
0
0
3
@mertistaken
πš–πšŽπš›πš 🦧
8 months
@GodfatherOrwa @Bugcrowd congrats mate! πŸ™Œ
1
0
2
@mertistaken
πš–πšŽπš›πš 🦧
2 years
0
0
2
@mertistaken
πš–πšŽπš›πš 🦧
8 years
@DarkieDuck @zseano @mongobug Haha, I don't plan holiday these days. πŸ™ˆ
1
0
3
@mertistaken
πš–πšŽπš›πš 🦧
8 years
@nijagaw art of XSS. πŸ˜€
0
0
3
@mertistaken
πš–πšŽπš›πš 🦧
6 years
@knowledge_2014 @Bugcrowd thanks bro, you too! :)
0
0
3
@mertistaken
πš–πšŽπš›πš 🦧
3 years
@dmxjon @Bugcrowd thanks β™₯️ RCE.
0
0
3
@mertistaken
πš–πšŽπš›πš 🦧
5 years
@A_Burak_Gokalp πŸ‘ŠπŸ–πŸ‘ŠπŸ–
1
0
3
@mertistaken
πš–πšŽπš›πš 🦧
10 months
@krishnsec @Bugcrowd thank you for your kind words brother! πŸ™Œβ™₯️
0
0
3
@mertistaken
πš–πšŽπš›πš 🦧
5 years
@evrnyalcin πŸ”₯ πŸ”₯ πŸ”₯
0
0
3
@mertistaken
πš–πšŽπš›πš 🦧
6 years
@evrnyalcin @Bugcrowd @caseyjohnellis it's nice! I hope we can keep this streak. πŸ™‚
1
0
3
@mertistaken
πš–πšŽπš›πš 🦧
4 months
@krishnsec wow, old but gold πŸ₯²
0
0
2
@mertistaken
πš–πšŽπš›πš 🦧
1 month
0
0
2
@mertistaken
πš–πšŽπš›πš 🦧
3 years
@bwnz_ @Bugcrowd thank you so much β™₯️ this is really irregular for me. some weeks only 5-10 hours, sometimes 30+.
0
0
2
@mertistaken
πš–πšŽπš›πš 🦧
1 year
@Masonhck3571 @Bugcrowd congrats mate!! πŸ”₯πŸ”₯
1
0
2