Siddhartha S Profile Banner
Siddhartha S Profile
Siddhartha S

@sidharthas8962

Followers
1,063
Following
334
Media
57
Statuses
511

Security Researcher

same planet as you
Joined February 2022
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
Pinned Tweet
@sidharthas8962
Siddhartha S
3 days
Hello everyone, I found 100 of emails of customers by running waybackurls on my target, now after visiting the URL I can send unlimited password reset emails to customers. I reported this to company, and they didn't consider it. any tip to increase my severity. #hackingtime
Tweet media one
Tweet media two
14
5
156
@sidharthas8962
Siddhartha S
3 months
Hello everyone, I have just found a API-Key in .Js file. But don't know what kind of this API-Key is? If you have any idea about, where I can identify this. Please let me know. #Hackingtime #BugBounty
Tweet media one
37
19
364
@sidharthas8962
Siddhartha S
10 days
Hello everyone. I have found a stored xss. payload by @coffinxp7 <details x=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx:2 open ontoggle="prompt(document.cookie);">
Tweet media one
7
38
308
@sidharthas8962
Siddhartha S
3 months
Hello everyone, I have found again Information Disclosure bug on BBP, hope they reward. #Hackingtime #BugBounty
Tweet media one
8
12
168
@sidharthas8962
Siddhartha S
5 months
Today I have found 10+ CORS misconfiguration in 2 websites with valid Video POC and screenshot also. 3 reported. I used an automatic tool and then I checked manually for Video POC. A special thanks for my friend and supportive @coffinxp7 #BugBounty #hackers
Tweet media one
8
16
155
@sidharthas8962
Siddhartha S
3 months
Mass hunting of CVE-2024-34102 A big thanks to @coffinxp7 for amazing idea. but don't know if they are running bug bounty program or not, could you please help me. @coffinxp7
Tweet media one
Tweet media two
Tweet media three
6
14
150
@sidharthas8962
Siddhartha S
4 months
Hey everyone, I have found 3 bugs in just 30 minutes. 1. html injection 2. html injection to open redirection and redirected to CIA.🥰😍 3. reflected XSS #bugbounty #bugbountytips
8
1
145
@sidharthas8962
Siddhartha S
2 months
Hello everyone, I have found a stored XSS by @coffinxp7 payload.
Tweet media one
6
4
124
@sidharthas8962
Siddhartha S
28 days
Hello everyone, during my directory-brute forcing on target subdomain by dirb, I have found multiple directories with 200 OK but when I check manually it is giving me error 404 not found. I don't know why. have you any suggestions, let me know #Hackingtime
Tweet media one
29
3
125
@sidharthas8962
Siddhartha S
4 months
Hey @coffinxp7 your XSS payload is really worked for me, thanks again for sharing. let's see what happens next because payload fired in chatbot which is created by program itself.
Tweet media one
8
1
126
@sidharthas8962
Siddhartha S
4 months
I have found a XSS on A BBP. hey @coffinxp7 you payload is really help full. I have just copied the payload and open BBP and paste the payload after the hit Enter the payload got fired.
Tweet media one
8
13
124
@sidharthas8962
Siddhartha S
4 months
Hey everyone, recently I have found a bug here are the details: Bug type: sensitive information discloser Bounty: 150EUR thanks to #bugbounty #Hackingtime
Tweet media one
11
2
88
@sidharthas8962
Siddhartha S
3 months
Hello everyone, I have found multiple API-key disclosure in .JS fiie. on BBP. hope they reward #Hackingtime #BugBounty
Tweet media one
15
1
89
@sidharthas8962
Siddhartha S
5 months
I have found 30+ Blind XSS in one website. almost every parameter is vulnerable to blind xss. #bugbounty #hackers
7
8
84
@sidharthas8962
Siddhartha S
4 months
Hey everyone, I have found multiple HTML injection in chat bot, should I report this? #BugBounty #bugbountytips 1. payload <img src="index.jpg" alt=" @coffinxp in a Jacket" width="1000" height="600">
Tweet media one
Tweet media two
Tweet media three
Tweet media four
6
10
83
@sidharthas8962
Siddhartha S
20 days
Hello everyone, I have found a stored XSS via Svg file upload, payload credit my brother @coffinxp7 #hackingtime Hey @coffinxp7 can you share your favorite image I want to try like this
Tweet media one
Tweet media two
Tweet media three
@coffinxp7
Coffin 
4 months
FINALLY I HACKED NASA ! (subdomain) @NASA
180
153
2K
3
6
57
@sidharthas8962
Siddhartha S
1 month
Hello everyone, is this causing a bug.? it has lots of information. #hackingtime
Tweet media one
Tweet media two
13
0
56
@sidharthas8962
Siddhartha S
1 month
Hello everyone, I was hunting on a program, during directory-brute forcing I have found a folder like /git/ I opened the domain and found this>> but don't what is this, if you have any idea, please let me know.
Tweet media one
12
3
53
@sidharthas8962
Siddhartha S
4 months
@Steiner254 @coffinxp7 <iframe srcdoc="<img src=x onerror=alert(999)>"></iframe> /path?next=javascript:top[/al/.source+/ert/.source](document.cookie) login?redirectUrl=javascript%3avar{a%3aonerror}%3d{a%3aalert}%3bthrow%2520document.domain
0
10
47
@sidharthas8962
Siddhartha S
3 months
Hello everyone, recently I have submitted a bug to h☆☆☆☆1 But got duplicate after 3 informational because this was submitted by another Researcher. But I am happy with that. Atleast I have found a valid bug I think. #Hackingtime #bugbounty
Tweet media one
7
1
46
@sidharthas8962
Siddhartha S
3 months
Hello everyone, I have found an Information Disclosure bug, Index of /. git but after checking their BB page they clearlily have mentioned that they don't provide bounty for bugs, So I didn't report them. They also have bbp on bug crowd. #Hackingtime #BugBounty
Tweet media one
Tweet media two
3
2
44
@sidharthas8962
Siddhartha S
26 days
Hello everyone, I have just got small 50$ bounty for reporting a bug. Bug type> AWS Api-KEY disclosure #Hackingtime #bugbounty
11
1
40
@sidharthas8962
Siddhartha S
4 months
Hello everyone, help me to understand this. #bugbountytip @coffinxp7 even my BXSS payload also fired here.
Tweet media one
Tweet media two
Tweet media three
Tweet media four
6
1
30
@sidharthas8962
Siddhartha S
5 months
Hello everyone I have found a file called /.DS_Store via directory brute forcing. is this sensitive, should I report it. #bugbounty #hackers
8
1
31
@sidharthas8962
Siddhartha S
4 months
Update: they replied, we use a third-party vendor for this msg'ing function so nothing we can do on our side. I agreed with them, because they cleared mention in their policy. by the away i have learned a new bug type. #BugBounty #Hackingtime
@sidharthas8962
Siddhartha S
4 months
Hey everyone, I have found multiple HTML injection in chat bot, should I report this? #BugBounty #bugbountytips 1. payload <img src="index.jpg" alt=" @coffinxp in a Jacket" width="1000" height="600">
Tweet media one
Tweet media two
Tweet media three
Tweet media four
6
10
83
0
1
24
@sidharthas8962
Siddhartha S
3 months
Happy birthday to a mastermind hacker who continuously pushes the boundaries of possibility. May your skills remain sharp, and may you always stay one step ahead. Have an amazing celebration! Keep hacking. "Best wishes for you, as a Security Researcher prospective" @coffinxp7
Tweet media one
1
1
23
@sidharthas8962
Siddhartha S
3 months
Hello everyone, I have found REACT_APP_FIREBASE_DEV_API_KEY disclose in .js file. but Company said this is not vulnerability. how can escalate to this, if possible, if you have any idea, please let me know, #Hackingtime #BugBounty
Tweet media one
2
0
22
@sidharthas8962
Siddhartha S
3 months
I will never forget the day. We met for the first time on social media and I was completely unaware that you would mean so much to me. @coffinxp7 @hexsh1dow @sidharthas8962
@coffinxp7
Coffin 
3 months
nOne can fix me Expect this
1
3
45
4
1
18
@sidharthas8962
Siddhartha S
1 month
Hello brother, @coffinxp7 I tried your BSQLI tool on different-different website, And I think it's the best tool for find bsqli with automation, but when I visit the vulnerable url/parameter the WAF is blocking me. Any suggestions.?
1
1
19
@sidharthas8962
Siddhartha S
3 months
Great achievement brother. Keep pushing the boundaries of hacking In ethical way. #Longlive @coffinxp7 #lostsec
@coffinxp7
Coffin 
3 months
Thank you so much guys for 10k Family 🎉😇❤️
Tweet media one
20
14
251
1
1
17
@sidharthas8962
Siddhartha S
5 months
Recently I was hunting bugs on a private program. when I was analyzing the .js file, I found this amazon_aws_access_key_id = AkiAknZCcwHAwAusAD98 is this bug or not. If its bug then what's impact of this, and how can show impact to that program. #bugbounty @coffinxp7 @_anonysm
4
1
15
@sidharthas8962
Siddhartha S
5 months
I was analyzing .js file and found this. If you have any idea please let me know. #BugBounty
Tweet media one
2
0
15
@sidharthas8962
Siddhartha S
5 months
Hey @coffinxp7 can you please make a video about csrf how can find, report, all about csrf, also how can I find csrf by XSRFProbe tool.
1
0
14
@sidharthas8962
Siddhartha S
4 months
Hello everyone I have found a subdomain takeover vulnerability which is vulnerable to helpscout. But I am not able to create a account because there strict signup prosses. What should I do? #bugbounty #bugbountytips
0
0
14
@sidharthas8962
Siddhartha S
5 months
@ChetnaP3 var a=document.createElement("script");a.src="";document.body.appendChild(a);
0
2
14
@sidharthas8962
Siddhartha S
4 months
@torik_1999 @coffinxp7 <details x=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx:2 open ontoggle="prompt(document.cookie);">
0
0
14
@sidharthas8962
Siddhartha S
4 months
Hey @coffinxp7 what color your Bugatti is. I can design in html let's see some sample if this is your favorite color let me know. 😍🥰 #bugbounty #bugbountytips comment for color change. HTML injection.
Tweet media one
Tweet media two
1
0
14
@sidharthas8962
Siddhartha S
4 months
Great achievement brother. Keep growing.
@coffinxp7
Coffin 
4 months
created a powerful Blind SQLi tool that detect sqli with 100% acuracy with 0% false postive issue uploading soon.. just working on the all types payloads for different DBMS
Tweet media one
28
78
621
1
1
12
@sidharthas8962
Siddhartha S
3 months
Hey @coffinxp7 can you please make a video on "mass hunting on remote code execution"
2
0
12
@sidharthas8962
Siddhartha S
23 days
Hey @coffinxp7 show me your Phone wallpaper.
Tweet media one
1
0
13
@sidharthas8962
Siddhartha S
5 months
I have found multiple directory listening vulnerability leads to disclose sensitive information in self hosted VRP which are providing bounty for that, but till that no response from companies. #BugBounty #hackers
1
1
12
@sidharthas8962
Siddhartha S
5 months
I have submitted a bug report to a BBP, the company reply my mail here are screenshot.
Tweet media one
1
0
11
@sidharthas8962
Siddhartha S
3 months
Happy to see my brother @coffinxp7 that you have achieved 10k followers on @X Wishing a filled with clandestine operations, encrypted communications, and ingenious exploits to a hacker who walks the line between genius and madness. Celebrate your day in true hacker fashion!
2
1
11
@sidharthas8962
Siddhartha S
3 months
Hey @coffinxp7 how to find ip addresses of all subdomain in one step, do you have any tool which can find ip addresses of subdomain file file. Please let me know. #bug #hacking
0
0
10
@sidharthas8962
Siddhartha S
3 months
Are you BlackHat Hacker. If yes then you need to hide you identity forever from internet. Because you have performed multiple cyber attacks and defaced there website/organization. Bye the away I love your content and your hacking skills. Keep hacking, keep growing.
@coffinxp7
Coffin 
3 months
This is how much BlackHat Hacker Earns :)
24
32
378
3
0
11
@sidharthas8962
Siddhartha S
9 days
Knock knock FBI FBI They are searching you, by land to land because they can't trace your location.
@coffinxp7
Coffin 
9 days
Malaysia top gambling casino betting site Strong WAF Bypassed ! But they have not contact email support what i do now ?
Tweet media one
22
9
209
1
0
11
@sidharthas8962
Siddhartha S
4 months
@rhetoric_URBAN </script>'"><img src=x onError=prompt(1)>
0
1
11
@sidharthas8962
Siddhartha S
11 days
Wow, happy to see that I am verified. Without buying premium.
Tweet media one
2
0
10
@sidharthas8962
Siddhartha S
3 months
Agreed.
@coffinxp7
Coffin 
3 months
no one is permanent in life, everyone comes for a particular period of time. so enjoy the phase of life & move on
4
5
64
0
0
9
@sidharthas8962
Siddhartha S
4 months
I have gained 100 followers in just 24 hours, Thanks to everyone. #bugbountytip
0
0
10
@sidharthas8962
Siddhartha S
28 days
Don't disappear brother. FBI needs you for catching cyber criminalS
@coffinxp7
Coffin 
28 days
𝙀𝙫𝙚𝙧𝙮𝙊𝙣𝙚 𝙞𝙨 𝙬𝙤𝙧𝙠𝙞𝙣𝙜 𝙩𝙤 𝙗𝙚 𝙨𝙚𝙚𝙣 𝙄'𝙖𝙢 𝙬𝙤𝙧𝙠𝙞𝙣𝙜 𝙩𝙤 𝘿𝙞𝙨𝙖𝙥𝙥𝙚𝙖𝙧
11
7
184
1
0
9
@sidharthas8962
Siddhartha S
15 days
Congratulations brother.
@coffinxp7
Coffin 
15 days
our latest bug hunting tool is featured in Recorded Future insikt research artical threat intel platform this is crazyy🔥🏆
Tweet media one
16
27
248
1
0
9
@sidharthas8962
Siddhartha S
5 months
@kuroOowannafly var a=document.createElement("script");a.src="";document.body.appendChild(a);
1
0
9
@sidharthas8962
Siddhartha S
4 months
Hey @coffinxp7 what is this? I am very disappointed bro.
Tweet media one
1
0
8
@sidharthas8962
Siddhartha S
3 months
Once again, Wishing a mind-blowing birthday to a hacker whose coding skills are the envy of the digital underworld. May your exploits be celebrated, your systems impenetrable, ""and your identity forever hidden in the shadows."" Keep hacking like professional. @coffinxp7
Tweet media one
1
0
7
@sidharthas8962
Siddhartha S
5 months
Note:: always use wpscan if your target website is running on wordpress for find directory listening bugs and other bugs like theme and plugins related. Cmd:: wpscan --url --api key -e --random agent -f for force if there any waf if blocking you...
0
1
7
@sidharthas8962
Siddhartha S
3 months
Hello everyone, again submitted a by me got duplicate, because its reported by another Researcher. Feel sad, why companies didn't pathed the bug if they have already information of that bug or submitted by another Researcher #Hackingtime #BugBounty
Tweet media one
2
0
7
@sidharthas8962
Siddhartha S
5 months
Hello everyone. I have embedded a XSS payload in pdf file. when I was trying to open this file in Firefox or chrome. the XSS payload is triggered. is this bug or not. #bugbounty #hackers @coffinxp7 Kindly help.
Tweet media one
4
1
7
@sidharthas8962
Siddhartha S
4 months
@NishanShil72327 /.git/config
1
1
6
@sidharthas8962
Siddhartha S
3 months
Hello Security Team of @recruitlyio I have submitted a bug to you 2 month ago by email. Why did you haven't pathed the bug and didn't response, if you don't care about Security, then why are running bug bounty for just show off that you care about Security and user privacy.
1
0
6
@sidharthas8962
Siddhartha S
2 months
Mine is LostSec_007
Tweet media one
@coffinxp7
Coffin 
2 months
what's your WIFI name mine is this one :)
Tweet media one
49
22
382
1
0
6
@sidharthas8962
Siddhartha S
4 months
@coffinxp7 @Hacker0x01 @ICICIBank @ICICIBank_Care Because they don't care of user data, privacy. I have also found multiple bugs in Indian private bank, but I didn't receive any response from 15 days.
0
0
6
@sidharthas8962
Siddhartha S
3 months
Hello Team of @Wildix_ I have submitted multiple bugs report to you by email. Kindly patch the bugs as soon as possible. and response. Sidhartha Security Researcher
0
1
5
@sidharthas8962
Siddhartha S
3 months
Hello @RunOnFlux I have submitted a Vulnerability report to you by email, why guys you all not responding to researcher mails. if you haven't time to reply to researcher mails, then why your running Bug Bounty program on internet.
Tweet media one
0
1
6
@sidharthas8962
Siddhartha S
2 months
Hello everyone, recently I have submitted 4 Information Disclosure bugs to bugcrowd. Here are the details. 1nd duplicate, submitted by another Researcher. 2nd duplicate, submitted by another Researcher 3nd not applicable 4nd not applicable due to not exploit. #Hackingtime #Bugs
Tweet media one
Tweet media two
Tweet media three
Tweet media four
1
0
6
@sidharthas8962
Siddhartha S
3 months
Tabahi
0
0
5
@sidharthas8962
Siddhartha S
10 days
Tweet media one
@0xchoudhary
Sushil Choudhary
10 days
👀
Tweet media one
2
1
54
0
0
5
@sidharthas8962
Siddhartha S
4 months
@pentesterzaman So basically I used dirb tool for directory brute forcing and I found /.git/config enabled I visited the url and found some Information. I reported.
1
1
5
@sidharthas8962
Siddhartha S
3 months
@coffinxp7 @InternetH0F Hope I will join you in future. And do some contribution to hack the scammers.
0
0
5
@sidharthas8962
Siddhartha S
4 months
bxss payload fired here.
Tweet media one
1
0
5
@sidharthas8962
Siddhartha S
6 months
I have found my first bug on private program. through @bugcrowd but its informational because I am unable to exploit the bug. But I am happy with that.
Tweet media one
1
0
4
@sidharthas8962
Siddhartha S
5 months
@coffinxp7 Can you share this template. Please
0
0
5
@sidharthas8962
Siddhartha S
2 months
I will try and share result with you soon. Brother, By the away thanks for sharing. I know it will be cool..
@coffinxp7
Coffin 
2 months
so finally wait is over i released my customBsqli tool i hope this will help you all in bbp to find timebased sqli..
31
126
533
2
0
5
@sidharthas8962
Siddhartha S
5 months
hey @IDFCFIRSTBank I am A Security Researcher I have found multiple bugs on your website. How can I report to you. That you can secure your website/web applications,
1
1
5
@sidharthas8962
Siddhartha S
4 months
and also, this.
Tweet media one
Tweet media two
1
0
4
@sidharthas8962
Siddhartha S
3 months
Hello @InfoSecComm I have found some bugs on your site, how can I report to you. let me know. #Hackingtime #BugBounty
0
0
4
@sidharthas8962
Siddhartha S
5 months
Hey @immunefi I am Security Researcher. I have found a bug in a bug bounty program which are registered on your platform, I want to submit report to that program, but I am confused what type of wallet need to receive a payment. Kindly Response.
3
0
4
@sidharthas8962
Siddhartha S
2 months
- Physical and mental health concerns: Hunters must prioritize self-care to avoid burnout and health issues. In summary, while bug bounty hunting can be a rewarding career, it comes with significant financial, emotional, and professional challenges also. Photos by @AIatMeta
Tweet media one
Tweet media two
Tweet media three
0
0
4
@sidharthas8962
Siddhartha S
5 months
@_anonysm The power of your subconscious mind. By Dr. Joseph Murphy You should also read this book. My recommendation.
1
0
4
@sidharthas8962
Siddhartha S
3 months
Hello @bugvsecurity I created a account on and did not receive verification email. I am unable to login.
0
0
4
@sidharthas8962
Siddhartha S
3 months
@coffinxp7 @hexsh1dow @rinz0h @PortSwigger @github Life is full of this type of people everywhere, don't be sad @coffinxp7 If the Team of portswigger or github forced you delete that, then delete it brother. You have faced takedown of multiple channel's, yt videos and manythings.
1
0
4
@sidharthas8962
Siddhartha S
19 days
Hello everyone, this is my first time, I am trying to find ssrf, I have attached the interactsh payload in svg and uploaded into profile pictures, and don't know next steps. if it is valid. please let me know if you have any references. #Hackingtime
Tweet media one
0
0
4
@sidharthas8962
Siddhartha S
4 months
Keep hacking..
@coffinxp7
Coffin 
4 months
FINALLY I HACKED NASA ! (subdomain) @NASA
180
153
2K
0
0
4
@sidharthas8962
Siddhartha S
6 months
Hello @helpscout I want to create a account for my web application. But unfortunately I couldn't create a account. Please try to solve my problem as soon as possible. Please @help @helpscout . I am waiting for your response.
2
0
2
@sidharthas8962
Siddhartha S
2 months
*Continuous Learning Required* - Constantly evolving field: Cybersecurity and technology are constantly changing - Significant time and effort required: Hunters must stay up-to-date with the latest tools, techniques, and technologies.
1
0
3
@sidharthas8962
Siddhartha S
2 months
*High Stress Levels* - Pressure to constantly find bugs: Hunters are under pressure to meet program requirements and stay ahead of the competition - Fear of missing out (FOMO): Hunters may feel anxious about missing potential bugs or payouts.
1
0
3
@sidharthas8962
Siddhartha S
5 months
@coffinxp7 That's why I only report to sensitive endpoint like Is this sensitive endpoints or not. Please reply?
1
0
3
@sidharthas8962
Siddhartha S
5 months
WhatsApp will exit india if forced to break the encryption saying, @WhatsApp
0
1
2
@sidharthas8962
Siddhartha S
3 months
@coffinxp7 How to setup this tool?.
1
0
3
@sidharthas8962
Siddhartha S
10 days
@HackenProof You should start giving money for hackers for p5 submission. I hope you understand.
1
0
3
@sidharthas8962
Siddhartha S
3 months
Hello @RunOnFlux I have found a bug on your web-application, how can I report to you.
1
0
3
@sidharthas8962
Siddhartha S
3 months
long live @coffinxp7 #lostsec my favorite.
0
0
3
@sidharthas8962
Siddhartha S
2 months
*Isolation and Solo Work* - Limited social interaction: Bug bounty hunting can be a solo activity - Isolation can lead to feelings of loneliness and disconnection. *Other Disadvantages*
1
0
3
@sidharthas8962
Siddhartha S
2 months
- Long hours and flexible schedule: Hunters may work irregular hours to meet program deadlines - Limited benefits: No traditional employment benefits like health insurance, retirement plans, or paid time off - Legal and ethical risks: Hunters must navigate complex guidelines.
1
0
3
@sidharthas8962
Siddhartha S
2 months
1
0
3
@sidharthas8962
Siddhartha S
5 months
Hello @duocirclellc I am a Security Researcher I have submitted bug report to you. Why your are not responding to us. Fix the bug and Response.
1
0
3
@sidharthas8962
Siddhartha S
5 months
@tabaahi_ I was also hunting found /.htaccess file its is bug or not? Kindly Response brother.
0
0
3
@sidharthas8962
Siddhartha S
2 months
@coffinxp7 @hexsh1dow Thanks, bro, for helping us.
0
0
3