Vivek Kashyap Profile Banner
Vivek Kashyap Profile
Vivek Kashyap

@starkcharry

Followers
2,099
Following
412
Media
147
Statuses
1,849

Bug Hunter | Delhi Technological University

127.0.0.1
Joined December 2020
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
Pinned Tweet
@starkcharry
Vivek Kashyap
1 year
I earned $2,500 for my submission on @bugcrowd 💝 Tip : "GET request for XML not found" changes the request to POST with XXE payload. #ItTakesACrowd #bugcrowd
Tweet media one
17
28
302
@starkcharry
Vivek Kashyap
7 months
I earned $1400 for my 7 submissions on @bugcrowd #ItTakesACrowd
Tweet media one
14
15
328
@starkcharry
Vivek Kashyap
2 years
MY First RCE from N/A to Triaged tip: shodan Ssl:"target Inc." 200 http.title look for palo alto networks (vps) https://target. com/global-protect/login.esp vuln version 8.1.15 #bugbounty #bugbountytips #ItTakesACrowd #infosec
Tweet media one
19
107
292
@starkcharry
Vivek Kashyap
2 years
I earned $1,450 for my submission on @bugcrowd 🥳 2023 First Bounty @Mohamed87Khayat @krishnsec @GodfatherOrwa Thank you! #ItTakesACrowd #BugBounty
Tweet media one
12
8
223
@starkcharry
Vivek Kashyap
8 months
BugBounty 😅
Tweet media one
15
1
200
@starkcharry
Vivek Kashyap
8 months
I think I've cooked something @Bugcrowd
Tweet media one
10
4
178
@starkcharry
Vivek Kashyap
1 year
I earned $2,500 for my submission on @bugcrowd 💝 Thanks to @Bugcrowd for helping me in this report. #ItTakesACrowd #bugcrowd
Tweet media one
13
6
169
@starkcharry
Vivek Kashyap
1 year
Again Collaborated with @krishnsec brother. 💝 #ItTakesACrowd
Tweet media one
8
9
173
@starkcharry
Vivek Kashyap
3 years
Information disclosure $$$ 1. subfinder -d target. com | httprobe -c 100 > target.txt got around 210 subdomains. 2. cat target.txt | aquatone -out ~aquatone/target 3. Checked every screenshot and found an interesting subdomain. #bugbountytips #bugbounty #infosec
7
47
163
@starkcharry
Vivek Kashyap
3 years
Another hit😍 ,I was manually checking GitHub and reported them and today they send me this also I am just 18 please let me know what should I message them @HackerGautam ? And again thank you so much @GodfatherOrwa @HackerGautam @theXSSrat #bugbounty #bugbountytip #infosec
Tweet media one
10
17
157
@starkcharry
Vivek Kashyap
3 years
Account takeover worth $$$$ 1. Created account on website using test mail id 2. Upload private document like resume and photos 3. Same site having android app > Created account using same mail id but different password 1/2 #bugbountytips #bugbounty #infosec
11
43
156
@starkcharry
Vivek Kashyap
3 years
Another Bounty after 2 months total 4000 rupees , ₹3000 is for hard-core GitHub leak thanks to @GodfatherOrwa for his blog & ₹1000 is for reflected XSS on 2 subdomain thanks to @HackerGautam for his script to automate XSS finding #bugbounty #bugbountytip #infosec
Tweet media one
14
10
142
@starkcharry
Vivek Kashyap
1 year
Happy to collaborate with @krishnsec 👑 $$$$ SSTI to RCE
Tweet media one
6
7
135
@starkcharry
Vivek Kashyap
2 years
In February I submitted 27 reports to 6 programs. Bugcrowd 93.3 success rate Special reports : Sony , Facebook Tip : just deeply follow @GodfatherOrwa write-ups,videos #bugbounty #bugbountytips
2
8
130
@starkcharry
Vivek Kashyap
3 years
Today is a special day for me I started learning bug hunting almost 2 months ago and today I got my First Bounty for Stored XSS I would like to thanks everyone @AnubhavSingh_ @cyph3r_asr @hunter0x7 @harshbothra_ @HackerGautam @theXSSrat #bugbounty #firstbounty #bugbountytips
Tweet media one
19
9
128
@starkcharry
Vivek Kashyap
1 year
I earned $650 for my submission on @bugcrowd #ItTakesACrowd
Tweet media one
6
5
123
@starkcharry
Vivek Kashyap
2 years
BOOM BOOM BOOMER 🫣 ALL RECON NO SCRIPTS 😎 @Bugcrowd #bugbounty
Tweet media one
Tweet media two
14
11
122
@starkcharry
Vivek Kashyap
2 years
Good morning!! First Triaged on Hackerone Thankyou @GodfatherOrwa #bugbounty #bugbountytips
Tweet media one
9
0
110
@starkcharry
Vivek Kashyap
2 years
I earned $500 for my submission on @bugcrowd February Rain $$$ #ItTakesACrowd @GodfatherOrwa @krishnsec
Tweet media one
5
5
98
@starkcharry
Vivek Kashyap
2 years
This was interesting. Tip : found a subdomain target-internal. com signup/in functionality was there so its obvious p1 just signup and can easily see internal data but i tried xss so register again but in name field put xss payload 1/2 #bugbounty #bugbountytips
Tweet media one
12
20
95
@starkcharry
Vivek Kashyap
3 years
Tweet media one
2
21
93
@starkcharry
Vivek Kashyap
7 months
2024 starts @intigriti
Tweet media one
10
5
88
@starkcharry
Vivek Kashyap
2 years
😁xss after a while #bugbounty
Tweet media one
12
5
70
@starkcharry
Vivek Kashyap
1 year
I turned 20 today. Thanks for the opportunities @Bugcrowd 💓
Tweet media one
30
0
75
@starkcharry
Vivek Kashyap
2 years
Another report Triaged on @Hacker0x01 Same issue but in different location #bugbounty #bugbountytips
Tweet media one
10
3
70
@starkcharry
Vivek Kashyap
2 years
Tweet media one
5
1
65
@starkcharry
Vivek Kashyap
2 years
Tweet media one
7
0
62
@starkcharry
Vivek Kashyap
2 years
1 program 5 RXSS , 1SXSS(N/A Don't know why) 2 Duplicate 🥹 only recon #bugbounty
Tweet media one
6
0
57
@starkcharry
Vivek Kashyap
2 years
Can't believe I Just reported a xss on Facebook I think it's gonna out of scope #bugbounty #bugbountytips
4
3
56
@starkcharry
Vivek Kashyap
2 years
Guessing I made a silly mistake , what I did was discover origin ip and no waf was there so got .env access exposing credentials, I made only one report should I made another report telling that origin ip disclose?? #bugbounty
Tweet media one
8
2
51
@starkcharry
Vivek Kashyap
2 years
😁One More New Phone😁 #bugbounty
Tweet media one
Tweet media two
3
1
50
@starkcharry
Vivek Kashyap
2 years
Tweet media one
Tweet media two
4
0
48
@starkcharry
Vivek Kashyap
10 months
I had a great conversation with @HusseiN98D at @bsidesahmedabad event. thank you for your valuable advice and guidance.
Tweet media one
1
1
49
@starkcharry
Vivek Kashyap
1 year
Tweet media one
4
1
47
@starkcharry
Vivek Kashyap
2 years
Thank you @PentesterLab Awesome stickers. #bugbounty
Tweet media one
3
2
43
@starkcharry
Vivek Kashyap
3 years
reported /.git exposed to private program and they said In order to be a triaged issue a submission must demonstrate an impact that can have an effect on the customer, or its users. Submissions should always answer the question "as an attacker I could", 1/2 #bugbountytips
12
6
40
@starkcharry
Vivek Kashyap
3 years
Tweet media one
4
1
41
@starkcharry
Vivek Kashyap
2 years
After a Heavy conversation💭💬🗯. #bugbounty
Tweet media one
2
1
39
@starkcharry
Vivek Kashyap
1 year
If you see your Target scopes are full of dead subdomains, then you should do a FULL Port scan & IP permutation you will see a huge difference and become closer to Bounty. (Don't try in akamai waf & cloudflair it will waste your time waste) Happy Hunting!..
2
4
34
@starkcharry
Vivek Kashyap
2 years
Tip of this submission: track every endpoint/parameters you see in a subdomain --> use Arjun/kxss/paramspider tool --> reflected param --> automation then manual trying for XSS/SQLi --> bounty
0
9
34
@starkcharry
Vivek Kashyap
2 years
Back to Back 😋 @Hacker0x01 #bugbounty
Tweet media one
2
0
30
@starkcharry
Vivek Kashyap
2 years
I'm planning to write a blog on my techniques to find hidden subdomains of a Wide Scope Program. You guys will love it. very soon #bugbountytips
6
0
30
@starkcharry
Vivek Kashyap
2 years
I'm testing a target there is an option called add video link so after that in collaborator showing http response but there is my public IP is it acceptable what else should I do? #bugbounty #ssrf
Tweet media one
9
3
27
@starkcharry
Vivek Kashyap
2 years
🙂19. Any suggestions for me.
Tweet media one
16
1
27
@starkcharry
Vivek Kashyap
2 years
Tweet media one
3
5
25
@starkcharry
Vivek Kashyap
2 years
Is there Any Tools to find Acquisition and Subsidiary of a company? #bugbounty #bugbountytips
9
0
25
@starkcharry
Vivek Kashyap
2 years
Joined @pentabug Red Team.
Tweet media one
2
0
24
@starkcharry
Vivek Kashyap
1 year
Use this Google Dorking
@TakSec
Mike Takahashi
1 year
Google Dork - Juicy Endpoints site:target[.]com ext:jsp | ext:asp | ext:aspx | ext:pl | ext:cfm | ext:py | ext:rb
Tweet media one
3
92
313
0
2
22
@starkcharry
Vivek Kashyap
3 years
Bought a new phone today
4
0
21
@starkcharry
Vivek Kashyap
2 years
1
0
19
@starkcharry
Vivek Kashyap
1 year
Any disadvantages of buying a MacBook Air M1 for bugbounty? Best windows laptop or a MacBook M1? #BugBounty #bugbountytips #infosec
10
0
17
@starkcharry
Vivek Kashyap
10 months
@Rohan_Lew 🤣🤣🤣 bikhari spotted
0
0
17
@starkcharry
Vivek Kashyap
1 year
How many of you guys are attending @bsidesahmedabad 2023 Excited !!
Tweet media one
4
0
18
@starkcharry
Vivek Kashyap
1 year
@krishnsec @Bugcrowd Bro called me poor in 100 different languages.
3
0
16
@starkcharry
Vivek Kashyap
1 year
I earned $130 for my submission on @bugcrowd #ItTakesACrowd Nothing special just bypassed old reports.
1
1
15
@starkcharry
Vivek Kashyap
3 years
4. Boom account created and able to see private documents 2/2
0
2
13
@starkcharry
Vivek Kashyap
2 years
P4 in 5 minutes. This was also found using my phone Recon is best when you are bored. Already shared shared tip in last posts. #bugbounty #bugbountytips
Tweet media one
3
0
14
@starkcharry
Vivek Kashyap
2 years
If a Sub-domain allows only target email to register/login but not Normal email, I have a situation where Demo_acc1 @gmail .com not allowed to register but Demo_acc1 @target .com is accepted and can register Is this a Vulnerability? #BugBounty
4
0
14
@starkcharry
Vivek Kashyap
2 years
Thank you @Kanhaiya_sh4rma I my subscription Will be expired on 13th March but now extended one more month 🙏🙏❤✌✌
Tweet media one
1
0
13
@starkcharry
Vivek Kashyap
2 years
In July, I submitted 2 vulnerabilities to 2 programs on @Hacker0x01 . #TogetherWeHitHarder
0
0
12
@starkcharry
Vivek Kashyap
3 years
Useful GitHub Repos for Bug Bounty (attacks,PoC,Tip's,Book's) 1. Book of Secret Knowledge 2. Awesome Hacking 3. Awesome Bug Bounty 1/2 #bugbountytips #bugbounty #infosec
1
5
13
@starkcharry
Vivek Kashyap
3 years
Tip if you're new must try on Indian websites ❤️❤️🎉
1
0
10
@starkcharry
Vivek Kashyap
1 year
@krishnsec Hello Master,
Tweet media one
1
1
12
@starkcharry
Vivek Kashyap
2 years
Found self,dom Xss on whole CIDR range of a program 💀 in cookie param mp_id=xss payload , need good possible Way's to make it stored or reflected. #bugbounty #xss
2
0
12
@starkcharry
Vivek Kashyap
2 years
How addictive is Bug Bounty so, today I was at barbershop waiting for my turn & apparently I found directory listing & .env file on a BC program with my phone which contains AWS,Keys. reported DL turns to P5 & SDE P4 cause it was expired. #bugbounty #bugbountytips
1
2
10
@starkcharry
Vivek Kashyap
3 years
I just completed @Pentesterlab 's Unix Badge!!!
0
1
8
@starkcharry
Vivek Kashyap
2 years
Just updates guys took 8 days. @Bugcrowd
Tweet media one
0
0
10
@starkcharry
Vivek Kashyap
1 year
Got 5 AWS credentials in a zip file, none of them are working 😭.
2
0
10
@starkcharry
Vivek Kashyap
3 years
@AllostaticSec @security_donut Yo man I surely tell them 👽 let me finish thier internet data , 256gb downloding data pending 🤭
4
0
10
@starkcharry
Vivek Kashyap
3 years
Hi,recently I submitted a lot of info disclosure of apikeys accesstoken to a program in bugcrowd but they didnt accepted it they ask impact. What to do now I don't know how to exploit them further!Help! @AkashHamal0x01 @cyph3r_asr @AnubhavSingh_ #bugbounty #bugbountytip #infosec
4
1
10
@starkcharry
Vivek Kashyap
2 years
@x_hosein_x @n__Neo Crt(.)sh, security trials & shodan Get ip and subdomains catch one interesting subdomain I can't able to extract urls from it so I use a powerful tool called acunetix it gives me hint that it can be vuln to xss I passed that endpoint to intuder with custom script than got a Xss
2
0
9
@starkcharry
Vivek Kashyap
2 years
It's happening with me since last week, Doing Recon, BurpSuite stuff ends up with Instagram Reel's 🥲😂
1
0
9
@starkcharry
Vivek Kashyap
2 years
I'll be back soon. Exam in few days. Pausing Bug Bounty.
3
0
9
@starkcharry
Vivek Kashyap
3 years
hii so i founded a github recon with login pass, and it allows me to see all internal employees files etc and i saw few of them its exposing everything but they don't have bugbounty program what should i do😖. #bugbounty #bugbountytip #infosec 1/2
5
1
9
@starkcharry
Vivek Kashyap
2 years
Let's see who will win share yours screenshot comment below 👇👇👇 #bugbounty #bugbountytips #bugbountytip #infosec
Tweet media one
2
0
9
@starkcharry
Vivek Kashyap
3 years
can you guys explain me when you are doing directory fuzzing generally after how many -recursion depth there is a chances to get something secrete/important @fardeenahmed411 @Farah_Hawaa @hunter0x7 @KathanP19 @harshbothra_ @HackerGautam @AnubhavSingh_ #bugbounty #bugbountytips
2
3
9
@starkcharry
Vivek Kashyap
3 years
Bro 🙏🏽🙏🏽🙏🏽🙏🏽 please release or DM, your 1-2 POC video's of idor and logic flow I know you are best in it ❤️❤️❤️🥺😭😭 thanks in advance @AkashHamal0x01 #bugbounty
4
1
9
@starkcharry
Vivek Kashyap
1 year
@bugoverfl0w @krishnsec Gdork's new paths. /hello/ ❌ /hello/access_please/ ✅
2
0
8
@starkcharry
Vivek Kashyap
3 years
but no responsible disclosure 🙃🙃 #bugbountytips #bugbounty #bugbountytip
Tweet media one
2
2
7
@starkcharry
Vivek Kashyap
3 years
🙃🙃 again no program #bugbounty #bugbountytip
Tweet media one
1
2
7
@starkcharry
Vivek Kashyap
2 years
Update
Tweet media one
2
0
8
@starkcharry
Vivek Kashyap
2 years
@harshbothra_ Here is one liner that i use most for my xss recon (secret). For tools I'll say I don't use a specific tool but my Recon starts from security trials, crtsh, my favorite for interesting subdomains definitely try ports scan and then higher possibility of P3 to P1 bugs
Tweet media one
2
0
9
@starkcharry
Vivek Kashyap
3 years
anyone can suggest me how to exploit it further in google it says cve 2017-12617 RCE #bugbountytips #bugbountytip #bugbounty
Tweet media one
1
1
6
@starkcharry
Vivek Kashyap
3 years
Tweet media one
Tweet media two
0
3
7
@starkcharry
Vivek Kashyap
2 years
@arth_bajpai @Bugcrowd big bro we need writeups,videos anything 🫤
2
0
7
@starkcharry
Vivek Kashyap
9 months
@krishnsec P1 poc record krte wakt website ne aukaat dikha di
1
0
7
@starkcharry
Vivek Kashyap
3 years
INFORMATION DISCLOSURE TIPS $$$$ #bugbounty #bugbountytips #infosec
Tweet media one
0
2
7
@starkcharry
Vivek Kashyap
9 months
@krishnsec 1.Customer ne triager ko private message krke apni aukaat dikha di 😂 2.Customer ne OOS domains bina announcement kiye dusre hunter ko bounty de kr aukaat dikha di 3.Triager ne same parameter bug different domains ko self duplicate krke apni aukaat dikha di
1
0
7
@starkcharry
Vivek Kashyap
1 year
Tweet media one
2
0
6
@starkcharry
Vivek Kashyap
3 years
what should i do next ? 🤔🤔 #bugbounty #bugbountytip
Tweet media one
2
0
7
@starkcharry
Vivek Kashyap
2 years
😍 Triaged!!!!
Tweet media one
0
0
7
@starkcharry
Vivek Kashyap
3 years
@IamRenganathan @AnubhavSingh_ Useful I found 2but not in scope 😣
1
0
7