Zin Min Phyo Profile Banner
Zin Min Phyo Profile
Zin Min Phyo

@zin_min_phyo

Followers
1,469
Following
1,439
Media
86
Statuses
702

I'm Independent Web Security Researcher From Myanmar H1: BC:

MM
Joined February 2019
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
@zin_min_phyo
Zin Min Phyo
3 years
I earned a $750 bounty Tips: I never miss dir fuzzing ffuf -recursion -mc all -ac -c -e .htm,.shtml,.php,.html,.js,.txt,.zip,.bak,.asp,.aspx,.xml,.sql,.old,.at,.inc -w path -u -t 5000 #bugbounty #bugbountytips
Tweet media one
Tweet media two
12
102
363
@zin_min_phyo
Zin Min Phyo
3 years
$2250 USD bounty for reporting a security issue Bugs: Information Disclosure and Cloudflare Bypass Reflected XSS Bypass payloads: <svg onload=prompt%26%230000000040document.domain)> <svg onload=prompt%26%23x000000028;document.domain)> #BugBounty #bugbountytips
Tweet media one
Tweet media two
12
103
313
@zin_min_phyo
Zin Min Phyo
9 months
Just 30 minutes. #BugBounty
Tweet media one
12
9
200
@zin_min_phyo
Zin Min Phyo
4 years
I got €750, just 2 day hunting!! Tips : target use the pimcore cms? try this '/js/routing' , '/js/routing?callback=fos.Router.setData' got admin informations and path,etc,, Bounty €300 #bugbountytips #bugbounty
Tweet media one
5
54
201
@zin_min_phyo
Zin Min Phyo
9 months
After long break, I quit my job and went back to bug hunting It only took 1 hour to find the bug. #bugbounty
Tweet media one
15
6
198
@zin_min_phyo
Zin Min Phyo
3 years
I earn a €300 bounty on the Yogosha platform AEM_Tips: I analyzed the javascript code, I found this parameter, but I can't bypass of Content-Type here is the template: Ref: Special thanks to @AEMSecurity #BugBountyTips
Tweet media one
Tweet media two
4
49
133
@zin_min_phyo
Zin Min Phyo
2 years
Tweet media one
9
0
132
@zin_min_phyo
Zin Min Phyo
2 years
CVE-2022-1388 PoC 😝
Tweet media one
Tweet media two
6
15
109
@zin_min_phyo
Zin Min Phyo
3 years
Tip: 403 ERROR Bypass 😂😂 #bugbountytip
Tweet media one
3
15
95
@zin_min_phyo
Zin Min Phyo
4 years
If you found aspx site? find debug page like this you will seen Directories,Memory usage,Server Environment,etc,, Bounty €150 #bugbountytips #bugbounty
Tweet media one
1
34
75
@zin_min_phyo
Zin Min Phyo
7 months
#CVE -2024-23897
Tweet media one
0
8
66
@zin_min_phyo
Zin Min Phyo
3 years
I got €450 Bounty, Just 15minute!!! #bugbounty
Tweet media one
8
2
62
@zin_min_phyo
Zin Min Phyo
3 years
I earned a 500 USD + 100 Euro Bounty Tips: check the WordPress version from install.php #Bugbountytip #Bugbounty
Tweet media one
Tweet media two
Tweet media three
3
13
56
@zin_min_phyo
Zin Min Phyo
3 years
Yayyyy, I receive 1500 Euro bounty from @zerocopter Platform By the way, did you see my internet 🤣 #bugbounty #Log4RCE
Tweet media one
4
3
54
@zin_min_phyo
Zin Min Phyo
1 year
#bugBounty 🔥🔥💥💥
Tweet media one
3
0
48
@zin_min_phyo
Zin Min Phyo
3 years
more templates I'll upload soon!!! #CVE -2017-7692 #bugbountytips #bugbounty
Tweet media one
Tweet media two
Tweet media three
2
14
42
@zin_min_phyo
Zin Min Phyo
3 years
I got $1000 USD for vulnerability reporting. #bugbounty #bugbountytips
Tweet media one
1
1
40
@zin_min_phyo
Zin Min Phyo
3 years
Euro 200 reward, just 5 minute 😀 #bugbounty
Tweet media one
4
1
38
@zin_min_phyo
Zin Min Phyo
2 years
Tweet media one
3
0
35
@zin_min_phyo
Zin Min Phyo
3 years
Swag from sony #BugBounty
Tweet media one
2
1
32
@zin_min_phyo
Zin Min Phyo
2 years
Hit 500 repo on H1 #bugbounty
Tweet media one
1
0
32
@zin_min_phyo
Zin Min Phyo
3 years
waiting for duplicate :v :v
Tweet media one
7
2
26
@zin_min_phyo
Zin Min Phyo
2 years
apple HoF
Tweet media one
3
1
29
@zin_min_phyo
Zin Min Phyo
3 years
I got €300 bounty Bug : Accounts Takeover Tips : Alway check the source codes :) #bugbountytips #bugbounty
Tweet media one
3
0
24
@zin_min_phyo
Zin Min Phyo
3 years
Duplicate --> 100EUR Reward Bug --> Reflected XSS #BugBounty
Tweet media one
2
1
21
@zin_min_phyo
Zin Min Phyo
4 years
use the TYPO3? use dirsearch got phpinfo file .aa .html got typo3 debug page Bounty €300 #bugbountytips #bugbounty
1
6
16
@zin_min_phyo
Zin Min Phyo
3 years
€ 500 rewards from @zerocopter #bugbounty
Tweet media one
0
1
16
@zin_min_phyo
Zin Min Phyo
3 years
cat list.txt | waybackurls | grep jcr #bugbountytip
3
5
16
@zin_min_phyo
Zin Min Phyo
4 years
I got Euro 600 + 100 USD Bounty Thank you @YogoshaOfficial Thank you Zapier Security Team Bug type: 403 Bypass Rate Limint Informations Disclosure,etc #BugBounty
Tweet media one
Tweet media two
1
2
15
@zin_min_phyo
Zin Min Phyo
4 years
@GodfatherOrwa Nice bro, you can try this, "aaaa><svg/onerror="alert(1)";//
0
4
13
@zin_min_phyo
Zin Min Phyo
2 years
Tweet media one
2
0
13
@zin_min_phyo
Zin Min Phyo
4 years
Target using s3,zendesk ? Try file upload, poc.jpg, poc.htm.jpg bypass with burp Got store XSS,xml DoS,SSRF bounty $200 #bugbountytips #bugbounty
0
3
10
@zin_min_phyo
Zin Min Phyo
3 years
Small awards Bugs: CVE-2021-38314 Apache 2.4.48 Mod_Proxy SSRF(CVE-2021-40438) Information Disclosure #BugBounty
Tweet media one
Tweet media two
Tweet media three
0
3
12
@zin_min_phyo
Zin Min Phyo
3 years
Yay, I was awarded a $100 bounty on @Hacker0x01 ! #TogetherWeHitHarder Duplicate --> rewards
Tweet media one
1
1
11
@zin_min_phyo
Zin Min Phyo
9 months
@IndiancinemaNL Just open your browser, check the source and js file, use dirsearch.
3
0
11
@zin_min_phyo
Zin Min Phyo
9 months
@ynsmroztas Detect the OOB first test%0A%24%28nslookup%24IFS%249PoC.*******.oastify.com%29%0Atest Some time firewall will block /etc/passwd
0
1
10
@zin_min_phyo
Zin Min Phyo
3 years
In July, I submitted 19 vulnerabilities to 8 programs on @Hacker0x01 . #TogetherWeHitHarder
0
0
10
@zin_min_phyo
Zin Min Phyo
3 years
PoC XSS
Tweet media one
Tweet media two
1
1
10
@zin_min_phyo
Zin Min Phyo
4 years
Hey! I am looking for a hunter for our team. Send me a collaboration request on 🤝 #BugBounty #LetsHackTogether
0
1
7
@zin_min_phyo
Zin Min Phyo
3 years
@IamRenganathan I think this way is normal, We have been trying for years
1
0
7
@zin_min_phyo
Zin Min Phyo
3 years
In December, I submitted 6 vulnerabilities to 5 programs on @Hacker0x01 . #TogetherWeHitHarder
0
0
7
@zin_min_phyo
Zin Min Phyo
4 years
Bounty From @zerocopter <3
Tweet media one
1
1
7
@zin_min_phyo
Zin Min Phyo
3 years
Small Bounty #BugBounty
Tweet media one
1
1
6
@zin_min_phyo
Zin Min Phyo
3 years
€450 rewards in this month :( :( #bugbounty
Tweet media one
0
1
6
@zin_min_phyo
Zin Min Phyo
1 year
finally 💥🔥
@DhiyaneshDK
Dhiyaneshwaran
1 year
🚨Nuxt.Js Vulnerabilities 🔥 @pdnuclei 1. Arbitrary File Read in Dev Mode - Nuxt.js [high] 2. Semi Arbitrary File Read in Dev Mode - Nuxt.js [medium] 3. Error Page XSS - Nuxt.js [medium] Nuclei Template - #bugbounty #hackwithautomation #pdteam
Tweet media one
3
63
209
1
1
6
@zin_min_phyo
Zin Min Phyo
3 years
@hackeriron1 similar report:
0
1
6
@zin_min_phyo
Zin Min Phyo
2 years
Tweet media one
1
0
5
@zin_min_phyo
Zin Min Phyo
3 years
After i fuzzing, i found the database backup files, i got many sensitive information But they rate low risk. $500USD
0
0
5
@zin_min_phyo
Zin Min Phyo
9 months
@bug_vs_me yes brother
1
0
5
@zin_min_phyo
Zin Min Phyo
2 years
@YogoshaOfficial surprised me every time. Tips: don't forget to check manually Bug: web cache poisoning #bugbounty #bugbountytips
Tweet media one
1
1
4
@zin_min_phyo
Zin Min Phyo
8 months
@intigriti @Renzi25031469 /logs/log /info.php 😀
0
0
5
@zin_min_phyo
Zin Min Phyo
3 years
အိမ်မက်တွေ ရပ်တန့်ကုန်ပီ မအေလိုး မင်းအောင်လိူင်
@avanish46
Avanish Pathak
4 years
Its monsoon in India, but it rained Account Takeovers for me.😀! I Would be publishing a write up on this soon. Thanks @Bugcrowd @codingo_ #bugbounty #TakeHacktion
Tweet media one
67
60
905
0
0
4
@zin_min_phyo
Zin Min Phyo
4 years
I was awarded a €750 + 200 USD bounty New year + good bounty
Tweet media one
Tweet media two
Tweet media three
0
0
3
@zin_min_phyo
Zin Min Phyo
3 years
In August, I submitted 16 vulnerabilities to 11 programs on @Hacker0x01 . #TogetherWeHitHarder
0
0
4
@zin_min_phyo
Zin Min Phyo
3 years
I earned $150 for my submission on @bugcrowd #ItTakesACrowd
Tweet media one
1
0
4
@zin_min_phyo
Zin Min Phyo
3 years
Traveling
Tweet media one
0
0
4
@zin_min_phyo
Zin Min Phyo
8 months
@Alra3ees 80% is scam or dead.
0
0
2
@zin_min_phyo
Zin Min Phyo
3 years
In October, I submitted 15 vulnerabilities to 8 programs on @Hacker0x01 . #TogetherWeHitHarder
0
0
4
@zin_min_phyo
Zin Min Phyo
4 years
Yay, I was awarded a $100 bounty on @Hacker0x01 ! #TogetherWeHitHarder
Tweet media one
0
0
2
@zin_min_phyo
Zin Min Phyo
3 years
@andridev_ Change GET to POST,PUT,OPTIONS... laravel debug 🌚
0
1
3
@zin_min_phyo
Zin Min Phyo
3 years
€150.00 EUR from @zerocopter #bugbounty
Tweet media one
3
0
3
@zin_min_phyo
Zin Min Phyo
2 years
@h4x0r_dz Because u r gay 😜😜😜😜
1
0
3
@zin_min_phyo
Zin Min Phyo
3 years
0
1
3
@zin_min_phyo
Zin Min Phyo
9 months
@ye_yint_htet Thanks nyi
1
0
3
@zin_min_phyo
Zin Min Phyo
2 years
bXSS god💥🔥
1
0
3
@zin_min_phyo
Zin Min Phyo
3 years
50 USD + € 50 Bounty Zapier,Zerocopter #bugbounty
Tweet media one
Tweet media two
0
0
3
@zin_min_phyo
Zin Min Phyo
3 years
😂😂😂
@micro0x00
Mohamed Mater🇵🇸
3 years
When I was Hunting in private #BugBounty program Fuc**** developer showed me that. #bugbountytips
Tweet media one
10
7
43
0
1
2
@zin_min_phyo
Zin Min Phyo
3 years
€ 50 reward from Zerocopter Platform
Tweet media one
0
0
3
@zin_min_phyo
Zin Min Phyo
3 years
collaborate with @MinWon219 #BugBounty
Tweet media one
1
1
3
@zin_min_phyo
Zin Min Phyo
2 years
The @YogoshaOfficial team still ignores my email, I didn't receive my bounties, Is it enough for waiting? Please give a specific answer.
@zin_min_phyo
Zin Min Phyo
2 years
I transfer my bounty to the bank account on @YogoshaOfficial , but I didn't receive money, I contact to support team, but they do not respond to me. today I got a small reward from yogosha CVD, possible to I lost too this money? @YogoshaOfficial @YogoshaM #bugbounty #yogosha
Tweet media one
Tweet media two
1
0
2
2
0
3
@zin_min_phyo
Zin Min Phyo
1 year
@alicanact60 @PlayStation @Hacker0x01 I reported a similar issue on H1, but h1_trigger didn't accept my report.
1
0
2
@zin_min_phyo
Zin Min Phyo
2 years
@420Unkn0wN420 I use shodan
1
0
1
@zin_min_phyo
Zin Min Phyo
3 years
Total reports:13 now two report accept, duplicate:5 other are wating....
Tweet media one
Tweet media two
0
0
2
@zin_min_phyo
Zin Min Phyo
3 years
@alamjahidul000 similar report:
0
0
2
@zin_min_phyo
Zin Min Phyo
4 years
@_Bugbountytips_ subfindr -d -silent | httpx -silent | anew | waybackurls | gf sqli >> sqli ; sqlmap -m sqli -batch –random-agent --level=5 --risk=3 -threads 5
2
2
2
@zin_min_phyo
Zin Min Phyo
3 years
@0xElkomy @AEMSecurity sometimes I can trigger to XSS, or report with text injections
0
0
2
@zin_min_phyo
Zin Min Phyo
3 years
We hit again, Collaborate with my brother @MinWon219 #BugBounty
Tweet media one
1
1
2
@zin_min_phyo
Zin Min Phyo
3 years
bad luck, any tips of django panel?
Tweet media one
1
0
2
@zin_min_phyo
Zin Min Phyo
4 years
0
0
2
@zin_min_phyo
Zin Min Phyo
3 years
Tweet media one
2
0
2
@zin_min_phyo
Zin Min Phyo
2 years
I transfer my bounty to the bank account on @YogoshaOfficial , but I didn't receive money, I contact to support team, but they do not respond to me. today I got a small reward from yogosha CVD, possible to I lost too this money? @YogoshaOfficial @YogoshaM #bugbounty #yogosha
Tweet media one
Tweet media two
1
0
2
@zin_min_phyo
Zin Min Phyo
3 years
@pdnuclei @DhiyaneshDK my favorite tool 🥰🥰
0
0
1
@zin_min_phyo
Zin Min Phyo
3 years
@nayeems3c similar report:
1
1
2
@zin_min_phyo
Zin Min Phyo
3 years
I got 174.69 USD From Private Program #bugbounty
Tweet media one
1
0
1
@zin_min_phyo
Zin Min Phyo
9 months
0
0
2
@zin_min_phyo
Zin Min Phyo
3 years
Tip: Never lazy to try for manual
0
0
2
@zin_min_phyo
Zin Min Phyo
3 years
Thanks Yogosha
Tweet media one
1
0
2
@zin_min_phyo
Zin Min Phyo
6 months
@nav1n0x @rene_kroka Found RCE on web3 program(bounty $500) 🥹
2
0
3
@zin_min_phyo
Zin Min Phyo
2 years
@h4x0r_dz £1500 = RCE
0
0
2
@zin_min_phyo
Zin Min Phyo
2 years
@starkcharry Laravel Debug
0
0
2
@zin_min_phyo
Zin Min Phyo
3 years
1
1
2
@zin_min_phyo
Zin Min Phyo
2 years
@0x0SojalSec Access_log //debug_log Config_JCR.json.0x%A.html
0
0
2