Gaurav Bisht (@gauravbisht1709) 's Twitter Profile
Gaurav Bisht

@gauravbisht1709

Building jsmon.sh, Software Developer and DevOps Engineer.

ID: 1608531551809306627

linkhttps://github.com/Qu4ntumGuy calendar_today29-12-2022 18:33:27

24 Tweet

68 Followers

30 Following

Jsmon - jsmon.sh (@jsmonsh) 's Twitter Profile Photo

🚨 NPM Dependency Confusion & Org Namespace Takeovers in 2025. Still a threat. Still leading to RCE. In our latest blog, we show how missing packages & unclaimed orgs can expose internal infra β€” with real recon tips. πŸ”— Read here: blogs.jsmon.sh/npm-dependency… #infosec #bugbounty

Jsmon - jsmon.sh (@jsmonsh) 's Twitter Profile Photo

πŸš€ New Update! Jsmon now detects 20+ AWS services directly from JavaScript files, including: βœ… S3 buckets βœ… CloudFront URLs βœ… Cognito tokens & IDs … and many more! πŸ”Ž Scan your domains now at jsmon.sh

πŸš€ New Update! Jsmon now detects 20+ AWS services directly from JavaScript files, including:
βœ… S3 buckets
βœ… CloudFront URLs
βœ… Cognito tokens & IDs
… and many more!
πŸ”Ž Scan your domains now at jsmon.sh
Jsmon - jsmon.sh (@jsmonsh) 's Twitter Profile Photo

πŸŽ‰ Milestone Unlocked! πŸŽ‰ We just crossed 1,000,000 JavaScript files scanned with Jsmon! Huge thanks to our early users, researchers & product team who made this possible. πŸ’™ Check live status at: jsmon.sh

πŸŽ‰ Milestone Unlocked! πŸŽ‰

We just crossed 1,000,000 JavaScript files scanned with Jsmon! Huge thanks to our early users, researchers & product team who made this possible. πŸ’™

Check live status at: jsmon.sh
Jsmon - jsmon.sh (@jsmonsh) 's Twitter Profile Photo

Top 5 Ways to use Jsmon Ask AI Feature. 5 examples on zomato's HackerOne program belowπŸ‘‡. Click on Ask Jsmon at jsmon.sh/askJsmon, scan domains or JS URLs and enter your prompts.

Top 5 Ways to use Jsmon Ask AI Feature. 5 examples on <a href="/zomato/">zomato</a>'s <a href="/Hacker0x01/">HackerOne</a> program belowπŸ‘‡.

Click on Ask Jsmon at jsmon.sh/askJsmon, scan domains or JS URLs and enter your prompts.
Jsmon - jsmon.sh (@jsmonsh) 's Twitter Profile Photo

πŸŽ‰ GIVEAWAY TIME! πŸŽ‰ Want to try Jsmon Pro for free? We're giving away 3 one-month subscriptions (worth $195 total)! Here's how to enter: βœ… Follow Jsmon - jsmon.sh πŸ” Retweet this post πŸ“Έ Share a screenshot of your scan and tag us! That's it. Winners announced in 7 days.

Jsmon - jsmon.sh (@jsmonsh) 's Twitter Profile Photo

πŸ’‘ Bug bounty tip: Archived JS files can expose hidden URLs, forgotten APIs & admin panels. Use this recon trick to level up your game. πŸ‘‰ blogs.jsmon.sh/extract-urls-f… #BugBounty #Recon #JavaScript #InfoSec #HackingTips

Jsmon - jsmon.sh (@jsmonsh) 's Twitter Profile Photo

πŸš€ 5 BurpSuite Plugins I Use Almost Every Time πŸ”Ή Shadow Repeater – Repeater with AI πŸ”Ή Autorize – Spot authorization bugs fast πŸ”Ή IP Rotate – Evade rate limits effortlessly πŸ”Ή Turbo Intruder – Lightning-fast fuzzing πŸ”Ή Param Miner – Uncover hidden parameters

encodedguy - jsmon.sh (@3nc0d3dguy) 's Twitter Profile Photo

HDFC Bank I’ve had a support ticket open for quite some time now, but there’s been no update. This delay is unexpected from HDFC. Even the local branch staff aren't responding properly. Can someone please look into this urgently? Ref no: CITIN52025050962019313.

Jsmon - jsmon.sh (@jsmonsh) 's Twitter Profile Photo

πŸŽ‰ Giveaway Results! πŸŽ‰ It was our first-ever giveaway, and while participation was small, we’ve still got 2 awesome winners: πŸ₯‡ x cyber Space πŸ₯ˆ Arif grunge There’s still a chance! Just follow the giveaway guidelines. We’ll pick one more winner soon.

Jsmon - jsmon.sh (@jsmonsh) 's Twitter Profile Photo

πŸ₯€ BOOM! Jsmon strikes again. We found another S3 Bucket Takeover, this time in a JavaScript file from Coca-Cola’s RDP (via Intigriti)! ⚠️ Triaged as High Severity πŸ† Got reward coupons Our JS Intelligence doesn’t miss. #BugBounty #CyberSecurity #Intigriti #S3Takeover

πŸ₯€ BOOM! Jsmon strikes again.

We found another S3 Bucket Takeover, this time in a JavaScript file from Coca-Cola’s RDP (via <a href="/intigriti/">Intigriti</a>)!
⚠️ Triaged as High Severity
πŸ† Got reward coupons

Our JS Intelligence doesn’t miss.
#BugBounty #CyberSecurity #Intigriti #S3Takeover
Jsmon - jsmon.sh (@jsmonsh) 's Twitter Profile Photo

🚨 Big Update: We’ve simplified Jsmon’s pricing! No more separate charges for Domain, URL, or File Scans. Now it’s just JS Scans, you only pay for how many JavaScript files we scan, no matter where they come from. One model. One metric. Live in production starting today.

Jsmon - jsmon.sh (@jsmonsh) 's Twitter Profile Photo

πŸŽ‰ We just crossed 2,000 users on Jsmon! From day 1, we've been focused on helping developers uncover JavaScript-based security risks in frontends, and today, 2,000 of you trust us to do just that. Thank you for the support, feedback & belief in the mission.

Jsmon - jsmon.sh (@jsmonsh) 's Twitter Profile Photo

πŸš€ JS Explorer is live now! Discover JS URLs from domains for free. Powered with 500M JS URLs and updating every week. Visit jsmon.sh/jsexplorer/ now. βœ… Retweet, bookmark and share link with your friends in bugbounty, cybersecurity and OSINT research.

Jsmon - jsmon.sh (@jsmonsh) 's Twitter Profile Photo

New search query implemented today, over domain + subdomains of the domain for searching over JS URLs. This've increased the searches JS URLs count by a lot.

Jsmon - jsmon.sh (@jsmonsh) 's Twitter Profile Photo

11/11That's a wrap! These Google Dorks are a powerhouse for: βœ… OSINT (Open-Source Intelligence) βœ… Ethical Penetration Testing βœ… Digital Research πŸ”’ Remember: With great power comes great responsibility. Always use ethically. Retweet if you found this useful! πŸ”

Jsmon - jsmon.sh (@jsmonsh) 's Twitter Profile Photo

Hello hackers! Our GitHub org (was rashahacks) is now jsmonhq - github.com/jsmonhq. πŸ”Ή Jsmon CLI β†’ github.com/jsmonhq/jsmon-… πŸ”Ή Jsmon Burp Suite Extension β†’ github.com/jsmonhq/jsmon-… Follow jsmonhq on Github for all our open-source updates! πŸ’»βœ¨

Jsmon - jsmon.sh (@jsmonsh) 's Twitter Profile Photo

πŸš€ DepiConf: New Tool Launch. Identify NPM packages vulnerable to dependency confusion. Link below πŸ‘‡. app.jsmon.sh/tools/npm-vali…