Harss25 (@harsh25nn) 's Twitter Profile
Harss25

@harsh25nn

@Intigriti Top 10 2025 Q2 | Bug Bounty Hunter | Security Researcher | Building @HICA_Community | Operational Head - BloggersCon Vision

ID: 1422224965546299393

calendar_today02-08-2021 15:57:27

13 Tweet

23 Followers

120 Following

Harss25 (@harsh25nn) 's Twitter Profile Photo

Hall Of Fame Received 🥳🥳 Tips - 1. Always try to visit on links which have “Server” in Name ( Look in Shodan.io ) 2. And then simply fuzz. You Will find something after Fuzz. Try to exploit or report it. Happy Hunting :)

Hall Of Fame Received 🥳🥳

Tips - 
1. Always try to visit on links which have “Server” in Name ( Look in Shodan.io )
2. And then simply fuzz.

You Will find something after Fuzz. Try to exploit or report it.

Happy Hunting :)
HICA (@hica_community) 's Twitter Profile Photo

Join the HackerOne HackerOne In-Person Hacking Meetup in Pune! Date: 26th & 27th April Don’t miss out on live hacking, networking & swag! Register now: h1.community/events/details… #HackerOne #BugBounty #Cybersecurity #PuneHackers #HICA #bytebloggerbase #meetup

Harss25 (@harsh25nn) 's Twitter Profile Photo

Many hunters miss out on chaining and minor findings — but that’s where the gold is. We’ve dropped a new lab[ 0N3_P1ECE By Raman_MG ] on our HICA.CTF platform to help you master this art. Ready to think deeper? Join in. hicactf.com HICA #BugBounty

Harss25 (@harsh25nn) 's Twitter Profile Photo

Made it to Intigriti Top 10 (2025 Q2) and Top 2 all-time on The Coca-Cola Co. VDP. Really happy about this — it’s been a fun ride so far. From the next post, I’ll start sharing some tips and things I’ve learned along the way. #BugBounty #Intigriti #Hacked #bugbountytips

Made it to <a href="/intigriti/">Intigriti</a>  Top 10 (2025 Q2) and Top 2 all-time on <a href="/CocaColaCo/">The Coca-Cola Co.</a>  VDP.

Really happy about this — it’s been a fun ride so far.
From the next post, I’ll start sharing some tips and things I’ve learned along the way.

#BugBounty #Intigriti #Hacked #bugbountytips
Harss25 (@harsh25nn) 's Twitter Profile Photo

Just Reported these bugs on a single asset a few days ago. - LFI - Stored/Blind XSS - Vertical Privilege Escalation (BAC) Tip - Always Look For JS Files they might reveal paths/API Calls (Unauthorized🙃). #BugBounty #bugbountytips

Just Reported these bugs on a single asset a few days ago.
- LFI
- Stored/Blind XSS
- Vertical Privilege Escalation (BAC)

Tip - Always Look For JS Files they might reveal paths/API Calls (Unauthorized🙃).

#BugBounty #bugbountytips
Harss25 (@harsh25nn) 's Twitter Profile Photo

Just Got Rewarded at Intigriti 🤑$$$$ Tip:- Fuzz the endpoints/path of one domain to other domains. mno[.]abc[.]com/logs -> 403 xyz[.]abc[.]com/logs -> 200 #intigriti #bugbounty #cybersecurity #bugreport #bounty #reward #hackerone #bugcrowd

Just Got Rewarded at <a href="/intigriti/">Intigriti</a> 
🤑$$$$

Tip:- Fuzz the endpoints/path of one domain to other domains.

mno[.]abc[.]com/logs -&gt; 403
xyz[.]abc[.]com/logs -&gt; 200

#intigriti #bugbounty #cybersecurity #bugreport #bounty #reward #hackerone #bugcrowd
Harss25 (@harsh25nn) 's Twitter Profile Photo

Imagine finding .htaccess, getting told it’s out of scope, and then calling it to ‘expose infra’💀 Real hunters: move on & learn. Fake ones: write blogs and call it ‘fraud’. ॐ KALKIकल्कि اَللّٰهُ Bro speedran the path from bounty hunter to bounty clown🤡 #bugbounty #cyber #intigriti

Imagine finding .htaccess, getting told it’s out of scope, and then calling it to ‘expose infra’💀

Real hunters: move on &amp; learn.
Fake ones: write blogs and call it ‘fraud’. <a href="/ElonVsKalki/">ॐ KALKIकल्कि اَللّٰهُ</a>

Bro speedran the path from bounty hunter to bounty clown🤡

#bugbounty #cyber #intigriti