Neel Ponkia (@neelponkia) 's Twitter Profile
Neel Ponkia

@neelponkia

Breaking apps & cashing checks 🐛

ID: 1649992759

calendar_today06-08-2013 09:57:39

130 Tweet

389 Followers

587 Following

Jenish Sojitra (@_jensec) 's Twitter Profile Photo

Yay, I was awarded a $1,200 bounty on HackerOne for tricky privilege escalation ! “ If API endpoint /api/path/ep throwing 401 try to go with /api/path/ep.json “ and it will fetch out json data without checking access control ! #bugbountytip

Orange Tsai  🍊 (@orange_8361) 's Twitter Profile Photo

The last part of our Attacking SSL VPN series is out - The Golden Pulse Secure SSL VPN RCE Chain, with Twitter as Case Study! blog.orange.tw/2019/09/attack… "If you have a nuclear level weapon, when is it ready for public disclosure?"

Jobert Abma (@jobertabma) 's Twitter Profile Photo

Hackers, today we’re announcing our Series D funding! This round brings us to over $110,000,000 USD invested since the company was founded. I wanted to take a moment to reflect on how you, the hacker community, have enabled us on our journey. Small story👇!

Jenish Sojitra (@_jensec) 's Twitter Profile Photo

Yay, I was awarded a $2,000 bounty on HackerOne! For accessing company dashboard via creating account with Email “[email protected]” on main web app and login to dashboard with SSO. #bugbountytip

Hussein Daher (@hussein98d) 's Twitter Profile Photo

To everyone struggling on starting #bugbounty.. Remember that a child too has to learn walking, and then he can start running. You won't get 10 bounties the first month, but it's worth joining.

Intigriti (@intigriti) 's Twitter Profile Photo

Can't get CSRF with POST? Then GET it! Use 'change request method' in Burp Suite to check if the server also accepts GET requests. Thanks for the #BugBountyTip, ! #HackWithIntigriti

Can't get CSRF with POST? Then GET it! 
Use 'change request method' in Burp Suite to check if the server also accepts GET requests. Thanks for the #BugBountyTip, <a href="/spaceraccoon/"></a>! #HackWithIntigriti
Jenish Sojitra (@_jensec) 's Twitter Profile Photo

Yay, I was awarded a $10,000 bounty on HackerOne For "Hijacking Enitre DNS management Panel For target.com " With this I reached 200K across all my earnings on all the bb platforms and private client companies hackerone.com/jensec #TogetherWeHitHarder

Intigriti (@intigriti) 's Twitter Profile Photo

One bug does not mean one bounty! Maximise your 💰 using securitytrails.com, thanks to this excellent tip from Geekboy! 🇮🇳 #HackWithIntigriti

One bug does not mean one bounty! Maximise your 💰 using securitytrails.com, thanks to this excellent tip from <a href="/emgeekboy/">Geekboy</a>! 🇮🇳 #HackWithIntigriti
Alibaba Security Response Center (@asrcsecurity) 's Twitter Profile Photo

⭐️The second week of Double 11 festival bug bounty ⭐️Pure gold medal for Top 3 hackers. ⭐️Air tickets and hotel for top1 hacker to China agamimaulana saltedfish Neel Ponkia Batee5a Aagam Shah Yeasir Arafat(nullsaint) @real_us3r d Zeeshan Khalid ⭐️security.alibaba.com/online/detail?…

⭐️The second week of Double 11 festival bug bounty
⭐️Pure gold medal for Top 3 hackers. 
⭐️Air tickets and hotel for top1 hacker to China
<a href="/agamimaulana/">agamimaulana</a> <a href="/sa1tedf1sh/">saltedfish</a> <a href="/NeelPonkia/">Neel Ponkia</a> <a href="/Ahmed_ASherif/">Batee5a</a>  <a href="/neutrinoguy/">Aagam Shah</a> <a href="/SSkylinearafat/">Yeasir Arafat(nullsaint)</a> @real_us3r <a href="/0x61_/">d</a> <a href="/z33_5h4n/">Zeeshan Khalid</a> 
⭐️security.alibaba.com/online/detail?…
Hussein Daher (@hussein98d) 's Twitter Profile Photo

Sharing one of my secrets #BugBountyTip When discovering subdomains/domains/assets owned by a company, use the Google Analytics ID to expand your attack surface. The ID is in the HTML code. Reverse search then: site-overview.com/website-report… RT once this helps!#bugbountytips #infosec

TechFenix (@techfenixsec) 's Twitter Profile Photo

"why Asian companies lack of bug bounty programs?" The Quint talked with our team member Shubham Patel. This article also includes Issues With #AROGYASETU Bug bounty Program. thequint.com/tech-and-auto/… #BugBounty #TechNews #Techfenix

Jenish Sojitra (@_jensec) 's Twitter Profile Photo

#bugbountytips #bugbounty How I was able to find multiple critical vulnerabilities to get Full Account Takeover with the help of PlayStore and AppStore region settings.

#bugbountytips #bugbounty
How I was able to find multiple critical vulnerabilities to get Full Account Takeover with the help of PlayStore and AppStore region settings.