Gotcha1G (@gotcha1g) 's Twitter Profile
Gotcha1G

@gotcha1g

Bug Hunter Top 200 Bugcrowd # Top5 Dell_Technologies

ID: 1521937805123141632

calendar_today04-05-2022 19:40:34

265 Tweet

2,2K Followers

101 Following

Gotcha1G (@gotcha1g) 's Twitter Profile Photo

Just dropped my first write-up! Found a juicy auth bypass that gave me admin access through response tampering. Check it out and let me know what you think! medium.com/@arrasgotcha/a… medium.com/@arrasgotcha/a…

Just dropped my first write-up!
Found a juicy auth bypass that gave me admin access through response tampering.

Check it out and let me know what you think!
medium.com/@arrasgotcha/a…
medium.com/@arrasgotcha/a…
Gotcha1G (@gotcha1g) 's Twitter Profile Photo

Would you like this for the next write-up? Pretty sure this one’s getting bumped to Critical I had full control over the app: Create, read, update, delete. Total takeover. Stay tuned 🤫 #bugbounty #infosec #Gotcha1G

Would you like this for the next write-up?
Pretty sure this one’s getting bumped to Critical
I had full control over the app:
Create, read, update, delete.
Total takeover.

Stay tuned 🤫

#bugbounty #infosec #Gotcha1G
Gotcha1G (@gotcha1g) 's Twitter Profile Photo

🔥 Just dropped a new bug bounty write-up: From a simple 403 to full PII exposure and a P2 High severity! 🚀 medium.com/@arrasgotcha/f… #BugBounty #InfoSec #CyberSecurity #Hacking

Gotcha1G (@gotcha1g) 's Twitter Profile Photo

New Critical 🔥 $15,000 earned! From simple information disclosure → to full control over the webapp. Happy to hunt on Intigriti Stay focused, stay sharp! #bugbounty #infosec #Gotcha1G

New Critical 🔥 $15,000 earned!
From simple information disclosure → to full control over the webapp.

Happy to hunt on <a href="/intigriti/">Intigriti</a>
Stay focused, stay sharp!

#bugbounty #infosec #Gotcha1G
Gotcha1G (@gotcha1g) 's Twitter Profile Photo

I just published Part 2 ! From Out-of-Scope to Critical: How I Earned 2500$ by Breaking the Rules 🔥🔥medium.com/p/from-out-of-…

I just published Part 2 ! From Out-of-Scope to Critical: How I Earned 2500$ by Breaking the Rules 🔥🔥medium.com/p/from-out-of-…
Gotcha1G (@gotcha1g) 's Twitter Profile Photo

+50k bounty this month? 🤔 2 more critical & 1high triaged and pending for reward 🥰 Bug type : api endpoint misconfiguration Severity : High

+50k bounty this month? 🤔
2 more critical &amp; 1high  triaged and pending for reward 🥰
Bug type : api endpoint misconfiguration 
Severity : High
Gotcha1G (@gotcha1g) 's Twitter Profile Photo

From Out of Scope to 4-digit Bounty + Swag 🤑! This one started as out-of-scope and was closed initially… but the internal team took a closer look, saw the real impact, reopened it, and made an exception. Massive respect to the Yahoo for their fairness and deep dive. Intigriti

From Out of Scope to 4-digit Bounty + Swag 🤑!
This one started as out-of-scope and was closed initially… but the internal team took a closer look, saw the real impact, reopened it, and made an exception.
Massive respect to the <a href="/Yahoo/">Yahoo</a> for their fairness and deep dive.
<a href="/intigriti/">Intigriti</a>
Gotcha1G (@gotcha1g) 's Twitter Profile Photo

Birthday timing couldn’t be more perfect 🎉 Just got this awesome swag from the Yahoo Paranoids crew ☠️ “It pays to be Paranoid” indeed 🖤🔐 #Infosec #Yahoo #Paranoids #Birthday

Birthday timing couldn’t be more perfect 🎉 Just got this awesome swag from the <a href="/Yahoo/">Yahoo</a> Paranoids crew ☠️ “It pays to be Paranoid” indeed 🖤🔐 #Infosec #Yahoo #Paranoids #Birthday
Gotcha1G (@gotcha1g) 's Twitter Profile Photo

First excuse: “not owned or controlled by Meta” After Reopen and proof they change excuses to “privacy low impact” 🤷‍♂️ Bug was full ATO + panel access + PII 😅 But they marked critical report duplicate of PII leak lol admin panel for fb orgs screenshot below > #bugbounty #meta

First excuse: “not owned or controlled by Meta”
After Reopen and proof
they change excuses to “privacy low impact” 🤷‍♂️

Bug was full ATO + panel access + PII 😅 But they marked critical report duplicate of PII leak lol
admin panel for fb orgs screenshot below &gt;
#bugbounty #meta
Gotcha1G (@gotcha1g) 's Twitter Profile Photo

ZoomEye just dropped BugBounty Radar 🪲 a real-time asset tracker built for bug hunters. Perfect for recon, asset monitoring & finding fresh targets. DM them for a 15-day free trial 🔥 zoomeye.ai/bugbounty #BugBounty #Recon

ZoomEye just dropped BugBounty Radar 🪲 a real-time asset tracker built for bug hunters.
Perfect for recon, asset monitoring &amp; finding fresh targets.
DM them for a 15-day free trial 🔥
zoomeye.ai/bugbounty
#BugBounty #Recon
Gotcha1G (@gotcha1g) 's Twitter Profile Photo

Intigriti rewarded me with this amazing design for hitting $50K in short time and maintaining a streak of criticals. Grateful for the grind, and even more excited for what’s next 😍 #Hack4rlife #Gotcha1G #BugBounty

Intigriti rewarded me with this amazing design for hitting $50K in short time and maintaining a streak of criticals. Grateful for the grind, and even more excited for what’s next 😍
#Hack4rlife #Gotcha1G #BugBounty