sumgr0 (@sumgr0) 's Twitter Profile
sumgr0

@sumgr0

Pentester | Bug Bounty Hunter | #hackerone | #intigriti | #bugcrowd @[email protected]

ID: 41040613

linkhttps://cybergeeks.in calendar_today19-05-2009 03:02:45

24,24K Tweet

5,5K Followers

4,4K Following

Jsmon - jsmon.sh (@jsmonsh) 's Twitter Profile Photo

Jsmon.sh scans 5 times faster now ๐Ÿš€ . We found that for many customers data is loading very slowly. We've improved server specs and microservices connections.

Jsmon - jsmon.sh (@jsmonsh) 's Twitter Profile Photo

๐ŸŽ‰ Milestone Unlocked! ๐ŸŽ‰ We just crossed 1,000,000 JavaScript files scanned with Jsmon! Huge thanks to our early users, researchers & product team who made this possible. ๐Ÿ’™ Check live status at: jsmon.sh

๐ŸŽ‰ Milestone Unlocked! ๐ŸŽ‰

We just crossed 1,000,000 JavaScript files scanned with Jsmon! Huge thanks to our early users, researchers & product team who made this possible. ๐Ÿ’™

Check live status at: jsmon.sh
Jsmon - jsmon.sh (@jsmonsh) 's Twitter Profile Photo

๐ŸŽ‰ GIVEAWAY TIME! ๐ŸŽ‰ Want to try Jsmon Pro for free? We're giving away 3 one-month subscriptions (worth $195 total)! Here's how to enter: โœ… Follow Jsmon - jsmon.sh ๐Ÿ” Retweet this post ๐Ÿ“ธ Share a screenshot of your scan and tag us! That's it. Winners announced in 7 days.

Shakti Ranjan Mohanty || ๐Ÿ‡ฎ๐Ÿ‡ณ || (@3ncryptsaan) 's Twitter Profile Photo

HackerOne is hiring multiple Product Security Analysts in Pune! ๐Ÿ“ In-office (4โ€“5 days/week) | Shift-based role ๐Ÿ—“๏ธ Hiring Timeline: โ€ขRecruiter calls: Week of 7th July โ€ขTech rounds: 14โ€“25 July โ€ขChallenge: 28 Julyโ€“1 Aug If you're aiming to be one of them, feel free to DM me!

Jsmon - jsmon.sh (@jsmonsh) 's Twitter Profile Photo

๐Ÿšจ New Bug Bounty Write-up ๐Ÿšจ Our team at Jsmon - jsmon.sh discovered an S3 Bucket Takeover through a JavaScript file โ€” full control over a cloud asset just from a JS URL! ๐Ÿ‘‰ How we found it ๐Ÿ‘‰ How we took it over ๐Ÿ‘‰ How you can hunt these too Read here: blogs.jsmon.sh/s3-bucket-takeโ€ฆ

๐Ÿšจ New Bug Bounty Write-up ๐Ÿšจ

Our team at <a href="/jsmonsh/">Jsmon - jsmon.sh</a> discovered an S3 Bucket Takeover through a JavaScript file โ€” full control over a cloud asset just from a JS URL!

๐Ÿ‘‰ How we found it
๐Ÿ‘‰ How we took it over
๐Ÿ‘‰ How you can hunt these too

Read here: blogs.jsmon.sh/s3-bucket-takeโ€ฆ
Jsmon - jsmon.sh (@jsmonsh) 's Twitter Profile Photo

Big news! Jsmon now supports Workspace Sharing! You can now collaborate across teams or clients by sharing your workspaces with other users. Perfect for agencies, bug bounty teams, and security researchers managing multiple projects.

sumgr0 (@sumgr0) 's Twitter Profile Photo

Hey Grok, based on your analysis of the last 365 days, list in sequence 10 accounts that frequently visit my profile. Do not mention the person, only @.username and the rate of visits to the profile per month.

Jsmon - jsmon.sh (@jsmonsh) 's Twitter Profile Photo

๐Ÿš€ JS Explorer is live now! Discover JS URLs from domains for free. Powered with 500M JS URLs and updating every week. Visit jsmon.sh/jsexplorer/ now. โœ… Retweet, bookmark and share link with your friends in bugbounty, cybersecurity and OSINT research.

encodedguy - jsmon.sh (@3nc0d3dguy) 's Twitter Profile Photo

Searching Google.com returned around 78.8K JS URLs in less than a second. Previously google.com was giving nothing in response. JS Explorer will become a game changing tool for BB hunters and security researchers now! ๐Ÿš€

Searching Google.com returned around 78.8K JS URLs in less than a second. Previously google.com was giving nothing in response.

JS Explorer will become a game changing tool for BB hunters and security researchers now! ๐Ÿš€
sumgr0 (@sumgr0) 's Twitter Profile Photo

Hey Grok , who was the most famous person to visit my profile? It doesn't need to be a mutual, don't tag them, just say who it was.

sumgr0 (@sumgr0) 's Twitter Profile Photo

Hey Grok based on your analysis of the last 365 days, list in sequence 10 accounts that frequently visit my profile. Do not mention the person, only @.username and the rate of visits to the profile per month.

bsysop (@bsysop) 's Twitter Profile Photo

TOOL RELEASE๐Ÿ”ฅ๐Ÿš€ Clear reports and good communication with the teams can make the difference in the outcome of your report, including the final bounty/bonus. To assist you in the reporting and communication, here is CrowdAssist โœจ. bugcrowd compatible. ๐Ÿงต๐Ÿ‘‡ #BugBounty #AI

TOOL RELEASE๐Ÿ”ฅ๐Ÿš€

Clear reports and good communication with the teams can make the difference in the outcome of your report, including the final bounty/bonus.

To assist you in the reporting and communication, here is CrowdAssist โœจ.

<a href="/Bugcrowd/">bugcrowd</a> compatible.

๐Ÿงต๐Ÿ‘‡

#BugBounty #AI
Intigriti (@intigriti) 's Twitter Profile Photo

๐Ÿ’ก Quick tip! Need to identify the origin server behind a WAF or CDN? Historical datasets are your friend! ๐Ÿค  Historical datasets of SSL/TLS certificates & DNS records can sometimes contain the IP of the origin server before it was in-front of a CDN. Example with

๐Ÿ’ก Quick tip!

Need to identify the origin server behind a WAF or CDN? Historical datasets are your friend! ๐Ÿค 

Historical datasets of SSL/TLS certificates &amp; DNS records can sometimes contain the IP of the origin server before it was in-front of a CDN.

Example with