Tushar Sharma (@tusharsharma_0) 's Twitter Profile
Tushar Sharma

@tusharsharma_0

If this weren't for `qwerty` I don't know who I will be
|Security Engineer | Bug Bounty Hunter |

ID: 1312993688075735040

calendar_today05-10-2020 05:51:15

430 Tweet

1,1K Followers

212 Following

Max Yaremchuk (@0xw2w) 's Twitter Profile Photo

This is the silliest and strangest 2FA bug I found (so far): The application generates the same TOTP key for every account. By obtaining a TOTP key for one account it's possible to obtain the current TOTP code for all other accounts.

This is the silliest and strangest 2FA bug I found (so far): The application generates the same TOTP key for every account. By obtaining a TOTP key for one account it's possible to obtain the current TOTP code for all other accounts.
Tushar Sharma (@tusharsharma_0) 's Twitter Profile Photo

Thank you Zerocopter !! Vulnerabilities - 3X SSRF leads to Port scanning ultimately creating DOS . (127.0.0.1:[PORT] - API endpoint leaking users email and name. #bugbounty #infosec

Thank you <a href="/zerocopter/">Zerocopter</a> !!

Vulnerabilities 
- 3X SSRF leads to Port scanning ultimately creating DOS . (127.0.0.1:[PORT]
- API endpoint leaking users email and name.

#bugbounty #infosec
️️Dipak Kumar Das (@d1pakdas) 's Twitter Profile Photo

Got a SSRF bypass via URL Shortener. 1. Got AWS metadata by supplying http://169.254.169.254/latest/meta-data/ in the vulnerable endpoint 2. Issue fixed 3. Bypass- Shorten the URL with bit.ly and used the shortned URL in the vulnerable endpoint. #bugbountytips

Got a SSRF bypass via URL Shortener.

1. Got AWS metadata by supplying http://169.254.169.254/latest/meta-data/ in the vulnerable endpoint
2. Issue fixed
3. Bypass- Shorten the URL with bit.ly and used the shortned URL in the vulnerable endpoint.
#bugbountytips
shubs (@infosec_au) 's Twitter Profile Photo

I just published a blog post for the people that want to get into bug bounties. I hope it helps people that are thinking about doing bug bounties, but haven't started yet. It explains what to expect and how to deal with common problems / situations: shubs.io/so-you-want-to…

Hussein Daher (@hussein98d) 's Twitter Profile Photo

Video of my talk at Security BSides Ahmedabad is finally out!🌟 🟥 Watch it on youtube: youtu.be/xnx0IQMQD3o 🟥 Slides available at webimmunify.com/bsides Thank you for your support. I'm looking forward to giving back more to the community soon 🎉 #bugbounty #cybersecurity

Video of my talk at <a href="/bsidesahmedabad/">Security BSides Ahmedabad</a> is finally out!🌟
🟥 Watch it on youtube: youtu.be/xnx0IQMQD3o  

🟥 Slides available at webimmunify.com/bsides  

Thank you for your support. I'm looking forward to giving back more to the community soon 🎉
#bugbounty #cybersecurity
Omid Rezaei (@omidxrz) 's Twitter Profile Photo

I just published a write-up about an account takeover where I abused reverse proxy to hijack the OAuth Code. blog.voorivex.team/hijacking-oaut…

Nagli (@galnagli) 's Twitter Profile Photo

Curious about how a $20,000 OAuth bug I discovered at a Live Hacking Event last year looks like? Today you can dive into an exact replica and see for yourself! I've collaborated with Ben Sadeghipour & HackingHub to create walkthrough video + demo lab 🧪 youtube.com/watch?v=VLgB2f…

Tushar Sharma (@tusharsharma_0) 's Twitter Profile Photo

Finished in the Top 10 of the Q1 India Leaderboard on HackerOne! Really hard with a full-time job 😅😥 Best quarter in terms of bounties earned on HackerOne Reported some quality bugs. Some of them, coming in collaboration with Yash Sharma #hackerone #bugbounty

Finished in the Top 10 of the Q1 India Leaderboard on <a href="/Hacker0x01/">HackerOne</a>! Really hard with a full-time job 😅😥

Best quarter in terms of bounties earned on <a href="/Hacker0x01/">HackerOne</a> 

Reported some quality bugs. Some of them, coming in collaboration with <a href="/05__Yash/">Yash Sharma</a> 

#hackerone #bugbounty
Tushar Sharma (@tusharsharma_0) 's Twitter Profile Photo

In June, I submitted 42 vulnerabilities to 14 programs on HackerOne . #TogetherWeHitHarder hackerone.com/last-month Reached 5000 reputation on HackerOne and finished in the Top 10 in the Quarterly Leaderboard (Apr-June). #bugbounty #hackerone

In June, I submitted 42 vulnerabilities to 14 programs on
<a href="/Hacker0x01/">HackerOne</a>
. #TogetherWeHitHarder hackerone.com/last-month   

Reached 5000 reputation on HackerOne and finished in the Top 10 in the Quarterly Leaderboard (Apr-June).

#bugbounty #hackerone