Vijith Vellora (@vijithvellora) 's Twitter Profile
Vijith Vellora

@vijithvellora

Security Analyst | Former Assistant commander @Cyberdomekerala 🇮🇳 | Hacker by Profession & Passion. Acknowledged by Google, Sony, Nokia, AT&T, IBM, Etc.

ID: 2176812868

linkhttp://vijithvellora.in calendar_today11-11-2013 11:01:30

1,1K Tweet

572 Followers

882 Following

Intigriti (@intigriti) 's Twitter Profile Photo

You've found a GraphQL target... But you don't have much time to test your target for every vulnerability... 😴 Here are 4 tools you can easily use to find over 5+ vulnerabilities in GraphQL APIs! 🤑 A thread! 👇

You've found a GraphQL target...

But you don't have much time to test your target for every vulnerability... 😴 

Here are 4 tools you can easily use to find over 5+ vulnerabilities in GraphQL APIs! 🤑 

A thread! 👇
zhero; (@zhero___) 's Twitter Profile Photo

happy to release my new article entitled: Next.js and cache poisoning: a quest for the black hole zhero-web-sec.github.io/research-and-t… good reading;

happy to release my new article entitled:

Next.js and cache poisoning: a quest for the black hole

zhero-web-sec.github.io/research-and-t… 

good reading;
Orange Tsai  🍊 (@orange_8361) 's Twitter Profile Photo

Thrilled to release my latest research on Apache HTTP Server, revealing several architectural issues! blog.orange.tw/2024/08/confus… Highlights include: ⚡ Escaping from DocumentRoot to System Root ⚡ Bypassing built-in ACL/Auth with just a '?' ⚡ Turning XSS into RCE with legacy code

Johann Rehberger (@wunderwuzzi23) 's Twitter Profile Photo

Prompt Injection can impact all aspects of the CIA security triad (Confidentiality, Integrity and Availability). arxiv.org/abs/2412.06090

Emad Shanab - أبو عبد الله (@alra3ees) 's Twitter Profile Photo

Find xss with KNOXSS Find subdomains. subfinder -d domain -all | httpx -o subs1 subdominator -d domain | httpx -o subs2 Merge all subs in one file cat sub1 subs2|anew subs Find history. cat subs | wayback |anew xss-wayback katana -list subs -o xss-katana cat subs | gau

YesWeHack ⠵ (@yeswehack) 's Twitter Profile Photo

With DomLogger++ by Kévin GERVOT (Mizu), tracking DOM interactions has never been easier for XSS testing! ☝ This powerful tool logs DOM modifications in real time, helping you pinpoint vulnerable elements and uncover interesting behaviours 🕵️ Check it out 👉 github.com/kevin-mizu/dom…

Vijith Vellora (@vijithvellora) 's Twitter Profile Photo

Excited to be named in Yogosha’s Top 10 Security Researchers for Q1 2025! 🎉 Big thanks to the Yogosha team for the shoutout. Congrats to all the talented researchers on the list!🕵️‍♂️🔒 #BugBounty #CyberSecurity #Yogosha

Orange Tsai  🍊 (@orange_8361) 's Twitter Profile Photo

Turns out my #PHRACK article is live! 🔥 > The Art of PHP — My CTF Journey and Untold Stories! Kinda a love letter to those CTF players & PHP nerds! Hope all the credit goes to the right ppl. Also huge thanks to [email protected] for not forgetting me, TMZ for the edits, and the

Turns out my #PHRACK article is live! 🔥

> The Art of PHP — My CTF Journey and Untold Stories!

Kinda a love letter to those CTF players &amp; PHP nerds! Hope all the credit goes to the right ppl. Also huge thanks to <a href="/0xdea/">raptor@infosec.exchange</a> for not forgetting me, <a href="/guitmz/">TMZ</a> for the edits, and the
Caido (@caidoio) 's Twitter Profile Photo

We’re expanding localized pricing to India! 🇮🇳 Individual plan prices drop by nearly 65%: 💸 Monthly: ~1,750 INR → 625 INR 💸 Yearly: ~17,500 INR → 6,250 INR Know a hacker in India who’s been waiting? Tag them. 👇 caido.io/blog/2025-08-2…

Frida (@fridadotre) 's Twitter Profile Photo

Frida 17.4 introduces Simmy, a new backend for Apple’s Simulators on macOS. Spawn, attach, and instrument apps — just like on a real device.

Behi (@behi_sec) 's Twitter Profile Photo

Bug Bounty Tool: Kiterunner bruteforces API routes using contextual wordlists to uncover hidden endpoints fast: GitHub github.com/assetnote/kite…

Abdelrhman Allam 🇵🇸 (@sl4x0) 's Twitter Profile Photo

Me and a friend just landed a bounty for an RCE using a technique I addict it earlier and have kept refining ever since. Grateful for the results. Alhamdulillah. More here: sl4x0.xyz/turning-depend… or sl4x0.medium.com/turning-depend…

Me and a friend just landed a bounty for an RCE using a technique I addict it earlier and have kept refining ever since. Grateful for the results. Alhamdulillah.  

More here:
sl4x0.xyz/turning-depend… or sl4x0.medium.com/turning-depend…
Godfather Orwa 🇯🇴 (@godfatherorwa) 's Twitter Profile Photo

I’ve added here github.com/orwagodfather/… PDF file for XSS, it can bypass any waf for who looking for Stored XSS , and it can be changed to blind if you want to Simply I encoded the payload as ASCII hex You can edit the payload over notepad++ #bugbountytips #bugbountytip

I’ve added here 
github.com/orwagodfather/…

PDF file for XSS, it can bypass any waf 
for who looking for Stored XSS , and it can be changed to blind if you want to

Simply I encoded the payload as ASCII hex

You can edit the payload over notepad++

#bugbountytips  #bugbountytip
André Baptista (@0xacb) 's Twitter Profile Photo

Need to find the APIs the devs forgot about? Combine waymore with xnLinkFinder or similar. - waymore: Gathers the archived URL responses. - xnLinkFinder: Extracts the hidden paths and parameters. GitHub repos 👇 github.com/xnl-h4ck3r/way… github.com/xnl-h4ck3r/xnL…

Need to find the APIs the devs forgot about?

Combine waymore with xnLinkFinder or similar.

- waymore: Gathers the archived URL responses.
- xnLinkFinder: Extracts the hidden paths and parameters.

GitHub repos 👇

github.com/xnl-h4ck3r/way…
github.com/xnl-h4ck3r/xnL…
Sahil Choudhary (@sahilsince2000) 's Twitter Profile Photo

No jailbreak. No problem. 🔓 I built a tool that bypasses iOS SSL Pinning using OpenVPN + iptables — works with Burp Suite & mitmproxy out of the box. 👇 GitHub github.com/SahilH4ck4you/… #CyberSecurity #BugBounty #iOS #Pentesting

Vasileiadis A. (Cyberkid) (@anastasis_king) 's Twitter Profile Photo

Claude Bug Bounty Hunter - Claude Code skill for AI-assisted bug bounty hunting - recon, IDOR, XSS, SSRF, OAuth, GraphQL, LLM injection, and report generation github.com/shuvonsec/clau…

Claude Bug Bounty Hunter - Claude Code skill for AI-assisted bug bounty hunting - recon, IDOR, XSS, SSRF, OAuth, GraphQL, LLM injection, and report generation

github.com/shuvonsec/clau…