Shodan is one of my favorite recon tools. It helps me find exposed servers, APIs, and misconfigs during bug bounty hunting. A must-have for any hacker.
#Shodan#BugBounty#OSINT#Recon#InfoSec
As an ethical hacker, I’m currently working on a target where I’ve identified 15 live subdomains using Google Dorking and GitHub recon. Each subdomain was verified through tools like httpx and dnsx.
Recon on a live domain for a #BugBounty program — subdomain enum, DNS analysis & attack surface mapping.
Meanwhile solving @TryHackMe rooms to sharpen my web exploitation & enum skills.
Learn. Practice. Apply.
#EthicalHacking#Infosec#CyberSecurity
Discovered a powerful subdomain enumeration tool called OneForAll
Python-based, supports passive and active recon
Also checks for subdomain takeover
GitHub: github.com/zhzyker/OneFor…
bugbounty recon subdomain oneforall infosec
rubid=3 causes 500 Internal Server Error on GET & HEAD requests, while other values return 200 OK. Indicates a backend bug and poor input validation. #BugBounty#WebSecurity#Pentesting
Found a login endpoint that throws 500 Internal Server Error when a long password is submitted. Repeated requests slow the server down to 3–4s response time. Possible DoS via input overload.
#BugBounty#DoS#WebSecurity#OpenBugBounty
I have identified a rate limiting vulnerability while testing a domain on the OpenBugBounty platform
The forgot password feature was accepting multiple reset requests without any proper rate limiting control
Successfully reported multiple security vulnerabilities via OpenBugBounty.org.
The reports have been accepted and are now visible.
Following responsible disclosure policy, no technical details are shared.
Grateful for the opportunity to contribute to a safer internet.
Discovered a DOM Based XSS vulnerability today
The payload executes entirely on the client-side without any server-side reflection
Identifying DOM XSS can be challenging, but proper analysis makes it possible
Alhamdulillah
Found a SQL Injection vulnerability on a live domain during testing via OpenBugBounty.
Target is out of scope, so couldn’t report it.
Still, a great learning experience.
#BugBounty#SQLi#CyberSecurity#JakirPentest#EthicalHacking
Discovered a phpinfo() info leak on a live domain via OpenBugBounty. Not submitted — out of scope per platform rules.
Always check scope before reporting.
[domain]net/alp/info.php
#BugBounty#ResponsibleDisclosure#InfoSec
Hello everyone,
I’m Md Jakirul Alam, an Ethical Hacker and Security Enthusiast from Bangladesh.
Starting my journey in cybersecurity and ethical hacking. Excited to learn and contribute.
#cybersecurity#infosec
"Exploring the world of Ethical Hacking and learning something new every day! 💻🔐
Cybersecurity is both exciting and challenging, and I'm loving the journey so far. 🚀
What's your favorite cybersecurity tip or tool?
#EthicalHacking#CyberSecurity#LearnToHack"
1 Followers 31 FollowingI'm a beginner in ethical hacking and bug bounty, currently focused on learning mobile app and API security through platforms like TryHackMe and HackerOne. I'm
3 Followers 49 FollowingI'm a Cloud Engineer building & deploying on AWS with Terraform(IaC), containers, & security. || AI Solution Architect(Small Business). || Also a Dropshipper.
76 Followers 2K Following🐞 Bug Bounty Hunter | 🧠 Think like a dev, hack like a ghost
Focus: Business Logic | RCE | LFI | SSRF
On a $10K mission | #YesWeHack #bugcrowd
9 Followers 47 FollowingI wanna help people who needs it. I wanna live my full potential. I wanna bring peace not only for myself but for anyone in the world. I work for a better world
381 Followers 116 FollowingApplication Security Specialist | Red Teamer | Researcher at Synack Red Team | OSCP-OSEP-OSWE-ECPPT-CRTE/P/O | CTF Player @DeadSecCTF Capturing flags since 2011
275K Followers 447 FollowingCo-Founder of ByteByteGo | Author of the bestselling book series: ‘System Design Interview’ | YouTube: https://t.co/9gPSJSrtPU
2K Followers 2K Following16 year old whimsical wizard and part time fintech phantom. Red Team & Bug Bounty. CPTS,CRTP | Views are my own. Not affiliated with my employer.
22 Followers 186 Followingbe very careful with what you do on the Internet everything leaves traces!;🧑💻
which one should be tested?;(
4920616d206d65207468657265206973206e6f2032
1 Followers 32 Following🌒 Where time slips & secrets linger 🌒 Echoes in the machine, whispers in void 🌒 Deciphering patterns of fractured reality 🌒 Beauty in the broken code