Rockpratapsingh's profile picture. Radhe Radhe 🙏 || Security Researcher | Bug Hunter | Ethical Hacker | VAPT |  Google, Nokia, NASA, Apple, Lenovo, Blackberry, Cambridge, Indian UK gov HOF🇮🇳 |

Rock Pratap Singh (Rocksec)

@Rockpratapsingh

Radhe Radhe 🙏 || Security Researcher | Bug Hunter | Ethical Hacker | VAPT | Google, Nokia, NASA, Apple, Lenovo, Blackberry, Cambridge, Indian UK gov HOF🇮🇳 |

Rock Pratap Singh (Rocksec) reposted

Bro is solo carrying Bug Bounty twitter rn

Classic IDOR, but lets talk SSRF: /pdfEngine/v2/prepaidStatement?consNo={consumer}&month=April&year=2025 One of the things I've been seeing more (not less) of, is developers passing parameter values like this {consumer} into back end paths. So lets assume this, on the back…



Rock Pratap Singh (Rocksec) reposted

🚨 Doing a giveaway for my Blind XSS Masterclass Most people think they know XSS, until they meet blind XSS, the kind that fires where you’ll never see it. Same methods that helped me earn $250K+ from real reports. hhub.io/nahamsecbxss 🎁 Retweet and reply to enter.

NahamSec's tweet image. 🚨 Doing a giveaway for my Blind XSS Masterclass
Most people think they know XSS, until they meet blind XSS, the kind that fires where you’ll never see it.
Same methods that helped me earn $250K+ from real reports. hhub.io/nahamsecbxss
🎁 Retweet and reply to enter.

osm techniques♥️♥️

Just released the Ultimate IDOR Testing Checklist 🧩 I combined techniques from many sources to cover IDOR scenarios. Know a technique I missed? Drop it in the comments. Notion: mrdesoky0.notion.site/Ultimate-IDOR-… GitHub: github.com/mrdesoky0/vuln… #bugbountytips #IDOR #AppSec #InfoSec

mrdesoky0's tweet image. Just released the Ultimate IDOR Testing Checklist 🧩

I combined techniques from many sources to cover IDOR scenarios.

Know a technique I missed? Drop it in the comments.

Notion:
mrdesoky0.notion.site/Ultimate-IDOR-…
 
GitHub:
github.com/mrdesoky0/vuln…

#bugbountytips #IDOR #AppSec #InfoSec
mrdesoky0's tweet image. Just released the Ultimate IDOR Testing Checklist 🧩

I combined techniques from many sources to cover IDOR scenarios.

Know a technique I missed? Drop it in the comments.

Notion:
mrdesoky0.notion.site/Ultimate-IDOR-…
 
GitHub:
github.com/mrdesoky0/vuln…

#bugbountytips #IDOR #AppSec #InfoSec
mrdesoky0's tweet image. Just released the Ultimate IDOR Testing Checklist 🧩

I combined techniques from many sources to cover IDOR scenarios.

Know a technique I missed? Drop it in the comments.

Notion:
mrdesoky0.notion.site/Ultimate-IDOR-…
 
GitHub:
github.com/mrdesoky0/vuln…

#bugbountytips #IDOR #AppSec #InfoSec
mrdesoky0's tweet image. Just released the Ultimate IDOR Testing Checklist 🧩

I combined techniques from many sources to cover IDOR scenarios.

Know a technique I missed? Drop it in the comments.

Notion:
mrdesoky0.notion.site/Ultimate-IDOR-…
 
GitHub:
github.com/mrdesoky0/vuln…

#bugbountytips #IDOR #AppSec #InfoSec


Radhe Radhe🙏🙏Bounty time☺ 🐞Bug: 1. Mobile Number modified Without Verification 2. Identity Verification Bypass via API Manipulation 💰 Bounty: $$$$ #bugbounty #bugcrowd #bounty #hacker #vulnerability #xss #bughunting #rockpratapsingh #hackerone #vdp #security

Rockpratapsingh's tweet image. Radhe Radhe🙏🙏Bounty time☺

🐞Bug: 
1. Mobile Number modified Without Verification
2. Identity Verification Bypass via API Manipulation 

💰 Bounty: $$$$

#bugbounty #bugcrowd #bounty #hacker #vulnerability #xss #bughunting #rockpratapsingh #hackerone #vdp #security

Radhe Radhe🙏🙏Bounty time🥳🥳 🐞Bug: Stored XSS leads to ATO 💰 Bounty: $$$$ ❤️‍🔥Resources (Reports & writeups) to learn XSS❤️‍🔥 1. github.com/resources/arti… 2. share.google/Lhzeqfrk2Zib38… 3. share.google/gGyNhXFnVud47j… 4. 5. share.google/EGS7L0Fb9Dfz3F… #bugbounty

Rockpratapsingh's tweet image. Radhe Radhe🙏🙏Bounty time🥳🥳

🐞Bug: Stored XSS leads to ATO 
💰 Bounty: $$$$

❤️‍🔥Resources (Reports & writeups) to learn XSS❤️‍🔥

1. github.com/resources/arti…

2. share.google/Lhzeqfrk2Zib38…

3. share.google/gGyNhXFnVud47j…

4. 

5. share.google/EGS7L0Fb9Dfz3F…
#bugbounty

Rock Pratap Singh (Rocksec) reposted

Hey @Shopify @Hacker0x01 ... I have had two bug hunters come to me and tell me horror stories about your bug bounty lately. Valid bugs being exploited and you coming out saying... "oh we had planned on fixing that... no impact" That is NOT the bug bounty contract. If there…


Loading...

Something went wrong.


Something went wrong.