_jensec's profile picture. Web2 and AI Offensive Security research. Creator of http://crxplorer.com Security @Exodus

Jenish Sojitra

@_jensec

Web2 and AI Offensive Security research. Creator of http://crxplorer.com Security @Exodus

Pinned

Last month was my highest in bug bounty so far with almost $131k in bounty. Total paid reports: 18 Average reward: $7.3k Category: most were logical findings via reversing mobile applications and discovering internal endpoints leading to code execution and missing auth etc

_jensec's tweet image. Last month was my highest in bug bounty so far with almost $131k in bounty. 

Total paid reports: 18
Average reward: $7.3k
Category: most were logical findings via reversing mobile applications and discovering internal endpoints leading to code execution and missing auth etc

Does anyone has experience with @Microsoft bug bounty program? Specifically Azure


Jenish Sojitra reposted

“Kill the boy, Jon Snow. Kill the boy and let the man be born.” This is very important if you want to do anything in life.


I live in India so according to PPP, I make equivalent $1,041,600 in states. x.com/i/grok?convers… Doing Bug bounty makes great sense looking at PPP when you are in low PPP countries but not so much when in states.

240k TC and that too without insurance, 401k, or any safety net. One flu, one triager in bad mood, one company dispute - income gone. No paid leave, no stability, no compounding equity. Damn that’s quite less unless you’re in LCOL.



I usually brute-force API paths with "Debug":true parameter and often it leads to reveal internal debug info to reverse proxies exposing API secrets and tokens.

_jensec's tweet image. I usually brute-force API paths with "Debug":true parameter and often it leads to reveal internal debug info to reverse proxies exposing API secrets and tokens.

I think portswigger.net/web-security is one of the best way to start learning web security

As someone that has no knowledge what so ever in this field, what/where would you recommend to start learning ? I'm very curious how one get into this field, it seems fun somehow



Last year, I accidently hacked into @united airlines and found an issue that allowed me to buy inflight food and merchandise for free. Funny part, Both United Security team and I had to onboard an actual flight to verify the finding. United Awarded me 500k rewards miles

_jensec's tweet image. Last year, I accidently hacked into @united airlines and found an issue that allowed me to buy inflight food and merchandise for free.

Funny part, Both United Security team and I had to onboard an actual flight to verify the finding. 

United Awarded me 500k rewards miles

Jenish Sojitra reposted

~30 Bugs pending on HackerOne waiting to be paid. Hoping November to be a good month


2 months back into bug bounty with an year long break and I already made ~$40k. Imposter syndrome is real.


Nice finding - I always wondered if this type of testing is legal and allowed when there is no bug bounty program and agreement b/w parties. There are millions of companies and portal with such flows that we can exploit

We found a way to access Max Verstappen's passport, driver's license, and personal information. Along with every other @Formula1 driver's sensitive data. It took us 10 minutes using one simple security flaw 🧵

galnagli's tweet image. We found a way to access Max Verstappen's passport, driver's license, and personal information. Along with every other @Formula1 driver's sensitive data. 

It took us 10 minutes using one simple security flaw 🧵


Happy Diwali 🧨


BugBounty platforms who won’t stay true and transparent to hackers will lose the business.


Recently had a road trip with my mom in Italy 🇮🇹

_jensec's tweet image. Recently had a road trip with my mom in Italy 🇮🇹
_jensec's tweet image. Recently had a road trip with my mom in Italy 🇮🇹
_jensec's tweet image. Recently had a road trip with my mom in Italy 🇮🇹
_jensec's tweet image. Recently had a road trip with my mom in Italy 🇮🇹

Everyone needs a summer in Europe

kaushikmuraliux's tweet image. Everyone needs a summer in Europe
kaushikmuraliux's tweet image. Everyone needs a summer in Europe
kaushikmuraliux's tweet image. Everyone needs a summer in Europe
kaushikmuraliux's tweet image. Everyone needs a summer in Europe


Lmao 😭😂😂

_jensec's tweet image. Lmao 😭😂😂

I have created an API product for Crxplorer to help with usability and growing infra cost. Checkout crxplorer.com/api-access

_jensec's tweet image. I have created an API product for Crxplorer to help with usability and growing infra cost. 

Checkout crxplorer.com/api-access

You do not need Courses and Certificates to make your first 100k in InfoSec.


Jenish Sojitra reposted

back in 2023, i found a vulnerability on Discord to grab a support ticket details using just it's id. ticket ids are incremental so an attacker could have enumerated the entire platform and stolen everything. i reported it to their bug bounty program. they marked it as an…

hackermondev's tweet image. back in 2023, i found a vulnerability on Discord to grab a support ticket details using just it's id. 

ticket ids are incremental so an attacker could have enumerated the entire platform and stolen everything.

i reported it to their bug bounty program. they marked it as an…

Loading...

Something went wrong.


Something went wrong.