mr_encryption's profile picture. A web 3 Smart contract Auditor

Mr_encryption 🇮🇳

@mr_encryption

A web 3 Smart contract Auditor

Pinned

@emgeekboy @Farah_Hawaa @thedawgyg Thank you guys for your videos and writeup , Today i finally got my first 4 digits bounty✌✌😊

mr_encryption's tweet image. @emgeekboy @Farah_Hawaa @thedawgyg 

Thank you guys for your videos and writeup , Today i finally got my first 
4 digits bounty✌✌😊

Mr_encryption 🇮🇳 reposted

Seeing a potential re-entrancy exploit with the @SteadyStackNFT contract. Looks like anyone on the goldlist can re-use their signatures to mint as many NFTs as they want. There's no supply check on this function so someone could mint out the remaining supply (limited by gas).

0xCygaar's tweet image. Seeing a potential re-entrancy exploit with the @SteadyStackNFT contract.

Looks like anyone on the goldlist can re-use their signatures to mint as many NFTs as they want.

There's no supply check on this function so someone could mint out the remaining supply (limited by gas).

Just started doing web3 development. Alchemy is helping me learn with tutorials and deploy smart contracts. Check it out here: alchemy.com/?s=zM0NTM3NzA4… 🙌


Hey @auroraisnear Need help regarding one issue, please check my DM


Hey @MyOnlineCA I am facing an issue on Refund status .Please Help me regarding this

mr_encryption's tweet image. Hey @MyOnlineCA 

I am facing an issue on Refund status .Please Help me regarding this

Mr_encryption 🇮🇳 reposted

I found Critical Idor in Instagram And I Got 49500$ Bounty (45000$ Bounty And 4500 $ Bonus) From Facebook. #Facebook #Bugbounty #instagram #cybersecurity #infosec

root_n33r4j's tweet image. I found Critical Idor in Instagram And  I Got 49500$ Bounty (45000$ Bounty And 4500 $ Bonus) From Facebook. 
#Facebook #Bugbounty #instagram #cybersecurity  #infosec

Mr_encryption 🇮🇳 reposted

Hacking APIs Book Giveaway sponsored by APIsec.ai! We are giving away 10 print books. One entry per: ♥️ Like 🔁 RT 👑Bonus entry to anyone who follows @apisec_ai. Ends in 48 hours!

hAPI_hacker's tweet image. Hacking APIs Book Giveaway sponsored by APIsec.ai! We are giving away 10 print books. 

One entry per:
♥️ Like 🔁 RT

👑Bonus entry to anyone who follows @apisec_ai.  Ends in 48 hours!

Mr_encryption 🇮🇳 reposted

Authorization. Easy to understand. Critical if implemented incorrectly. Want to see an example? (dumb question Corben, yes, why not) Last month, I found an auth bypass that lead to a full account takeover. Here's how I found it:


Mr_encryption 🇮🇳 reposted

302 Military FTP servers. Imagine you had access to 302 military FTP servers. What data could possibly be on them? Who would get hurt by that data? Who would it benefit? 5 years ago, A 17-year-old gained access to 300 military FTP servers. Here's how I did it:


AI ( Artificial intelligence) these days 💥💥😄 @apple @Meta


Mr_encryption 🇮🇳 reposted

😂😂😂😂😂

ofjaaah's tweet image. 😂😂😂😂😂

Mr_encryption 🇮🇳 reposted

Shopify disclosed a bug submitted by @mr_encryption: hackerone.com/reports/1406495 - Bounty: $900 #hackerone #bugbounty

disclosedh1's tweet image. Shopify disclosed a bug submitted by @mr_encryption: hackerone.com/reports/1406495 - Bounty: $900 #hackerone #bugbounty

Mr_encryption 🇮🇳 reposted

Tips to look for log4j with @Burp_Suite - #bugbountytips #log4j #RCE #bugbounty 1- You can use wappalyzer to check whether application is using java or not addons.mozilla.org/en-US/firefox/… 2- Like this see attached pic 1 , web app is using java 3- Now open your burp > checkout

krishnsec's tweet image. Tips to look for log4j with @Burp_Suite  - #bugbountytips #log4j #RCE #bugbounty 
1- You can use wappalyzer to check whether application is using java or not 
addons.mozilla.org/en-US/firefox/…
2- Like this see attached pic 1 , web app is using java 
3- Now open your burp > checkout

Hello @GodfatherOrwa @Samm0uda Recently I found a hidden Source code file link( http://××××××/app.js) of Company X login page. Can i report this issue directly to Company X or digg deeper in JS file?. What's your view ?


First Log4j Dos submission 😄

mr_encryption's tweet image. First Log4j Dos submission 😄

Mr_encryption 🇮🇳 reposted

Impressive work here! 🙌💫🌟 #bugbounty #infosec

Just Updated my Subdomain Enumeration Guide with new techniques, fixes, etc. Have a look 😊 Boost your Recon game !!🚀🚀 sidxparab.gitbook.io/subdomain-enum… #bugbounty #infosec

sidxparab's tweet image. Just Updated my Subdomain Enumeration Guide with new techniques, fixes, etc.

Have a look 😊
Boost your Recon game !!🚀🚀

sidxparab.gitbook.io/subdomain-enum…

#bugbounty #infosec


Mr_encryption 🇮🇳 reposted

Let’s have some fun, I’m going to give away $30,000 to 1 random person who retweets this tweet AND follows @Pulte and me!!! (So we can dm you the money if you win). Will show proof of paying winner ❤️


First zero click vulnerability 😊

mr_encryption's tweet image. First zero click vulnerability 😊

Loading...

Something went wrong.


Something went wrong.