root@AkashHamal0x01:~/ # 🇵🇭 Profile picture
Solo | https://t.co/I6KH8X4bpm | Community Helper 🤝| WebApp Security 🐞 | !Hacker | Avid Learner 📖 | He/Him | #HackingForLiving
Apr 19, 2022 24 tweets 5 min read
🧵A Thread:
2+ years in bugbounty here are my stats:

->Total reports: 403

⟢Resolved: 59
⟢N/A: 81
⟢Duplicate: 82
⟢Informative: 165
⟢Triaged: 13
⟢New: 3

Approach: Manual testing, 0% recon!

Here is what i learnt 👇

#BugBounty #Infosec 1/n Initially starting everyone does mistakes, we grow up learning from others . So don't give up keep learning and stay persistent
Sep 7, 2021 8 tweets 2 min read
I have seen many reports regarding MFA bypass and many repos has got techniques to bypass MFA but here is one of my personal method or never seen before technique to bypass MFA, make sure to add it to your checklist ;)..... follow 👇

#bugbountytips #bugbountytip #bugbountytip 1) access control issues are everywhere in website right?

normal login flow :

email + passwd => mfa => enters acc

the flaw :

email + password => enters wrong mfa code and intercepts the req with burp, changes request line and params .....