Bull Profile Banner
Bull Profile
Bull

@v0sx9b

7,225
Followers
174
Following
27
Media
317
Statuses

.HACK.

India
Joined August 2016
Don't wanna be here? Send us removal request.
Pinned Tweet
@v0sx9b
Bull
6 years
Stealing 10,000$ Yahoo Cookies!
10
161
390
@v0sx9b
Bull
3 months
No, this was no lucky find, but 7 months of pain for me! 7 months ago, I saw something I couldn't sleep on, while it consisted multiple pieces to it which i collected over the months, but it was not yet complete or had little hope to![Thread/2]
Tweet media one
47
37
580
@v0sx9b
Bull
4 years
Made $95k in #h12004 , thanks to amazing @TheParanoids and @Hacker0x01 ! And shout out to @_tabahi , would not have happened if I wasn’t hacking with him! 😆😎
Tweet media one
28
22
423
@v0sx9b
Bull
2 years
Nothing Feels Better than your First ever House. Exactly How we(& @_tabahi ) ever imagined it and Luxuries. 🎉 #Bugbounty
Tweet media one
Tweet media two
17
6
246
@v0sx9b
Bull
6 years
Ok! so this was my best month so far. I made $29,532.26 in total, of which $18,000 from @Hacker0x01 and $11,532.26 from @Bugcrowd . 😆🤣😀. Thanks to platforms.
Tweet media one
Tweet media two
31
19
232
@v0sx9b
Bull
6 years
Yay, I was awarded a $11,500 bounty (in which $1.5k bonus) on @Hacker0x01 ! #TogetherWeHitHarder
9
5
163
@v0sx9b
Bull
3 months
When I realised the final piece to it, even tough I haven’t tested it yet, knowing it will work and left my desk. Everything around me Blacked out in a way I had near zero consciousness of my surrounding, it lasted pretty long. And It worked! I had an absolute time of my life![2]
6
2
100
@v0sx9b
Bull
3 years
Excited to have joined Appsec @noon ! 🎉
12
0
94
@v0sx9b
Bull
4 years
Pic at Yahoo! Office LA with @_tabahi n @rootxharsh 😎
@Hacker0x01
HackerOne
4 years
Meet Shivam! Based in India, Shivam, @v0sx9b , is a full-time hacker. Shivam quit the traditional route of going to college and getting a desktop job and opted to pursue hacking as a full-time career. 🐂 More here: #TogetherWeHitHarder #HackForGood
Tweet media one
8
22
229
1
1
79
@v0sx9b
Bull
6 years
India's first live hacking event! Stoked and stoned to get this beautiful @Hacker0x01 h1-91832 MVH belt. Got to meet some Awesome hackers. Thanks for this amazing event, I had a very good time.
Tweet media one
Tweet media two
7
3
81
@v0sx9b
Bull
4 years
@_tabahi
Tabahi
4 years
Me and ⁦ @v0sx9b ⁩ got this sweet car with our bounties! #bugbountycar
Tweet media one
Tweet media two
10
6
162
0
0
73
@v0sx9b
Bull
4 years
My interview with HackerOne! 👀
@Hacker0x01
HackerOne
4 years
Meet Shivam! Based in India, Shivam, @v0sx9b , is a full-time hacker. Shivam quit the traditional route of going to college and getting a desktop job and opted to pursue hacking as a full-time career. 🐂 More here: #TogetherWeHitHarder #HackForGood
Tweet media one
8
22
229
2
4
65
@v0sx9b
Bull
6 years
Very Excited to say i have joined @SynackRedTeam ! 😀🙂😁
12
0
68
@v0sx9b
Bull
4 years
Go go @_tabahi , #2 ! 😁 great job! #h12010
Tweet media one
5
2
67
@v0sx9b
Bull
7 years
Reflected XSS on @Bugcrowd and so many other website's Main domain! I could read all your Submissions! Stay tunned
Tweet media one
5
3
57
@v0sx9b
Bull
6 years
Headed to Argentina for #h15411 ! Too excited about it! 😆
8
0
55
@v0sx9b
Bull
4 years
Just got @Hacker0x01 #h1213 poster framed! Reminds me of that one time in LA!
Tweet media one
2
2
54
@v0sx9b
Bull
6 years
And yahoo swag just arrived! My favourite. Thanks @YahooSecurity , loved it.😆😛
Tweet media one
Tweet media two
3
0
52
@v0sx9b
Bull
5 years
On my way to singapore for @Hacker0x01 #h165 ! ✈️ 👋 🙂
2
0
51
@v0sx9b
Bull
4 years
#h12004 was fun! Submitted only criticals! Checkout
2
0
46
@v0sx9b
Bull
6 years
It was an honor to sit down with @yaworsk and thanks to @tabahi_90 for encouraging me to do it!
@yaworsk
yaworsk
6 years
Sorry to all that came before him but think I just recorded my favorite Web Hacking ProTips interview to date with @v0sx9b . His #bugbounty success makes so much sense now. We talked a lot about the mental game to hacking and his approach to it is awesome. Hopefully up tomorrow.
9
6
90
3
0
47
@v0sx9b
Bull
7 years
My first swag is so awesome! Thanks @Bugcrowd and the team, me and my cat loved it! 😊❤❤ #ItTakesACrowd
Tweet media one
Tweet media two
Tweet media three
Tweet media four
7
0
42
@v0sx9b
Bull
6 years
Some of the best of my times! Awesome event and got to meet all the hackers! Thanks @Hacker0x01
@Hacker0x01
HackerOne
6 years
So proud to host an amazing group of talented hackers and partner with the Paranoids of @oath for yet another incredible event! We had the greatest percentage of first-time participants at a live hacking event EVER! We ❤️ you Argentina! #h15411 #eko14
Tweet media one
3
28
164
0
1
42
@v0sx9b
Bull
4 years
Just resigned from @SynackRedTeam ! 😏
3
0
38
@v0sx9b
Bull
7 years
Yahoooo, I was awarded a $10,000 bounty on @Hacker0x01 !
3
1
39
@v0sx9b
Bull
6 years
Yahoo hall of fame 2018! XD happy new year
Tweet media one
3
0
37
@v0sx9b
Bull
7 years
Whoo hoo! made it to #1 in #MasterCard hall of fame on @Bugcrowd
Tweet media one
5
1
35
@v0sx9b
Bull
7 years
If you wondering, this is stealing cookies and will probably do a writeup!
@v0sx9b
Bull
7 years
Yahoooo, I was awarded a $10,000 bounty on @Hacker0x01 !
3
1
39
3
1
28
@v0sx9b
Bull
6 years
You may steal headers above your Typical CRLF(which you cant push down with crlf to html body) by using a-c-expose-headers, a-c-allow-origin and a-c-allow-cred to read it with xhr such as /path/%0d%0a a-c-expose-headers: set-cookie
@v0sx9b
Bull
6 years
Stealing 10,000$ Yahoo Cookies!
10
161
390
2
3
27
@v0sx9b
Bull
7 years
oh no! I have just started to love yahoo XD
Tweet media one
2
0
26
@v0sx9b
Bull
7 years
All you ever wanted to know! Thanks for effort @prakharprasad
Tweet media one
1
3
25
@v0sx9b
Bull
6 years
I got so excited seeing Leets @fransrosen and @jobertabma in real. It was pleasure seeing them and @Hacker0x01 😄😄😄🤣
@Hacker0x01
HackerOne
6 years
Hackers hanging at @nullcon . @fransrosen @jobertabma Say 👋 and come by #hackerholi !
Tweet media one
Tweet media two
Tweet media three
5
11
105
0
0
25
@v0sx9b
Bull
7 years
Ssrf to AWS meta-data exfiltration via pdf generator for today.😎😁 #bugcrowd #bugbounty
3
4
24
@v0sx9b
Bull
5 years
On my way to LA! #h1213 see yaa! 🤟😎
1
0
21
@v0sx9b
Bull
6 years
I will be at my first security conference ! @nullcon ! Who else i will see there?
4
0
22
@v0sx9b
Bull
6 years
Find more bugs! 👇
@_tabahi
Tabahi
6 years
Just published my first bug bounty write up! 😀
3
61
199
0
1
21
@v0sx9b
Bull
4 years
Check out my 2019 Year In Review on @Hacker0x01 : ! #TogetherWeHitHarder
1
0
17
@v0sx9b
Bull
6 years
Buenos Aires
Tweet media one
1
0
18
@v0sx9b
Bull
3 years
Purrrrrr + 1
Tweet media one
Tweet media two
Tweet media three
0
0
18
@v0sx9b
Bull
6 years
@Hacker0x01 @okta Thanks @Hacker0x01 ! Cant tell how I am feeling! 💓😊😁
1
0
16
@v0sx9b
Bull
4 years
Awesome! 👏 helpfull!
@samwcyo
Sam Curry
4 years
Slides for "Attacking Secondary Contexts in Web Applications" -
13
362
784
0
1
16
@v0sx9b
Bull
7 years
Stay safe ya all yahoo accounts! XD #bugbounty #hackerone
Tweet media one
0
0
16
@v0sx9b
Bull
6 years
🤗
Tweet media one
Tweet media two
0
1
14
@v0sx9b
Bull
6 years
Spot good programs who occasionally offer bonus/promotion rewards
0
0
14
@v0sx9b
Bull
7 years
I dropped my college to Hack companies you get placed into (or wish to) #unqualifiedfortech
1
1
12
@v0sx9b
Bull
6 years
In such response 200 OK Set-Cookie: session Lang: en[your crlf Injection here] Non sensitve: headers
0
0
12
@v0sx9b
Bull
6 years
In 2017, I have submitted 22 vulnerabilities to 6 programs on @Hacker0x01 ! Check out my full recap at . Here's to many more reports to come! #TogetherWeHitHarder
1
2
11
@v0sx9b
Bull
7 years
Finally Cracked! Thank you for the challenge and awesome research.
@albinowax
James Kettle
7 years
I've built a replica of the most interesting vulnerability found in my Cracking the Lens research. Can you crack it?
3
33
81
1
0
10
@v0sx9b
Bull
3 years
Check out my 2020 Year In Review on @Hacker0x01 : ! #TogetherWeHitHarder
0
0
9
@v0sx9b
Bull
7 years
A week vacation at thailand with @tabahi_90 ! All Thanks to @Bugcrowd !
Tweet media one
1
0
10
@v0sx9b
Bull
5 years
1
0
9
@v0sx9b
Bull
6 years
@jobertabma @Hacker0x01 Thanks for the amazing event! Glad you liked my findings, super stoked to get MVH belt!😆😁😆
0
0
10
@v0sx9b
Bull
4 years
@Hacker0x01 Thank you @Hacker0x01 ! 👋 ❤️
0
0
9
@v0sx9b
Bull
8 years
First bug resolved and got paid on @Hacker0x01 . Yeaaa #bugbounty
1
1
9
@v0sx9b
Bull
6 years
finally cracked the ctf. It was hard and fun and so much. Thanks for the challenge :)
@jobertabma
Jobert Abma
6 years
Hackers, hack your way to NYC this December for h1-212! An engineer of launched a new server for a new admin panel. He is completely confident that the server can’t be hacked, so he hid a flag. Details: . #TogetherWeHitHarder
3
47
126
0
0
6
@v0sx9b
Bull
7 years
@gerben_javado @TomNomNom Took some time, but done!
Tweet media one
0
0
7
@v0sx9b
Bull
7 years
I just got rewarded $1,500 for my submission on @bugcrowd .
0
0
7
@v0sx9b
Bull
5 years
@tabahi_90 @Hacker0x01 Absolutely great job! Nice bug man congrats on five fig. ! 😮
1
0
7
@v0sx9b
Bull
6 years
@jobertabma @Hacker0x01 @Bugcrowd Thank you! 😁 and looking forward to see you at @nullcon
0
0
7
@v0sx9b
Bull
7 years
If you have forgotten, this will bypass most of the CRLF blacklist filters- Just bypassed one!
0
3
6
@v0sx9b
Bull
6 years
0
0
6
@v0sx9b
Bull
4 years
@bhavukjain1 @Apple Congrats man! 😬
0
0
6
@v0sx9b
Bull
8 years
Some quick triage and reward before weekend! #bugbonty awesome on @Bugcrowd
Tweet media one
0
0
6
@v0sx9b
Bull
4 years
@w_hat_boy @tabahi_90 Really! I can’t get enough 😍
0
0
5
@v0sx9b
Bull
6 years
@mongobug xss would read data from bank and even perform actions using locker key(csrf token) and i have many more and can write a full blogpost on scope.
1
0
6
@v0sx9b
Bull
6 years
@caseyjohnellis @Bugcrowd Thanks 😁. My first P1 not to be dup took significant time. Company removed the service as fix. Lol
Tweet media one
0
0
5
@v0sx9b
Bull
6 years
1
0
6
@v0sx9b
Bull
5 years
@Hacker0x01 @inhibitor181 Absolute legend there! Congrats on MVH man! 🙌
0
0
6
@v0sx9b
Bull
6 years
@stokfredrik @Hacker0x01 Woo! Congrats 👏
0
0
5
@v0sx9b
Bull
6 years
@tabahi_90 @Hacker0x01 Huge! Rocking 🤣
1
0
5
@v0sx9b
Bull
6 years
@mongobug Yes alot! I have many reports in small scope program on out of scope assets resolved! When the cookie scope is set to *.target.com its right their game over. Subdomain takeover / rce would steel them. Even if it’s cookies not scoped wide, alot CORS allow *.target.com and small1/2
2
0
5
@v0sx9b
Bull
6 years
@bugbountyforum @orange_8361 Thank you, amazing! 🍊
0
0
5
@v0sx9b
Bull
6 years
@akita_zen Sure man! I have checked in, where are you?
0
0
5
@v0sx9b
Bull
7 years
So many programs are just advertising themselves with big reward. :/
0
1
5
@v0sx9b
Bull
3 months
@silentgh00st Thank you!
0
0
4
@v0sx9b
Bull
6 years
@mongobug I think those poorly protected houses DO have direct link with bank(in most cases) and alot of programs have been setting up wrong scope due to budget reasons/ less understanding etc (not talking about those who have no intentions to break into bank)
1
0
4
@v0sx9b
Bull
7 years
@locomotivecms zero day xss on @Bugcrowd ! How i could read your submission data!
2
3
4
@v0sx9b
Bull
6 years
@uraniumhacker Thanks man! 🤣
0
0
4