Electrical engineer Hacking the planet, full time, in pink. Always curious, constantly learning. Bug bounty Hunter on @bugcrowd and @hacker0x01

127.0.0.1
Joined January 2023
Perks of being a Bug Bounty Hunter: Found a bug in GitHub, got it accepted, and now I have GitHub Pro for FREE… FOREVER.
8
7
124
Authentication Bypass via forgot password 18 days in triage is never a good sign though. #bugbounty
5
103
Today I found a promising CORS misconfiguration that should have leaked PII! Here’s a critical detail that’s often missed. For successful exploitation, the ‘SameSite’ attribute on the cookie must be set to ‘Lax’ or ‘None’. In this case it was set to ‘Strict’🛡️ #BugBounty #CORS
My first paid bug on Bugcrowd was an Authentication Bypass. I will definitely push a write up after I’m done with my research! :)
22
4
3
215
Of course, why would I work for free ¯\_(ツ)_/¯
3