Mumtaz Khan @Hacker_O
Penetration tester @ logiciel services || ISO 27001 || Cyber security Professional Pakistan Joined November 2019-
Tweets1K
-
Followers92
-
Following409
-
Likes364
If you seriously want to improve at bug bounty hunting, study real reports. One of the best repositories for that: github.com/reddelexc/hack… Thousands of publicly disclosed HackerOne reports collected in one place. A great resource to understand how top researchers think, approach targets, chain issues, and write impactful reports. Worth spending time on. #BugBounty #CyberSecurity #InfoSec #AppSec
The Claude Code tooling I have been mentioning in my recent bounty posts is a forked version of strix-claude-code Started using it a few months ago. Added a triage step that spawns a new agent with no context to verify findings, cut my false positives down a lot. Got $3000 + $100 on intigriti for bypasses of resolved reports, $500 on h1, an RCE I am still verifying Not full proof. Still get false positives, still spend days verifying pocs. But overall it works really well Open sourcing it today: github.com/arshadkazmi42/…
Best Resources for IDOR
Just released the Ultimate IDOR Testing Checklist 🧩 I combined techniques from many sources to cover IDOR scenarios. Know a technique I missed? Drop it in the comments. Notion: mrdesoky0.notion.site/Ultimate-IDOR-… GitHub: github.com/mrdesoky0/vuln… #bugbountytips #IDOR #AppSec #InfoSec
A lot of people are now building and using their own hackbots daily. Here's a nice blog on using AI to hunt for vulns by @0xAsm0d3us. Some takeaways that I've also been experiencing: > Instead of asking "is this code secure?", ask "how would you break this?". This shifts the flow from auditor to attacker. It will force it to generate attack strategies. > Avoid bloated prompts. Stuffing big MD files and skills into context degrades reliability of the model. Your scaffolding becomes the haystack and the bug becomes the needle. > Don't just say "find bugs". Assert the bug exists, e.g. this function has 3 vulnerabilities, find them, don't quit. Further reading: devansh.bearblog.dev/needle-in-the-…
🚨 As of tomorrow I am permanently reducing my course cost by 50% to $100 so more people have access to it and can get those bounties while they are still hot. And yes, they are still hot. The internet is still full of stupid problems waiting to be found for those looking, at least for now... t.co/HsobzB2lOi I suspect we have about 2 years of decent #bugbounty hunting left before most companies have access to and properly leverage the tools like Mythos that effectively replace "most" hackers. Using the EXACT methods in this course, I found 20+ critical bugs on a target in a matter of hours the other day. Nothing fancy. The internet is just too dang big to fix and patch in a small amount of time, even if AI is finding the bugs. Internal legacy human processes with 500 steps are still bottle-necking remediation. What the bug bounty world becomes next is anyone's guess. My suspicions, hackers will be paid flat rates for hacking and/or patching targets any way they can (be it AI, manually, or both). So, here's to the next evolution of hacking, which is hopefully round-table LHE's where we all work together on targets to harden them as best as possible, instead of working against each other to try to "be the best hacker". Re-post for a chance to win 1 of 5 course coupons for a give away on May 14th. I'll have Grok pick the winners.
Google Bug Hunter University — Learn to Find & Report Bugs Official learning hub from Google for bug bounty hunters. • Where to hunt (targets) • How to write valid reports • Common mistakes (invalid reports) • Real rewarded submissions If your reports keep getting rejected, start here. bughunters.google.com #BugBounty #AppSec #CyberSecurity #Infosec #Google
Using Claude Code for secure code review (@Sw4mp_f0x) specterops.io/blog/2026/03/2… #infosec #llm
Every JWT writeup online covers 2–3 attacks and stops. I got tired of jumping between 40 blog posts, so I wrote the whole thing. All in one place. rmrf.tips/en #infosec #appsec #bugbounty #websec #jwt
BREAKING: I asked Claude to upgrade my LinkedIn profile. It didn’t just “upgrade” it. It turned it into a recruiter magnet. Here are the exact 7 prompts I used:
BREAKING: If you're not using Claude at your job, you're already behind. Copy these 7 prompts:
@zomasec @GodfatherOrwa جزاكم الله خيرًا. أنا كنت لخصت أغلب فيديوهات Orwa في صفحة Notion وساعدتني كتير وأنا بتعلم Recon، وحابب أشاركها لعلها تفيد أي حد بيبدأ. بس الرابط مش راضي يتحط في التعليقات على اليوتيوب، فلو حضرتك ممكن تضيفه في تعليق مثبت عندك هتفيد الناس notion.so/sources_Orwa-2…
INSTEAD OF WATCHING NETFLIX TONIGHT, WATCH THIS 1 HOUR FULL CLAUDE COURSE. THANK ME LATER!!!
🧠🔥 CLAUDE “100% MODE” — PRO BUG BOUNTY SYSTEM ⸻ ⚙️ 1. MASTER SYSTEM PROMPT (CORE ENGINE) Paste this FIRST into Claude: You are an elite offensive security researcher operating at a top-tier bug bounty level. You think like a professional attacker but act strictly within authorized security testing. Your mindset: - You hunt broken assumptions, not just vulnerabilities - You prioritize real-world impact over theoretical issues - You think in systems, flows, and trust boundaries - You chain weaknesses into meaningful impact - You ignore noise and focus only on high-probability findings You are not a scanner. You are a strategist. --- CORE MODEL: 1. System Decomposition Break the target into: - APIs, frontend, backend, auth, background jobs, integrations 2. Trust Boundary Mapping Identify where the system assumes: - identity is valid - ownership is enforced - state is consistent 3. High-Value Zones Focus only on: - Access control (IDOR, privilege escalation) - Auth/session flaws - Business logic abuse - SSRF/internal access - Injection in non-obvious contexts - Race conditions 4. Edge Case Thinking - Type confusion - Missing/null values - Encoding tricks - Flow manipulation - Alternate formats 5. Chaining Always ask: → “How does this become critical?” --- EXECUTION: - Explain WHY something may be vulnerable - Provide precise, non-destructive testing strategies - Highlight validation signals - Think like a triager: clear, reproducible, impactful --- OUTPUT: 1. Attack Surface 2. Broken Assumptions 3. Top Vulnerability Hypotheses 4. Testing Strategy 5. Signals 6. Impact 7. Chains --- Stay within ethical, authorized testing only. ⸻ 🔁 2. THE 6-PHASE HUNTER LOOP (REAL SECRET) This is how top hunters think — you’ll run Claude through this loop every target. ⸻ 🔍 PHASE 1 — SYSTEM MAPPING Break this target into components and data flows. Where does user input enter and where is it trusted? ⸻ 🧠 PHASE 2 — ASSUMPTION BREAKING List all assumptions this system makes about: - identity - ownership - state - sequencing Which of these can be broken? ⸻ 🎯 PHASE 3 — HIGH-PROBABILITY BUGS Give ONLY top 5 real vulnerabilities likely to exist. Rank by likelihood and impact. No generic answers. ⸻ ⚔️ PHASE 4 — PRECISION TESTING Design exact step-by-step testing for the #1 vulnerability. Focus on: - edge cases - bypass techniques - validation signals ⸻ 🔗 PHASE 5 — CHAINING If this vulnerability is valid, how can it escalate? Combine with: - access control - logic flaws - race conditions ⸻ 💰 PHASE 6 — REPORT MODE Write a HackerOne-quality report: - Title - Summary - Steps to reproduce - Impact - Severity justification ⸻ 🎯 3. ELITE MICRO-PROMPTS (HIGH ROI) Use these to zoom into specific bug classes: ⸻ 🔐 Access Control Killer Find non-obvious IDOR and privilege escalation paths. Focus on multi-tenant and indirect references. ⸻ 🧾 Business Logic Breaker Break this workflow. Where can steps be skipped, repeated, or abused? ⸻ 🌐 SSRF Hunter Where can the server be forced to make internal requests? Think beyond obvious URL inputs. ⸻ 🔑 Auth & JWT How can identity or roles be confused or escalated? ⸻ ⚡ Race Conditions Where can timing or parallel requests break consistency? ⸻ 💉 Injection (Advanced) Where could injection exist in non-traditional inputs? (JSON, filters, background jobs) ⸻ ⚙️ 4. REAL-WORLD STACK (YOUR FLOW) You already use tools — here’s how Claude fits: Your stack: •gau / waybackurls •httpx •nuclei (optional) •Burp Flow: 1.Collect endpoints 2.Feed into Claude: Analyze attack surface: [paste endpoints] 3.Run 6-phase loop 4.Only test top 1–2 hypotheses 5.Validate manually 6.Generate report ⸻ 💀 WHAT “100% MODE” ACTUALLY MEANS This is the difference: Average Hunter100% Mode Runs toolsBreaks systems Tests payloadsBreaks assumptions Finds low bugsChains into critical Spams reportsWrites 1 winning report
One of my less known-about tools is called hakoriginfinder, but it's really impactful. It finds origin servers behind WAFs using a technique that I haven't seen anywhere else (at least, not at scale). It's a weird one because, unlike my other tools, the messages I get about this tool only come from really top hackers. Check it: github.com/hakluke/hakori…
I published one of the techniques that I've been using against OAuth providers, honetly, it's led me to discover many flaws, and recently I used it to find a 1-click ATO on one of the most widely visited websites,I hope you find it useful :-) blog.voorivex.team/story-of-abusi…
Use this prompt for a thorough JS analysis:
You are an expert JavaScript reverse engineer and code analyst. I will provide you with
a JavaScript file. Perform a structured analysis with the following objectives:
## 1. High-Level Overview
- What is this code's purpose?
- Architecture pattern
- Key dependencies and frameworks used
- Execution flow: how does the code initialize and what is the main entry path?
## 2. Attack Surface & Endpoints
Extract and list ALL of the following in structured tables:
| Category | Examples to look for |
|-----------------------|---------------------------------------------------------|
| API routes/endpoints | paths, HTTP methods, route patterns |
| Parameters | query params, body fields, URL params, headers expected |
| Auth mechanisms | tokens, cookies, session logic, OAuth flows, API keys |
| WebSocket events | event names, channels, message schemas |
| External calls | fetch/axios URLs, third-party APIs, webhook targets |
## 3. Hidden & Interesting Artifacts
Look beneath the surface for:
- Hardcoded strings: URLs, IPs, hostnames, ports, internal service names
- Environment variables referenced (process.env.*)
- Database schemas, table/collection names, field names
- Role names, permission levels, feature flags
- Debug/admin/test routes or commented-out functionality
- Error messages that reveal internal structure
- Regex patterns (what are they validating/extracting?)
- File system paths (uploads, logs, configs, temp dirs)
## 4. Data Flow Map
Trace how user input moves through the code:
- Entry point (where does external data come in?)
- Transformations (parsing, validation, sanitization, or lack thereof)
- Storage (where does it end up: DB, file, cache, external service?)
- Output (what gets returned/rendered to the user?)
## Formatting Rules
- Use tables for structured data (endpoints, params, env vars)
- Use code snippets with line references for each finding
- Flag anything that seems intentionally obscured or unusual
- If the code is minified/obfuscated, note patterns and attempt to
identify the original framework or library
---
Here is the code:
Spent a week testing AI for vulnerability research. 14 confirmed bugs in 20 min on one target. 5% hit rate on a hardened one. Same AI, same setup. 4 approaches, what worked, what failed, why target selection matters more than model sophistication. xclow3n.github.io/post/7
Hello Folks, I have just published a Writeup on: How I hacked AI Agent and worth bounty of $$$$ medium.com/@manan_sanghvi… @Bugcrowd #hackingonsteroids #llmsecurity #aisecurity #promptinjection #bugbounty #bugcrowd #aiagent #agenticai #agent #cybersecurity #ai #medium #writeup
Added 3,600+ publicly disclosed HackerOne reports that paid a bounty to the MCP. 👇 github.com/PatrikFehrenba… This should help Claude to decide where to focus on, what attack surface was looked at before, and where new vulnerabilities could be 👀 (in theory 😏)
Rajendra nath Behera @Rajendranath_AI
33 Followers 1K Following
Stuetha @StuethaIXWIKyT
66 Followers 3K Following
Chefea @ChefeauCGRnDh
82 Followers 3K Following
law_sm @lawsm189760
60 Followers 2K Following
Hither mann @Hitherman15
209 Followers 3K Following Venture Capitalist | Property | Business | Financial Markets I Founder of The Billionaire Project & Fortune Academy
Md Torikul Islam🇧�... @torik_1999
217 Followers 1K Following
hacker one @hackerone434535
19 Followers 333 Following
AR groups @ARgroups11
17 Followers 380 Following A cybersecurity engineer @kern . / Bug Hunter, Freelancer, Product Security Engineer...
Sadeq Alshaikh @Sadeq_AlShaikh
6 Followers 410 Following
sovatey @sovatey11
9 Followers 51 Following
Smoo max @SmooMax26084
5 Followers 377 Following
Nithin Raj @Nithin_Raj64
5 Followers 156 Following
Yhia Ahmed @yhiaahmed8
137 Followers 2K Following 🐍 Python Developer | Browser Automation & Web Scraping - Selenium • Playwright • DrissionPage | Bug Bounty Hunting
praveen challa @praveencha75984
7 Followers 226 Following
marwan @marwan_9889
0 Followers 2K Following
diyar @diyar_mhammed
724 Followers 3K Following
Lawyer Cyberry @yogywizo
96 Followers 442 Following cyber security researchers | pentester | bug hunter | back end developer | cyber Forensic investigator | DevOps | ReadTeam | . . . . . . . . . . . . . . . . . .
Dhawal Suthar @DhawalSuthar101
11 Followers 460 Following
Quan the third III @big_Rbs
173 Followers 1K Following Infosec / security researcher 🔬 undiscovered talent Striving to Learn more and Earn more. #BugbountyHunter #Cultivator🌱#Systemanalyst Mentors welcome.
bd boy @zz__344dd
51 Followers 2K Following
Hibban Cilacap - #MWI... @zahidclp95
58 Followers 2K Following Hi,I am a Freelance Web Pentester self-taught since 2013. In the future I plan to take Certified CEH,, Bismillah Someone lahir 2004 , Religius, Akhwat Mode
Mehdi Moughtanim @MMoughtani80228
1 Followers 60 Following
iamlegit92 @iamlegit92
392 Followers 2K Following Christian | Cyber Security enthusiast | OSINT | Software Engineer | Web App Development - Full Stack | Java | Flutter | Angular | Python | Teacher 🇬🇭
Basel @BaSelhoosSam
52 Followers 686 Following
Haykeens @genesisandet
10 Followers 97 Following full stack web developer||Robotics/Autonomous system developer|| Software Engineering enthusiastic||mobile app dev
NeasherSec @neashersec
64 Followers 817 Following strong background in Computer Science & Engineering, I specialize in full-stack JavaScript development, web security, malware removal and more
aya3t @aayyaa3t
1 Followers 106 Following
Ahmed Badry @NomadSec0
2K Followers 1K Following offensive cyber security engineer eWPTXv3 & eMAPT & MCSA Geek 👽👽👽 Hall of Fame AT&T IBM Sony Honda Ford Vodafone DOD British Airways Stanford
Dikshant @Bboydikshant14
621 Followers 4K Following some people do it & some people really really do it.....!
... @zcxzxse
81 Followers 2K Following
Anirban das @anirbandas_09
47 Followers 2K Following
trace37 @trace37_labs
1K Followers 323 Following Hacker - Security Researcher - Bug Bounty Hunter - Security Tooling Developer
Arcanum Information S... @arcanuminfosec
5K Followers 16 Following Expert Cybersecurity Training and Consulting by @jhaddix
the_IDORminator @the_IDORminator
9K Followers 0 Following #1 USA Hacker on Bugcrowd - Top 10 Globally Take the Course & Learn to Earn by Hacking! Course URL: https://t.co/CF9jbWwPAa
OSINTdefender @sentdefender
2.4M Followers 2K Following Open Source Intelligence Monitor focused on Europe and Conflicts across the World. RT ≠ Endorsement. Want to Support my Work? https://t.co/PcUbewwuEZ
Coffin @lostsec_
30K Followers 216 Following ʜᴇʟᴘɪɴɢ ᴏʀɢᴀɴɪᴢᴀᴛɪᴏɴꜱ ꜱᴛᴀʏ ꜱᴇᴄᴜʀᴇ ᴛʜʀᴏᴜɢʜ ʙᴜɢ ʜᴜɴᴛɪɴɢ, ᴏꜱɪɴᴛ ᴀɴᴅ ꜱᴇᴄᴜʀɪᴛʏ ʀᴇꜱᴇᴀʀᴄʜ | ᴡʀɪᴛᴇᴜᴘꜱ: https://t.co/39DXITYobD | ᴄᴏᴍᴍᴜɴɪᴛʏ: https://t.co/otIBnWOeua
Tehran Times @TehranTimes79
323K Followers 8 Following Iran's Leading International Daily Newspaper. Telegram channel: https://t.co/NPENjt0hxw
Middle East Observer @ME_Observer_
379K Followers 2K Following 🇱🇧 Galilean Middle East Analysis/History/Politics/Memes reporting Subtitling Videos for you Support the subtitling project here: https://t.co/7UPdbUoegq
The Pakistan Experien... @ThePakistanExp1
29K Followers 239 Following The Pakistan Experience is a podcast that believes in conversations. Let's talk! https://t.co/gawFlGBcmb
@rohithshrm @0dayex
3 Followers 137 Following
xss0r @xss0r
7K Followers 3K Following xss0r Deploying an alert box in a web app is like having a tiny pop-up comedian shout 'Surprise!' whenever you least expect it! #xss0r #ibrahimXSS #Blindxss0r
Dark Web Intelligence @DailyDarkWeb
195K Followers 0 Following We work in the dark to bring clarity to the light.
Mohamed Anani @0xM5awy
2K Followers 945 Following Someone who will be one of the best Egyptians in this field
offensivecon @offensive_con
28K Followers 1 Following OffensiveCon is a technical international security conference focused on offensive security only. Organised by @Binary_Gecko. Stay tuned #Offensivecon #Tokyo.
Boris Larin @oct0xor
19K Followers 709 Following Former console hacker (PS3/PS4). Hunting in the wild 0-days at Kaspersky GReAT. All tweets are my own.
CertusCybersecurity @CertusCyber
205 Followers 12 Following Certus Cybersecurity provides industry-leading information security services to Fortune 100 enterprises and innovative, high-growth businesses worldwide.
🇸🇦 Murtada Bin ... @0x_rood
29K Followers 340 Following Digital Nomad Lifestyle 💎 | Not doing collabs, not selling courses
BurpSuite.guide @BurpSuiteGuide
3K Followers 22 Following Your guide to all things Burp Suite! Subscribe to my newsletter: https://t.co/Nxtewg5M1x
noraj @noraj_rawsec
3K Followers 390 Following 🇫🇷 Penetration test engineer. 🐧 #BlackArch Linux maintainer. 🔣 (Unicode) security researcher.
x1337loser @x1337loser
4K Followers 47 Following A 24-year-old Hacker, Gamer, Eater, Trainer, programmer(python, go, bash) Hungry learner, Noob at bug bounty😪😪
/ XNL -н4cĸ3r (and ... @xnl_h4ck3r
10K Followers 992 Following Aspiring Bug Bounty Hunter & dev of tools: GAP, xnLinkFinder, waymore, urless, XnlReveal, knoxnl, xnldorker 🤘 RTFM🧐... always... PLEASE!
Clint Gibler @clintgibler
26K Followers 574 Following 🛡️ Leading Cyber at @OpenAI 📚 Creator of https://t.co/xwtIAI0CuJ newsletter
Netsec Explained @GTKlondike
1K Followers 495 Following I'm a senior security consultant who makes videos to level up my team on AI, pentesting, and bug bounty. Check out my channel on YouTube.
@ddǝɐuɐp @DanaEpp
4K Followers 222 Following I help builders and breakers of code learn to find security vulnerabilities in their apps and APIs.
Sergio Pereira @SergioRocks
46K Followers 1K Following CTO building tech products, startup teams & writing about it. I work as a Fractional CTO for tech startups. DMs open
bogo @xb0g0
3K Followers 537 Following Lead Security Researcher @CertoraInc | @ArtOfAuditing | Prev - #14 @cantinaxyz All-time Leaderboard & Multiple TOP1/TOP5/TOP10 finishes
m0uka_Dz 🇩🇿 @m0uka_Dz
4K Followers 693 Following JUST A KID PLAYING IN NETWORK, CHASING R-W IMPACT | Expert Red Teaming At Algerie Telecom
Peter M @pmnh_
3K Followers 560 Following aka pmnh / ex-Security researcher / Synack #1 SRT 2022-2023 / Synack, HackerOne, BC / Deep recon / source code analysis. Opinions my own, not employer.
r0bre | Accretion.xyz @r0bre
6K Followers 1K Following solana security officer | ceo & chief solana auditor @accretion_xyz | @hackhackai | dm for audits
Jayesh Madnani @Jayesh25
14K Followers 506 Following Researcher in charge @ Ethical InfoSec Services | HackerOne Top 10 | https://t.co/JSX03Wv1vl
Nikhil Mittal @nikhil_mitt
20K Followers 439 Following Hacker, Infosec Researcher, Military Affairs & History, PowerShell, AD and Azure pwner, Creator of Nishang and others :) Founder @alteredsecurity
Prateek Tiwari @prateek_0490
9K Followers 347 Following abnormally normal!!! Views, posts, and opinions shared are my own.
Cory House @housecor
161K Followers 816 Following I help dev teams be insanely productive with AI. Courses: https://t.co/D5emROQHUh & https://t.co/6L1fD89GbP Consulting: https://t.co/Qfp4TfpB8N ⚛️
Bloqarl | Zealynx @TheBlockChainer
5K Followers 1K Following Founder of @ZealynxSecurity. 10 years QA → 4+ years Smart Contract Security. Building an audit firm in public. Building https://t.co/OfrgnFHscJ for Web3 builders
InventiveRepair @InventiveRepair
108 Followers 69 Following Pentesting & Ethical Hacking with a Minor in Web Design.



















































