Rohan_lew Profile Banner
Rohan_lew Profile
Rohan_lew

@Rohan_Lew

3,716
Followers
285
Following
121
Media
797
Statuses

Genius by birth Hacker by choice ๐Ÿง‘โ€๐Ÿ’ป

Pune, India
Joined July 2020
Don't wanna be here? Send us removal request.
Pinned Tweet
@Rohan_Lew
Rohan_lew
1 year
I'm making a full of my methodology video , The actual method that i use to find privilege escalation vulnerabilities easily ๐Ÿ˜‰ i have reported multiple privilege issues in hackerone using this method. I will post the videos in *Monday* keep on eye ๐Ÿ‘โ€๐Ÿ—จ #bugbounty #infosec
Tweet media one
Tweet media two
Tweet media three
Tweet media four
28
76
651
@Rohan_Lew
Rohan_lew
2 years
Quick tips : How i found 10+ information disclosure in hackerone public program 1/n 1st: collect all ip's from shodan shodan search :"*" 200 --fields ip_str | httpx | tee ips.txt 2nd: fuzz all ips using dirsearch
43
266
604
@Rohan_Lew
Rohan_lew
2 years
Bug type: 403 Bypass Bounty: $600 Quick tips: ๐Ÿ’ป site[.]com/env => 403 Forbidden site[.]com/env/HTTPS2 => Bypassed #bugbountytips #bugbountytips #hacking #cybersecuritytips
Tweet media one
26
109
573
@Rohan_Lew
Rohan_lew
3 years
Information disclosure is โค๏ธ tip: If you found any sensetive url, or config. js, which is giving 404. use waybackurls => echo "sensetive link" | waybackurls - get-versions, And it will give you old version of that file. Thanks @TomNomNom #infosec #bugbountytips @Hacker0x01
Tweet media one
29
149
387
@Rohan_Lew
Rohan_lew
2 years
Found a Method by which I Got Some Database Credentials leaks Recently "Quick Tips" Or "writeups" #bugbounty #cybersecurity #Hackingtime
Tweet media one
Tweet media two
Tweet media three
27
43
269
@Rohan_Lew
Rohan_lew
1 year
Sorry for the delayed๐Ÿ˜… Now you can access all the videos by filling this google form : You will get a proper guide for finding privilege escalation and hopefully able to report privilege this month $$$๐Ÿ’ฐ๐Ÿ˜‰ #bugbounty #cybersecurity #bugbountytips
@Rohan_Lew
Rohan_lew
1 year
I'm making a full of my methodology video , The actual method that i use to find privilege escalation vulnerabilities easily ๐Ÿ˜‰ i have reported multiple privilege issues in hackerone using this method. I will post the videos in *Monday* keep on eye ๐Ÿ‘โ€๐Ÿ—จ #bugbounty #infosec
Tweet media one
Tweet media two
Tweet media three
Tweet media four
28
76
651
5
46
245
@Rohan_Lew
Rohan_lew
2 years
Found 10+ information disclosure on @Hacker0x01 Expecting 4k+ USD #bugbounty #cybersecurity #Hackingtime
Tweet media one
17
4
236
@Rohan_Lew
Rohan_lew
2 years
I was rewarded 350$ bounty! #bugbounty #cybersecurity #hacking
Tweet media one
18
0
190
@Rohan_Lew
Rohan_lew
2 years
I Was Awarded a $3750 Bounty for Multiple Vulnerabilities. 2 => Sql Injection ๐Ÿ’‰ 3 =>Reflected Xss 2 => Information Disclosure #bugbounty #infosec #cybersecurity
Tweet media one
14
8
187
@Rohan_Lew
Rohan_lew
1 year
Late post ๐Ÿค’ Bug: Privilege Escalation Bounty: 1200$ #bugbounty #CyberSecurity #infosec
Tweet media one
8
6
159
@Rohan_Lew
Rohan_lew
2 years
Reward: $820 Bug name: Information Disclosures #bugbounty #hacking #cybersecurity
Tweet media one
6
0
141
@Rohan_Lew
Rohan_lew
3 years
Tweet media one
12
2
134
@Rohan_Lew
Rohan_lew
2 years
Recon Always Wins ๐Ÿ”ฅ๐Ÿ’ป Reward : $1,000 #bugbounty #hackerone #cybersecurity
Tweet media one
7
3
136
@Rohan_Lew
Rohan_lew
1 year
Yay, I was awarded a $550 bounty on @Hacker0x01 ! #TogetherWeHitHarder #bugbounty #cybersecurity Bug: 3 IDORS Focusing on functionalities testing instead of recon
Tweet media one
Tweet media two
Tweet media three
6
6
134
@Rohan_Lew
Rohan_lew
1 year
ThanXx bug bounty ๐Ÿ’ป๐Ÿ”ฅ #bugbounty #cybersecurity
Tweet media one
4
1
132
@Rohan_Lew
Rohan_lew
3 years
Found 5 Open Redirection ๐Ÿ˜‰ => payload: /////evil.com/ => Target(.) com/////evil.com/ #bugbountytips #infosec #cybersecurity #bugbounty
3
35
130
@Rohan_Lew
Rohan_lew
1 year
"My presonal method to find privilege escalation" video is public now๐Ÿ‘‡ Link: Also like or subscribe ๐Ÿ›‘if u like it i will add more videos in my YouTube ๐Ÿ˜‰ #bugbountytips #cybersecurity #hacking #infosec
0
25
149
@Rohan_Lew
Rohan_lew
2 years
Information Disclosure is Love โค๏ธ #bugbounty #cybersecurity #hacking
Tweet media one
7
8
111
@Rohan_Lew
Rohan_lew
3 years
Rewarded 150โ‚ฌ Bug type: Reflected Xss ๐Ÿง‘โ€๐Ÿ’ป #bugbounty #infosec #cybersecurity
Tweet media one
4
3
104
@Rohan_Lew
Rohan_lew
3 years
Rewarded 300$ bug: Session Takeover #infosec #cybersecurity #bugbounty
Tweet media one
7
7
88
@Rohan_Lew
Rohan_lew
3 years
Again 100โ‚ฌ tips: keep recon hard ๐Ÿ’ฅ #bugbounty #infosec #cybersecurity #bugbountytips
Tweet media one
2
10
82
@Rohan_Lew
Rohan_lew
3 years
Tweet media one
6
2
82
@Rohan_Lew
Rohan_lew
1 year
Working on a video of my methodology like how i look for privilege escalation vulnerabilities will post in 4-5 days #bugbountytips #bugbounty #hackinglife #cybersecurity
7
5
84
@Rohan_Lew
Rohan_lew
1 year
Tweet media one
3
0
75
@Rohan_Lew
Rohan_lew
2 years
Reward: $100 Bug: Information disclosure #hackerOne #bugbounty #hacker #CyberSecurity
Tweet media one
6
0
77
@Rohan_Lew
Rohan_lew
2 years
Again โ‚ฌ100 Bug: Information Disclosure #BugBounty #hackinglife
Tweet media one
6
0
75
@Rohan_Lew
Rohan_lew
2 years
Bounty: โ‚ฌ200 Bug: Information disclosure #bugbounty #cybersecurity #hacking
Tweet media one
5
1
70
@Rohan_Lew
Rohan_lew
2 years
Reward: 100โ‚ฌ #BugBounty #cybersecurity
Tweet media one
3
1
61
@Rohan_Lew
Rohan_lew
1 year
Yay, I was awarded a $250 bounty on @Hacker0x01 ! #TogetherWeHitHarder
Tweet media one
3
0
61
@Rohan_Lew
Rohan_lew
1 year
Yay, I was awarded a $xxxx bounty on @Hacker0x01 ! #TogetherWeHitHarder #BugBounty Recon like a boss ๐Ÿ”ฅ
Tweet media one
9
0
59
@Rohan_Lew
Rohan_lew
2 years
Bug type :- Critical information disclosure #bugbounty #cybersecurity #hackinglife
Tweet media one
6
2
57
@Rohan_Lew
Rohan_lew
1 year
Tweet media one
1
0
56
@Rohan_Lew
Rohan_lew
1 year
Happy birthday @GodfatherOrwa ๐ŸŽ‰๐ŸŽ‰
Tweet media one
1
0
55
@Rohan_Lew
Rohan_lew
2 years
2/n 3rd: Found .htaccess folder Accessable which contains target internal ip's 4th : cat all_ip's.txt | httpx | tee live_ip's.txt i use my own custom nuclei templates cat live_ips.txt | nuclei -t ~/custom_templates #bugbountytips #bugbounty #cybersecurity
3
5
45
@Rohan_Lew
Rohan_lew
1 year
Tweet media one
4
0
46
@Rohan_Lew
Rohan_lew
2 years
I was rewarded 500$ For Sensetive Information Disclosure Quick tips: - Always try this => https://target[.]com/target[.],. sql.tar.z and so on... #bugbounty #cybersecurity #hacking
Tweet media one
3
14
46
@Rohan_Lew
Rohan_lew
1 year
Bounty: $50 amazon gift Bug: Privilege escalation allows user to change billing details. #bugbounty #cybersecurity #hacking
Tweet media one
0
3
45
@Rohan_Lew
Rohan_lew
1 year
Tweet media one
4
0
44
@Rohan_Lew
Rohan_lew
2 years
I will post more about how to find information disclosure bugs ๐Ÿ˜‰
5
1
40
@Rohan_Lew
Rohan_lew
2 years
Hello @cex_io team i reported a security issue on your website in 03-07-2022 and your security team rewarded me 200$ in 06-10-2022 but from one year i ask for payment and your team is saying no updates everytime look into it. @cex_io
Tweet media one
7
3
39
@Rohan_Lew
Rohan_lew
2 years
BACK IN THE GAME ๐Ÿ’ป Reward:100โ‚ฌ #bugbounty #cybersecurity #hackinglife
Tweet media one
6
0
38
@Rohan_Lew
Rohan_lew
2 years
Bug type :- Security Misconfiguration #bugbounty #cybersecurity #Hackingtime
Tweet media one
1
0
37
@Rohan_Lew
Rohan_lew
10 months
After many days "Back to the hunt"๐Ÿ’ป #bugbounty #cybersecurity
Tweet media one
2
2
40
@Rohan_Lew
Rohan_lew
1 year
Keep going bro๐Ÿ”ฅ๐Ÿ”ฅ #bugbounty #cybersecurity
@adil_rehan20
adilrehan
1 year
Bug :- privilege escalation Thanks for your Guidance @Rohan_Lew My first bounty $$$๐Ÿค‘๐Ÿค‘ #bugbounty #cybersecurity #Hacking
Tweet media one
5
4
56
2
2
34
@Rohan_Lew
Rohan_lew
3 years
big day โค๏ธ ThanXx for always supporting me ๐Ÿ˜Š @ADITYASHENDE17
Tweet media one
2
0
32
@Rohan_Lew
Rohan_lew
2 years
I was rewarded โ‚ฌ200 Bug: Privilege escalation #bugbounty #Hackers #cybersecurity
Tweet media one
1
0
32
@Rohan_Lew
Rohan_lew
1 year
Reported 10+ idors in the past few days in #HackerOne ๐Ÿ’ป So, what should i do? #BugBounty
Writeups
205
Quick tips
63
8
3
29
@Rohan_Lew
Rohan_lew
3 years
got my first bounty today ๐Ÿ˜Š thanXx to these friends who always reply when u needed.. @RogueSMG @_Base_64 @R29k_ @alan_abhilash @KabirSuda @ADITYASHENDE17 #bugbountytips #infosec #bugbounty
Tweet media one
8
5
28
@Rohan_Lew
Rohan_lew
2 years
Reward 100$ Bug: Information disclosure #bugbounty #Hackerone #cybersecurity
Tweet media one
1
0
27
@Rohan_Lew
Rohan_lew
4 years
my first hall of fame ๐Ÿ˜Š thank you @ADITYASHENDE17 sir
Tweet media one
2
0
27
@Rohan_Lew
Rohan_lew
3 years
Tweet media one
Tweet media two
3
1
27
@Rohan_Lew
Rohan_lew
2 years
Bug: Sensetive information disclosure Bounty in INR โ‚น #cybersecurity #bugbounty #hacking
Tweet media one
3
3
25
@Rohan_Lew
Rohan_lew
2 years
Diwali Bounty ๐Ÿช” Bug: Reflected Xss #bugbounty #hacker #cybersecurity
Tweet media one
0
1
23
@Rohan_Lew
Rohan_lew
2 years
I Bought Omnitrix Today ๐Ÿ˜ Comment your Fav Alien Name #Ben10
Tweet media one
10
1
21
@Rohan_Lew
Rohan_lew
2 years
Tweet media one
0
3
23
@Rohan_Lew
Rohan_lew
1 year
๐Ÿ”ฅ๐Ÿ”ฅ๐Ÿ”ฅ
@sarfarazmoin1
sarfaraz moin
1 year
Thanks for your guidance @Rohan_Lew
Tweet media one
6
2
25
2
0
21
@Rohan_Lew
Rohan_lew
1 year
How to you test web app when web app doesn't allow you to run burpsuite in the background . #bugbounty #infosec #cybersecurity #bugbountyhelp
9
0
21
@Rohan_Lew
Rohan_lew
1 year
Tweet media one
4
1
18
@Rohan_Lew
Rohan_lew
1 year
๐Ÿ”ฅ๐Ÿ”ฅ
@adil_rehan20
adilrehan
1 year
Thanks for your guidance @Rohan_Lew Bounty ๐Ÿค‘๐Ÿค‘๐Ÿค‘
Tweet media one
3
0
39
0
0
18
@Rohan_Lew
Rohan_lew
3 years
After Getting continuously Dups Never give up...๐Ÿ”ฅ๐Ÿ’ป tip ; put Xsshunter payload in burpusuite match and replace section..! 1. User agent 2. Referer Header #bugbountytips #bugbounty
Tweet media one
3
8
18
@Rohan_Lew
Rohan_lew
3 years
Again got 300โ‚ฌ bug type: Buisness logic #bugbounty #infosec #cybersecurity
Tweet media one
0
3
15
@Rohan_Lew
Rohan_lew
10 months
Tweet media one
0
1
17
@Rohan_Lew
Rohan_lew
2 years
Hack_the_world โค๏ธ
2
0
13
@Rohan_Lew
Rohan_lew
1 year
Keep going bro ๐Ÿ”ฅ๐Ÿ”ฅ๐Ÿ”ฅ
@atif2816
Atif Alam ๐Ÿ‡ฎ๐Ÿ‡ณ
1 year
Bug :- Privilege escalation @Rohan_Lew thanks for tips bro ๐Ÿ˜Ž๐Ÿ”ฅ #BugBounty #bug #hacker #Hacking #hackthebox #hackerone #bugbountytips
Tweet media one
6
11
153
3
0
14
@Rohan_Lew
Rohan_lew
2 years
Should I write Detailed writeups on Information disclosure bugs or post Quick tips.
Quick tips
13
Detailed Writeups
31
2
0
14
@Rohan_Lew
Rohan_lew
2 years
Congratulations bro๐Ÿฅณ๐Ÿฅณ
@atif2816
Atif Alam ๐Ÿ‡ฎ๐Ÿ‡ณ
2 years
@Rohan_Lew thanks for always guiding me โค๏ธ Again 100 dollar ๐Ÿ”ฅ๐Ÿ˜Ž #bugbountytips #BugBounty #Hackers #HackersNews #bugs
Tweet media one
2
0
6
0
0
14
@Rohan_Lew
Rohan_lew
1 year
Keep going bro ๐Ÿ”ฅ๐Ÿ”ฅ
@Vivekkk_a
Vivek Kumar Digar
1 year
First bounty ๐Ÿ’ฐ @Rohan_Lew thanks for guiding and support โค #bugbountytips #bugbounty #hackerone #bug #hacker
Tweet media one
4
0
37
0
0
13
@Rohan_Lew
Rohan_lew
1 year
I Have also created a what's up group for those who are enrolled the methodology and teaching "How do i find targets" Some "information disclosure tips" #bugbounty #cybersecurity #hacking
@Rohan_Lew
Rohan_lew
1 year
Sorry for the delayed๐Ÿ˜… Now you can access all the videos by filling this google form : You will get a proper guide for finding privilege escalation and hopefully able to report privilege this month $$$๐Ÿ’ฐ๐Ÿ˜‰ #bugbounty #cybersecurity #bugbountytips
5
46
245
0
0
11
@Rohan_Lew
Rohan_lew
1 year
Congratulations man ๐ŸŽ‰๐ŸŽ‰
@adil_rehan20
adilrehan
1 year
One more bounty in the list ๐Ÿค‘๐Ÿค‘๐Ÿค‘๐Ÿค‘ Thanks @Rohan_Lew for the guidance & support โค๏ธ
Tweet media one
9
0
34
1
0
13
@Rohan_Lew
Rohan_lew
2 years
Hey @CoinomiWallet @CoinomiSupport it's been over 2 months and you fixed my reported bug but you haven't reply to my mail Are you gonna reply or not?? #bugbounty #hacking
Tweet media one
3
0
11
@Rohan_Lew
Rohan_lew
3 years
Tweet media one
3
0
8
@Rohan_Lew
Rohan_lew
10 months
Congratulations bro ๐ŸŽ‰ ๐ŸŽ‰ #bugbounty #infosec #cybersecurity
@Vivekkk_a
Vivek Kumar Digar
10 months
Tweet media one
1
0
15
2
0
11
@Rohan_Lew
Rohan_lew
1 year
Keep it up bro ๐Ÿ˜‰
@ansariaj283
Md Arbaj
1 year
First triaged on @Bugcrowd Thanks to @Rohan_Lew for your support and guidance.. #bugbounty #CyberSecurity #bugcrowd
Tweet media one
2
0
13
1
0
9
@Rohan_Lew
Rohan_lew
3 years
Bug type: Buisness Logic #infosec #bugbounty
Tweet media one
0
2
7
@Rohan_Lew
Rohan_lew
3 years
Tweet media one
0
2
6
@Rohan_Lew
Rohan_lew
1 year
Tweet media one
2
0
8
@Rohan_Lew
Rohan_lew
2 years
@_2os5 'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z
1
1
7
@Rohan_Lew
Rohan_lew
3 years
Making a wordlist for your target.. 1. 'Cewl' > cewl - m 4 - w /wordlist1. txt - d target. com 2.urls > cat urls.txt | cut -d โ€œ/โ€ -f4,5,6,7,8,9 | tee wordlist2. txt 3.github endpoints () github-endpoints target. com - raw - o /wordlist3. txt #bugbountytips
0
1
7
@Rohan_Lew
Rohan_lew
2 years
@JerrySh43332033 i'm jst changed the method GET to TRACE then it will automatically append HTTPS2
2
0
6
@Rohan_Lew
Rohan_lew
3 years
Thanks to our #infosec community and the amazing hackers for sharing there knowledge or writeups @sillydadddy @Alra3ees
@hakluke
Luke Stephens (hakluke)
3 years
I just hit 30k followers ๐Ÿ˜Š To celebrate giving away 30 @PentesterLab subscriptions. To enter, quote tweet this with a message of gratitude to someone that has helped you become a better hacker/human. Thanks to @PentesterLab / @snyff who provided 50% of the subs. โค๏ธ๐Ÿงก๐Ÿ’›๐Ÿ’œ๐Ÿ’š
93
78
488
1
1
4
@Rohan_Lew
Rohan_lew
3 years
In January, I submitted 9 vulnerabilities to 6 programs on @Hacker0x01 . 7 Vulnerabilities in to 3 programs in @bugcrowd All are Trigged ๐Ÿ˜Š 7 get dups 2 Rewarded ๐Ÿ˜… in @Hacker0x01 #togetherwehitharder
0
0
5
@Rohan_Lew
Rohan_lew
1 year
Happy to see ๐Ÿ˜„ #bugbounty
Tweet media one
@Rohan_Lew
Rohan_lew
1 year
Sorry for the delayed๐Ÿ˜… Now you can access all the videos by filling this google form : You will get a proper guide for finding privilege escalation and hopefully able to report privilege this month $$$๐Ÿ’ฐ๐Ÿ˜‰ #bugbounty #cybersecurity #bugbountytips
5
46
245
0
1
6
@Rohan_Lew
Rohan_lew
1 year
Sure bro ..
2
1
6
@Rohan_Lew
Rohan_lew
1 year
@ashu_barot @pdnuclei Have hear about the udemy? If yes then go to the udemy and watch how people taking more money to teach how to find subdomains using subfinder and how to fillter subdomains using httpx tool and then come and comment
3
0
6
@Rohan_Lew
Rohan_lew
2 years
Iโ€™m happy to share that iโ€™m starting a new position as a Security Analyst at @Net_Square_ #cybersecurity #hacking
Tweet media one
1
0
6
@Rohan_Lew
Rohan_lew
2 years
Congratulations bro ๐Ÿฅณ
@atif2816
Atif Alam ๐Ÿ‡ฎ๐Ÿ‡ณ
2 years
@Rohan_Lew thanks for always guiding me ๐Ÿ˜Ž๐Ÿ”ฅ Happy Holi โค๏ธ #BugBounty #bugbountytips #Hacking
Tweet media one
0
0
4
0
0
6
@Rohan_Lew
Rohan_lew
2 years
@kingcoolvikas ok will share some tips tomorrow
2
0
5
@Rohan_Lew
Rohan_lew
1 year
@Mdhsan19 It's suspense bro
0
0
6
@Rohan_Lew
Rohan_lew
3 years
0
1
4
@Rohan_Lew
Rohan_lew
1 year
What is your fav cartoon name mine is Ben 10 โŒš๏ธ
2
0
5