What an insight! @NahamSec
"When I can't find bugs, I change perspective not targets.
Client-side -> API Issues
Main App -> Developer Platform"
"Give Me 13 Minutes and 2025 Will Be Your Best Bug Bounty Year"
YouTube Link: youtube.com/watch?v=PER6Nv…
Alhamdulillah!
Awarded with $600 for finding an IDOR vulnerability!
Context:
- The Web App was letting users to upload payment screenshots if they chose 'Bank Transfer' method for boosting their posts.
- But abusing the IDOR vulnerability, I could upload/replace victims' images.
Alhamdulillah...!
Rewarded with $480 for a Race Condition attack...!
Double Tips for Hunters:
1. Always test #race_condition if a function offers rewards e.g., coin, money, etc.
2. Don't hesitate to negotiate logically with programs.
#bugbounty#whitehat#race#condition#tips
Alhamdulillah...!
Rewarded with $500 for a Stored XSS for Bypassing the Validation...
Tips for You:
Never trust the first page security!
My malicious name was validated when I commented for the first time.
But when I REPLIED to MY comment then it fired.
#bugbounty#xss#tips
Alhamdulillah...!
Awarded with $750 for an IDOR issue...!
Tip: Change the target website's country/language to a different one. Because sometimes it may offer an additional feature for another region.
Example: rashedulcss.com/?lan=en ➡️ rashedulcss.com/?lan=ar#bugbounty#tips
Alhamdulillah...!
@TecnoSRC (TECNO Mobile) featured me in their anniversary as a "#Security_Researcher with the Most Badges" for my contributions to their overall Android Applications and Websites security.
Alhamdulillah...
Rewarded with $7K (6K+1K) for being #TOP_2 in the yearly leaderboard (globally) of TECNO Security Response Center with the special recognition #Precious_Gem.
"...And Allah provides for whoever He wills without limit." [Al Quran - Sura 24:38]
#bugbounty#security
Now #VIP Hacker of @TecnoSRC (TECNO Mobile Brand)...!
Just received the badge today...
It requires 4 high/6 medium valid vulnerability reports...
Dive deep matters...!
#bug#bounty#ethical#hacking
450 Followers 2K FollowingVideo gamer, Self Certified hacker, Pentester,Just call me Vector.
I am Legion.
This account belongs to a god⚡.
In Christ alone
236 Followers 563 FollowingBug Bounty Hunter | Web App Hacker | Red Team Specialist | Finding vulnerabilities, exploiting weaknesses, and securing the web one app at a time. ▂▃▄▅▆▇█
1K Followers 1K FollowingBug Bounty Amateur, Ambitious to be Information Security Developer. Aspirant to improve IT & CySec. https://t.co/aJptMzdum2 https://t.co/0hE2tMp1nx
345 Followers 2K FollowingWe are a #ciso marketplace selling information security services, digital products, and various IT swag items. #IoT #infosec #cybersecurity vCISO and Compliance
367K Followers 286 Following🐳 Whale: Most popular games, leaderboards, and more.🎰🎉
🥇 Wheel of Whales: Collect tokens via P2E game
🚫 Please play responsibly. 18+ only. T&C Apply.
42K Followers 286 FollowingYapping about AI, AppSec, Hacking, & Cybersecurity • Helped secure organizations like Google • Opinions are my cat's • Part-time shitposter
3K Followers 0 FollowingSecuring the mobile world 🌐
We know how to protect your Android & iOS apps with our robust vulnerability-scanning solutions
#MobileAppSecurity #Cybersecurity
57K Followers 874 FollowingBuilding communities one event at a time. Thirteen years, over eight hundred events, and we're just getting started.
@[email protected]
4K Followers 3K FollowingAlibaba Security Response Center (ASRC), Point of Contact of all the Alibaba related vulnerabilities, cooperations, and so on.
12K Followers 17 Following👨💻 Penetration testing
🧑💼 Cybersecurity consulting
🎓Appsec training
🌏 Born in Australia, serving customers globally
Founded by @hakluke
7K Followers 140 FollowingWe create content and manage socials for your cybersecurity organization. 🚀
Sound good? 👉 https://t.co/H8NucTI4zJ
Founded by @hakluke