0xHun73r ๐Ÿ‡ต๐Ÿ‡ธ (@0xhun73r) 's Twitter Profile
0xHun73r ๐Ÿ‡ต๐Ÿ‡ธ

@0xhun73r

A Bug Bounty Security Researcher

ID: 1880591194490888193

linkhttps://despconton.lol/0xHun73r calendar_today18-01-2025 12:21:12

80 Tweet

153 Takipรงi

143 Takip Edilen

0xHun73r ๐Ÿ‡ต๐Ÿ‡ธ (@0xhun73r) 's Twitter Profile Photo

Day 2 โ€“ Bug Bounty Challenge - Still dealing with the flu & fever but got 5h hunting + 1h10m reading writeups on mainly focused on logic bugs. - Spent a lot of time understanding the target and test all the main features manually. - No finds, see you tomorrow. Total earned: $0

0xHun73r ๐Ÿ‡ต๐Ÿ‡ธ (@0xhun73r) 's Twitter Profile Photo

Day 3 โ€“ Bug Bounty Challenge - Started the challenge late today. Spent 3 hours hunting and 1 hour reading CaptinSHArky(Mahdi๐Ÿ‡น๐Ÿ‡ณ) writeups lots of helpful insights there. - Found 2 interesting issues but didnโ€™t get the time to dig deeper. - Will continue tomorrow. Total earned: $0

0xHun73r ๐Ÿ‡ต๐Ÿ‡ธ (@0xhun73r) 's Twitter Profile Photo

Alhamdulillah, just discovered a new bug! -Tip: When hunting Open Redirects, try inserting //evil.com/..;/css in the URL The server treats it as a local path but the browser redirects outside Add a .js or .css file at the end. #CyberSecurity #Hacker101 #bugbountytips #BugBounty

Alhamdulillah, just discovered a new bug!

-Tip:
When hunting Open Redirects, try inserting
//evil.com/..;/css in the URL
The server treats it as a local path but the browser redirects outside
Add a .js or .css file at the end.
 #CyberSecurity #Hacker101 #bugbountytips #BugBounty
0xHun73r ๐Ÿ‡ต๐Ÿ‡ธ (@0xhun73r) 's Twitter Profile Photo

Day 4 โ€“ Bug Bounty Challenge -Hunted for 4 hours today and found an Open Redirect in the DoS program using a nice little technique. -Spent some time on my main target but didnโ€™t find anything yet. -Tomorrow Iโ€™ll try to push harder and get more done inshaaAllah. Total earned: $0

0xHun73r ๐Ÿ‡ต๐Ÿ‡ธ (@0xhun73r) 's Twitter Profile Photo

If youโ€™re new or a pro at web pentesting, you gotta check out Web Hacking Arsenal by Rafay Baloch. Youโ€™ll learn useful tools and tricks to boost your skills fast and catch real bugs for real. #CyberSecurity #Hacker101 #bugbountytips #BugBounty

If youโ€™re new or a pro at web pentesting, you gotta check out Web Hacking Arsenal by <a href="/rafaybaloch/">Rafay Baloch</a>.
Youโ€™ll learn useful tools and tricks to boost your skills fast and catch real bugs for real.

#CyberSecurity #Hacker101 #bugbountytips #BugBounty
0xHun73r ๐Ÿ‡ต๐Ÿ‡ธ (@0xhun73r) 's Twitter Profile Photo

Day 5 โ€“ Bug Bounty Challenge -Hunted for 3 hours today with my team and found a vulnerability, which we reported. -Didnโ€™t study anything today, lost quite a bit of time. -Weโ€™ll continue tomorrow. Total earned: $0

0xHun73r ๐Ÿ‡ต๐Ÿ‡ธ (@0xhun73r) 's Twitter Profile Photo

I was just testing some random parameters with a very simple payloads. Payload: (parametr c=)'>"<svg%2Fonload=confirm("0xhun73r-6")> #bugbountytips #BugBounty

I was just testing some random parameters with a very simple payloads.
Payload: 
(parametr c=)'&gt;"&lt;svg%2Fonload=confirm("0xhun73r-6")&gt;

 #bugbountytips #BugBounty
0xHun73r ๐Ÿ‡ต๐Ÿ‡ธ (@0xhun73r) 's Twitter Profile Photo

That really made me happy, thank you for saying that ๐Ÿ™ Iโ€™ll do my best to get back to hunting and share notes & daily updates soon insha'allah

Mohamed Reda Desoky (@mrdesoky0) 's Twitter Profile Photo

Just released the Ultimate IDOR Testing Checklist ๐Ÿงฉ I combined techniques from many sources to cover IDOR scenarios. Know a technique I missed? Drop it in the comments. Notion: mrdesoky0.notion.site/Ultimate-IDOR-โ€ฆ GitHub: github.com/mrdesoky0/vulnโ€ฆ #bugbountytips #IDOR #AppSec #InfoSec

Just released the Ultimate IDOR Testing Checklist ๐Ÿงฉ

I combined techniques from many sources to cover IDOR scenarios.

Know a technique I missed? Drop it in the comments.

Notion:
mrdesoky0.notion.site/Ultimate-IDOR-โ€ฆ
 
GitHub:
github.com/mrdesoky0/vulnโ€ฆ

#bugbountytips #IDOR #AppSec #InfoSec
Coffin (@coffinxp7) 's Twitter Profile Photo

I miss the early Twitter BBP community where people actually shared tips and lessons from their findings. Nowdays my feed is flooded with bounties screenshots, tools and there paid services promos and courses ads. Itโ€™s just not the same vibe anymore..