Mcerfa11l | Sultan Al-Abdali (@7evv1) 's Twitter Profile
Mcerfa11l | Sultan Al-Abdali

@7evv1

BugHunter, Interested in #Hacking ، #BugHunting ، #PenTesting #cybersecurity

ID: 1451995177258717191

calendar_today23-10-2021 19:34:29

138 Tweet

210 Followers

151 Following

Mcerfa11l | Sultan Al-Abdali (@7evv1) 's Twitter Profile Photo

Easy Business Logic Flaw 1-Chose a Subscription plan 2-Intercept the request 3-Modify parameters related to the subscription tier upgrade 4- Change it to a lower tier 5- Verify that the tier has been changed within the same price Great impact But Dup😓 #bugbountytips

Easy Business Logic Flaw 
1-Chose a Subscription plan 
2-Intercept the request 
3-Modify parameters related to the subscription tier upgrade 
4- Change it to a lower tier 
5- Verify that the tier has been changed within the same price

Great impact But Dup😓 #bugbountytips
Mcerfa11l | Sultan Al-Abdali (@7evv1) 's Twitter Profile Photo

THREAD How did I find 2 DOM XSS by hacking Swagger-UI? 1-Do a subdomain enum to find subs that use Swagger Ui 2-Get the live subs 3-Run Nuclei in all the live subs using the (-tags swagger) 4-Find Swagger Ui endpoints #BugBounty #bugbountytip #bugbountytips #Cybersecurity

THREAD
 How did I find 2 DOM XSS by hacking Swagger-UI?

1-Do a subdomain enum to find subs that use Swagger Ui 
2-Get the live subs 
3-Run Nuclei in all the live subs using the (-tags swagger)
4-Find Swagger Ui endpoints
#BugBounty  #bugbountytip  #bugbountytips #Cybersecurity
Mcerfa11l | Sultan Al-Abdali (@7evv1) 's Twitter Profile Photo

Geting ready for subdomain enumeration on 1500+ domains Day 1 and still counting , i think it will take a week 😅 #BugBounty #BugBountytips #BugBountytip

Mcerfa11l | Sultan Al-Abdali (@7evv1) 's Twitter Profile Photo

Update : I've reported 5 3 of them got triaged Vala sepix y'all were laughing and said it would be dups😅 #bugbountytip #bugbounty #bugbountytips #CyberSecurity

Update :

I've reported 5
 3 of them got triaged

<a href="/Vabro_/">Vala</a> <a href="/0xSepix/">sepix</a> y'all were laughing and said it would be dups😅

#bugbountytip #bugbounty #bugbountytips #CyberSecurity
SentinelX Research (@sentinelxteam) 's Twitter Profile Photo

We're happy to announce that we created a tool to automate the process of finding CVE-2024-24142 and detecting the SQL Error. by @Ev1ct1on & Meshaal github.com/SentinelXResea… #bugbountytips #bugbountytip #bugbounty

Mcerfa11l | Sultan Al-Abdali (@7evv1) 's Twitter Profile Photo

improper access control الحمدلله رجعت بشي يجمّل بعد وفي شركة عالمية ، اول مايصحلونها ويحددون خطورتها راح اشارككم تفاصيها شكرا على الTip الي كان في مقطع سوني Rushy😼 #امن_سبراني #bugbountytips #bugHunting #BugBounty

improper access control
الحمدلله رجعت بشي يجمّل بعد وفي شركة عالمية ، اول مايصحلونها ويحددون خطورتها راح اشارككم تفاصيها

شكرا على الTip الي كان في مقطع سوني <a href="/0xrushy/">Rushy</a>😼 

 #امن_سبراني #bugbountytips #bugHunting #BugBounty