AbdulRahman🇮🇳 (@abdulx01t) 's Twitter Profile
AbdulRahman🇮🇳

@abdulx01t

Bug hunter.

ID: 1272830953421828098

linkhttp://xss.report/c/abdulrahman calendar_today16-06-2020 09:59:10

1,1K Tweet

579 Followers

429 Following

Emad Shanab - أبو عبد الله (@alra3ees) 's Twitter Profile Photo

Server Side Request Forgery (SSRF) Tips Resources Tools Writeups Cheatsheets Payloads github.com/JakobTheDev/bu… gowsundar.gitbook.io/book-of-bugbou… github.com/csmali/WebVuln… blog.safebuff.com github.com/NeuronAddict/p… github.com/swisskyrepo/Pa… github.com/cujanovic/SSRF… github.com/giteshnxtlvl/Y…

Server Side Request Forgery (SSRF)
Tips 
Resources
Tools
Writeups
Cheatsheets
Payloads

github.com/JakobTheDev/bu…
gowsundar.gitbook.io/book-of-bugbou…
github.com/csmali/WebVuln…
blog.safebuff.com
github.com/NeuronAddict/p…
github.com/swisskyrepo/Pa…
github.com/cujanovic/SSRF…
github.com/giteshnxtlvl/Y…
Syed Mushfik Hasan Tahsin (@smhtahsin33) 's Twitter Profile Photo

Sharing it again, if anyone finds it useful! 🙌 "Stored XSS to Account Takeover : Going beyond document.cookie | Stealing Session Data from IndexedDB" infosecwriteups.com/stored-xss-to-…

Youstin (@iustinbb) 's Twitter Profile Photo

If you want to find domains associated to an organization, you can explore DuckDuckGo's tracker-radar. It's a publicly accesible dataset that stores web tracking information, including domains operated by an organization. github.com/duckduckgo/tra…

If you want to find domains associated to an organization, you can explore DuckDuckGo's tracker-radar. 
It's a publicly accesible dataset that stores web tracking information, including domains operated by an organization.
github.com/duckduckgo/tra…
Dr. Rohit Gautam (@hackergautam) 's Twitter Profile Photo

Tips to find DOM XSS: ⚡️🔥 1. Start Burpsuite Community Edition 2. Click on Open Browser 3. Go and click on the Burp icon in extension tab on browser 4. Click on Turn on DOM Invader 5. Inject a custom canary 6. Open target website, right click, Inspect and go to Invader

Tips to find DOM XSS: ⚡️🔥

1. Start Burpsuite Community Edition 
2. Click on Open Browser 
3. Go and click on the Burp icon in extension tab on browser 
4. Click on Turn on DOM Invader 
5. Inject a custom canary 
6. Open target website, right click, Inspect and go to Invader
Md Ismail Šojal 🕷️ (@0x0sojalsec) 's Twitter Profile Photo

Resources/ideas you can use your for GitHub searches: -github.com/zricethezav/gi… -github.com/eth0izzle/shhg… -github.com/pownjs/pown-le… -github.com/hisxo/gitGrabe… -github.com/michenriksen/g… #infosec #bugbountytip #cybersecurite

Resources/ideas you can use your for GitHub searches:

-github.com/zricethezav/gi…

-github.com/eth0izzle/shhg…

-github.com/pownjs/pown-le…

-github.com/hisxo/gitGrabe…

-github.com/michenriksen/g…

#infosec #bugbountytip #cybersecurite
Will Gates (@wllgates) 's Twitter Profile Photo

Looking for open S3 buckets? Use buckets.grayhatwarfare.com 😊 Tip taken from the amazing writeup mikey96.medium.com/cloud-based-st… mikey96.medium.com/cloud-based-st… made by Mikey credit: Michele Romano #bugbountytips #recon #informationsecurity

Jayesh Madnani (@jayesh25_) 's Twitter Profile Photo

Bug Bounty Tips: Account Hijacking via Invite Flows💰 I've reported 10+ similar issues involving these scenarios, securing me some quick victories! People often overlook straightforward logical issues, rushing to tackle the complex ones. However, these issues are deceptively

Bug Bounty Tips: Account Hijacking via Invite Flows💰

I've reported 10+ similar issues involving these scenarios, securing me some quick victories! People often overlook straightforward logical issues, rushing to tackle the complex ones. However, these issues are deceptively
Jayesh Madnani (@jayesh25_) 's Twitter Profile Photo

🔍Question of the Day: Where to hunt for XXE (XML External Entity) vulnerabilities? XXEs are lurking in unexpected places! When it comes to identifying XXE issues, you'll find these vulnerabilities almost everywhere. Here's my top 5 list of features and areas you should keep

🔍Question of the Day: Where to hunt for XXE (XML External Entity) vulnerabilities? XXEs are lurking in unexpected places!

When it comes to identifying XXE issues, you'll find these vulnerabilities almost everywhere. 

Here's my top 5 list of features and areas you should keep
Kévin GERVOT (Mizu) (@kevin_mizu) 's Twitter Profile Photo

I think it's time for a solution ⏰ To solve this challenge, you had to abuse the DOMPurify namespace misconfiguration to trigger an XSS this way 👇 Solution link: challenges.mizu.re/xss_02.html?ht… 1/6

I think it's time for a solution ⏰

To solve this challenge, you had to abuse the DOMPurify namespace misconfiguration to trigger an XSS this way 👇

Solution link: challenges.mizu.re/xss_02.html?ht…

1/6
Jayesh Madnani (@jayesh25_) 's Twitter Profile Photo

🔐 Bug Bounty Tips: Reported 15+ XSS Issues on a broad-scoped program leveraging AEM! 🚀 If you stumble upon a target app using AEM, make sure to use these XSS payloads for some quick wins! 💰 1️⃣ https://target[.]com/1<img src=x data'a'onerror=alert(domain)>.childrenlist.htm

🔐 Bug Bounty Tips: Reported 15+ XSS Issues on a broad-scoped program leveraging AEM! 🚀

If you stumble upon a target app using AEM, make sure to use these XSS payloads for some quick wins! 💰

1️⃣ https://target[.]com/1&lt;img src=x data'a'onerror=alert(domain)&gt;.childrenlist.htm
BBR - Bug Bounty Resources 🧵 (@bbr_bug) 's Twitter Profile Photo

🕵️‍♂️🔍🛠️ The Top Hacker Methodologies & Tools Notes 📝 Concrete5 CMS: Identification, Mass Hunting, Nuclei Template Writing & Reporting 🔗 Link: gist.github.com/ruevaughn/8a8e… #bugbounty #infosec #bugbountytip 👾🔒🔧

🕵️‍♂️🔍🛠️ The Top Hacker Methodologies &amp; Tools Notes 📝

Concrete5 CMS: Identification, Mass Hunting, Nuclei Template Writing &amp; Reporting

🔗 Link: gist.github.com/ruevaughn/8a8e…

#bugbounty #infosec #bugbountytip 👾🔒🔧
The Muslim (@themuslim786) 's Twitter Profile Photo

My hero Muhammad ﷺ My role model Muhammad ﷺ My guide Muhammadﷺ My motivation Muhammadﷺ My teacher Muhammadﷺ My leader Muhammadﷺ My Prophet Muhammad ﷺ I follow Muhammad ﷺ I love Muhammad ﷺ I admire Muhammad ﷺ We are Ummah of Muhammad ﷺ #arrest_Narsinghanand