A.fahimi (@af4himi) 's Twitter Profile
A.fahimi

@af4himi

Bug Hunter

ID: 1099184681541689344

calendar_today23-02-2019 05:50:24

390 Tweet

5,5K Followers

328 Following

A.fahimi (@af4himi) 's Twitter Profile Photo

- First Test with (htt[]ps://web.archive.org/cdx/search/cdx?url=*.domain&fl=original&collapse=urlkey) - Found a subdomain (sub.domain[.]com/scripts/sys_getpass.php?usercode=1) - Sql Injection found here :D - I was awarded a $4,050 bounty :D #TogetherWeHitHarder

- First Test with (htt[]ps://web.archive.org/cdx/search/cdx?url=*.domain&fl=original&collapse=urlkey)
- Found a subdomain (sub.domain[.]com/scripts/sys_getpass.php?usercode=1)
- Sql Injection found here :D
- I was awarded a $4,050 bounty :D
#TogetherWeHitHarder
PT SWARM (@ptswarm) 's Twitter Profile Photo

💥 We have reproduced CVE-2023-22527 in Atlassian Confluence. A template injection vulnerability allows an unauthenticated attacker to achieve RCE on an affected instance. Update your software ASAP!

💥 We have reproduced CVE-2023-22527 in Atlassian Confluence.

A template injection vulnerability allows an unauthenticated attacker to achieve RCE on an affected instance.

Update your software ASAP!
🇪🇨🍫 (@bxmbn) 's Twitter Profile Photo

More and more BBPs programs leaving/closing at a crazy rate New VDPs every month Almost 300 Reports in less than a week for this new VDP We are doomed.

More and more BBPs programs leaving/closing at a crazy rate

New VDPs every month

Almost 300 Reports in less than a week for this new VDP

We are doomed.
Nagli (@galnagli) 's Twitter Profile Photo

The damage of VDP programs and their Incentivization is far greater than giving some hunters "points" for farming none-bugs that they can later boast on their CV's, I believe it might actually ruin Bug Bounty platforms in the near future, Let's explore the facts 📜 So VDP's, as

The damage of VDP programs and their Incentivization is far greater than giving some hunters "points" for farming none-bugs that they can later boast on their CV's, I believe it might actually ruin Bug Bounty platforms in the near future, Let's explore the facts 📜

So VDP's, as
A.fahimi (@af4himi) 's Twitter Profile Photo

This month I earned $7,500 bounty and reached the 28th rank of P1 Warrior in bugcrowd , Only with 7 hours of work per day. #BugBounty

This month I earned $7,500 bounty and reached the 28th rank of P1 Warrior in <a href="/Bugcrowd/">bugcrowd</a> , Only with 7 hours of work per day.
#BugBounty
A.fahimi (@af4himi) 's Twitter Profile Photo

In the last month of the year, I earned $20k bounty and reached 6th P1-P2 leaderboard in October. I had great moments this year in the bugcrowd platform.

In the last month of the year, I earned $20k bounty and reached 6th P1-P2 leaderboard in October. I had great moments this year in the <a href="/Bugcrowd/">bugcrowd</a> platform.
A.fahimi (@af4himi) 's Twitter Profile Photo

Excited to share that I’ve made it to the Top 25 ranking researchers on bugcrowd this month! 🎉 It’s been a journey full of challenges and learning, and there’s still more to come. Big thanks to the amazing security community for the support and motivation! 🔥 #BugBounty

Excited to share that I’ve made it to the Top 25 ranking researchers on <a href="/Bugcrowd/">bugcrowd</a> this month! 🎉
It’s been a journey full of challenges and learning, and there’s still more to come.
Big thanks to the amazing security community for the support and motivation! 🔥 #BugBounty
Kamel (@sefiyed) 's Twitter Profile Photo

LBank.com TFy77c1qsBwjjo1gDfthNxVPjcnGy6Vxa4 I hope you get this message. I would like to inform you that the hacker's wallet address has been exposed and unauthorized transactions have been sent to your exchange. If possible, please block these transactions and help this

<a href="/LBank_Exchange/">LBank.com</a> 
TFy77c1qsBwjjo1gDfthNxVPjcnGy6Vxa4
I hope you get this message. I would like to inform you that the hacker's wallet address has been exposed and unauthorized transactions have been sent to your exchange. If possible, please block these transactions and help this
A.fahimi (@af4himi) 's Twitter Profile Photo

I took a little break from bug bounty. But I’m back now — and made $13,850 in just one month. Guess the bugs missed me 🐞💰 Huge thanks to bugcrowd and YesWeHack ⠵ for the support and awesome platforms 🙌 #Bugbounty #ItTakesACrowd

I took a little break from bug bounty.
But I’m back now — and made $13,850 in just one month.
Guess the bugs missed me 🐞💰
Huge thanks to <a href="/Bugcrowd/">bugcrowd</a>  and <a href="/yeswehack/">YesWeHack ⠵</a>  for the support and awesome platforms 🙌
#Bugbounty
#ItTakesACrowd
H4x0r.DZ (@h4x0r_dz) 's Twitter Profile Photo

Yesterday it was me and Godfather Orwa 🇯🇴. Today, HackerOne banned YS — one of the most talented hackers on the platform. Tomorrow it could be any of us… unless you’re a big content creator with a huge following. HackerOne grew because of hackers. We deserve to be

A.fahimi (@af4himi) 's Twitter Profile Photo

HackerOne is banning accounts without any clear reason. My account, with 2 years of work and $5000 left in bounties, was banned for nothing. It’s obvious they just want to take hackers’ rights. Shame on HackerOne." These actions by HackerOne are purely business-driven HackerOne

A.fahimi (@af4himi) 's Twitter Profile Photo

بچه هایی که باگ بانتی‌کارمیکنید سوال میکنید برای نقد کردن بانتیامون چیکارکنیم امیر Amir Kiani کارش‌ خیلی درسته آی‌دی تلگرامشم میزارم کمکی خواستید براتون اوکی میکنه t.me/Offensive

A.fahimi (@af4himi) 's Twitter Profile Photo

reading Js >> found an endpoint file inclusion >> LFI >> RCE :D Write-up will be published after fix on: blog.voorivex.team #BugBounty

reading Js &gt;&gt; found an endpoint file inclusion    &gt;&gt; LFI &gt;&gt; RCE :D
Write-up will be published after fix on:
blog.voorivex.team

#BugBounty
A.fahimi (@af4himi) 's Twitter Profile Photo

you just need to find the right entry point 🔥 Still hunting, still learning — the journey continues. Deep recon always pays off🤓 #Bugbounty

you just need to find the right entry point 🔥
Still hunting, still learning — the journey continues. 
Deep recon always pays off🤓
#Bugbounty
A.fahimi (@af4himi) 's Twitter Profile Photo

I’ve just published a write-up 👇 One endpoint, one bug, full root access. A real-world LFI → RCE case study with a $2,500 bounty. 👇 medium.com/@Af4himi/how-a… #bugbountytips #bugbounty #bugbountytip

A.fahimi (@af4himi) 's Twitter Profile Photo

Building and selling AI trained on researchers’ reports while closing researcher accounts without clear explanations? That’s not how you treat the community that built your platform. Transparency, consent, and respect for researchers are not optional. HackerOne