Atif Alam ๐Ÿ‡ฎ๐Ÿ‡ณ (@atif2816) 's Twitter Profile
Atif Alam ๐Ÿ‡ฎ๐Ÿ‡ณ

@atif2816

Ethical Hacker, Bug Bounty hunter

ID: 1488148589344071680

calendar_today31-01-2022 13:54:24

109 Tweet

452 Followers

976 Following

Maciej Piechota (@haqpl) 's Twitter Profile Photo

Somebody tell me this is not a dream ๐Ÿ˜… Yay, I was awarded a $200,000 ๐Ÿ”ฅ bounty on HackerOne! hackerone.com/haqpl #TogetherWeHitHarder

Godfather Orwa ๐Ÿ‡ฏ๐Ÿ‡ด (@godfatherorwa) 's Twitter Profile Photo

Hello everyone โ™ฅ a little bit write-up of #bugbountytip #bugbountytips I am going to write here ..... Title: getting unauthorized access on 3rd party's/workspaces & and building your checklist for quickly locating bugs there via massive recon we know that its helpful to look

Hello everyone โ™ฅ
a little bit write-up of #bugbountytip #bugbountytips I am going to write here ..... 

Title:
getting unauthorized access on 3rd party's/workspaces & and building your checklist for quickly locating bugs there via massive recon

we know that its helpful to look
Ahsan Khan (@hunter0x7) 's Twitter Profile Photo

bugcrowd HackerOne Why not hire people like who have seen the struggle of real hunting? Why not hire people who are working day/night for years, These people are Gems, They know what are the real problems and how to overcome them. Hire bug hunters instead of Pentesters,

Atif Alam ๐Ÿ‡ฎ๐Ÿ‡ณ (@atif2816) 's Twitter Profile Photo

While looking for #React2Shell with Rohan_lew we identified a critical SSRF flaw that enabled extraction of AWS metadata โ€” a serious cloud-security exposure. #bugbounty #Hacking #InfoSec #EthicalHacking #cybersecurity

While looking for #React2Shell with <a href="/Rohan_Lew/">Rohan_lew</a>  we identified a critical SSRF flaw that enabled extraction of AWS metadata โ€” a serious cloud-security exposure.

#bugbounty #Hacking #InfoSec #EthicalHacking #cybersecurity
Atif Alam ๐Ÿ‡ฎ๐Ÿ‡ณ (@atif2816) 's Twitter Profile Photo

Reported โ†’ Triaged โ†’ Rewarded โ†’ Patched One week laterโ€ฆ Tried bypass with %00 โ†’ Reported again โ†’ Retriaged Sometimes the patch is just the beginning. Tips :- https://example[.]com/endpoint -> Forbidden https://example[.]com/endpoint%00 -> bypassed #bugbountytips

Reported โ†’ Triaged โ†’ Rewarded โ†’ Patched
One week laterโ€ฆ
Tried bypass with %00 โ†’ Reported again โ†’ Retriaged

Sometimes the patch is just the beginning.

Tips :- https://example[.]com/endpoint -&gt; Forbidden 
https://example[.]com/endpoint%00 -&gt; bypassed

#bugbountytips