Mohamed Fodil (@_public_void) 's Twitter Profile
Mohamed Fodil

@_public_void

iOS Programming ~ Reverse Engineering | Electronic-ST | WhiteHat | Bug Bounty Hunter | Acknowledged By Apple ๐Ÿ

ID: 1386866376455897092

calendar_today27-04-2021 02:15:02

1,1K Tweet

2,2K Followers

704 Following

Mohamed Fodil (@_public_void) 's Twitter Profile Photo

I earned $600 for my submission on @bugcrowd #ItTakesACrowd ๐Ÿ˜ Bug: Broken Authentication Ability to initiate and re-generate a valid session by just using one leaked value in the requests. #bugbountytips #BugBounty #CyberSecurity

I earned $600 for my submission on @bugcrowd #ItTakesACrowd  ๐Ÿ˜

Bug: Broken Authentication

Ability to initiate and re-generate a valid session by just using one leaked value in the requests. 

#bugbountytips 
#BugBounty
#CyberSecurity
Mohamed Fodil (@_public_void) 's Twitter Profile Photo

Yay, I and my friend Samwell were awarded a $800 bounty on HackerOne #TogetherWeHitHarder Bug: HTML Injection XSS wasnโ€™t possible due to CSP + WAF #bugbountytips #BugBounty #CyberSecurity

Yay, I and my friend <a href="/uieyuyeriuzyer/">Samwell</a> were awarded a $800 bounty on <a href="/Hacker0x01/">HackerOne</a> #TogetherWeHitHarder

Bug: HTML Injection

XSS wasnโ€™t possible due to CSP + WAF

#bugbountytips 
#BugBounty 
#CyberSecurity
Mohamed Fodil (@_public_void) 's Twitter Profile Photo

Yay, I and my friend Samwell were awarded an extra $1100 bounty on HackerOne #TogetherWeHitHarder HTML Injection worth $1900 ๐Ÿ˜… Although XSS wasnโ€™t possible, we found a way to escalate the HTMLi #bugbountytips #BugBounty #CyberSecurity x.com/_public_void/sโ€ฆ

Yay, I and my friend <a href="/uieyuyeriuzyer/">Samwell</a> were awarded an extra $1100 bounty on <a href="/Hacker0x01/">HackerOne</a> #TogetherWeHitHarder

HTML Injection worth $1900 ๐Ÿ˜…

Although XSS wasnโ€™t possible, we found a way to escalate the HTMLi

#bugbountytips 
#BugBounty 
#CyberSecurity 

x.com/_public_void/sโ€ฆ
Mohamed Fodil (@_public_void) 's Twitter Profile Photo

First duplicate in 2024 โ˜น๏ธ it was already triaged, then boom ๐Ÿ’ฅthe program found it duplicate ๐Ÿฅฒ #BugBounty #CyberSecurity

First duplicate in 2024 โ˜น๏ธ it was already triaged, then boom ๐Ÿ’ฅthe program found it duplicate ๐Ÿฅฒ

#BugBounty 
#CyberSecurity
Mohamed Fodil (@_public_void) 's Twitter Profile Photo

The 2nd submission was triaged in just 24 hours ๐Ÿ˜ waiting for the other one ! Big shout out to bugcrowd Triage #BugBounty #CyberSecurity

The 2nd submission was triaged in just 24 hours ๐Ÿ˜ waiting for the other one ! 

Big shout out to <a href="/Bugcrowd/">bugcrowd</a> Triage 

#BugBounty 
#CyberSecurity
Mohamed Fodil (@_public_void) 's Twitter Profile Photo

Bad luck ๐Ÿ˜ I found a leaked "Authorization Bearer" that grant me access to read (internal/private repos content), I can even know what will be the upcoming updates! but it turned out to be a "read-only" token ๐Ÿ˜ฌ #bugbountytips #BugBounty #CyberSecurity

Bad luck ๐Ÿ˜ I found a leaked "Authorization Bearer" that grant me access to read (internal/private repos content), I can even know what will be the upcoming updates! but it turned out to be a "read-only" token ๐Ÿ˜ฌ

#bugbountytips 
#BugBounty
#CyberSecurity
Mohamed Fodil (@_public_void) 's Twitter Profile Photo

I got access to an IIS server vulnerable to SNS, managed to get into the Webroot directory and downloaded the content as PoC, triaged as P4. I reversed the DLL's and got sensitive information. Do you think Severity will increase? #bugbountytips #BugBounty #CyberSecurity

I got access to an IIS server vulnerable to SNS, managed to get into the Webroot directory and downloaded the content as PoC, triaged as P4.

I reversed the DLL's and got sensitive information. 

Do you think Severity will increase?

#bugbountytips 
#BugBounty 
#CyberSecurity
Mohamed Fodil (@_public_void) 's Twitter Profile Photo

Hereโ€™s how me and my friend Samwell demonstrated the HTML Injection impact ๐Ÿ‘‡ All-in-One PoC ๐Ÿ˜… We wrote a small report on the page itself in which we demonstrated 4 HTMLi examples in a single payload #bugbountytips #BugBounty #CyberSecurity

Hereโ€™s how me and my friend <a href="/uieyuyeriuzyer/">Samwell</a> demonstrated the HTML Injection impact ๐Ÿ‘‡

All-in-One PoC ๐Ÿ˜…

We wrote a small report on the page itself in which we demonstrated 4 HTMLi examples in a single payload

#bugbountytips 
#BugBounty 
#CyberSecurity
Mohamed Fodil (@_public_void) 's Twitter Profile Photo

Today, I received 20 private invitations to hack on private programs at HackerOne ๐Ÿ˜ƒ Although Iโ€™m a lazy hunter ๐Ÿ˜… Iโ€™ll try my best ! #BugBounty #CyberSecurity

Today, I received 20 private invitations to hack on private programs at <a href="/Hacker0x01/">HackerOne</a> ๐Ÿ˜ƒ Although Iโ€™m a lazy hunter ๐Ÿ˜… Iโ€™ll try my best !

#BugBounty 
#CyberSecurity
Mohamed Fodil (@_public_void) 's Twitter Profile Photo

Thanks for the invitation ๐Ÿ˜ƒ๐Ÿ˜ƒ I have to find an authentication flaw as this is the right way to say thanks ๐Ÿ˜ #bugbountytips #CyberSecurity

Thanks for the invitation ๐Ÿ˜ƒ๐Ÿ˜ƒ

I have to find an authentication flaw as this is the right way to say thanks ๐Ÿ˜ 

#bugbountytips 
#CyberSecurity
Mohamed Fodil (@_public_void) 's Twitter Profile Photo

Use FFUF for subdomains-list batch fuzzing ๐Ÿ‘‡ Windows PowerShell Save the code in the pic below as "script.ps1" Linux Save this as "script.sh" [#!/bin/bash for URL in $(<subs.txt); do ffufโ€ฆ-u "$URL/FUZZ" โ€ฆ done] #bugbountytips #BugBounty #CyberSecurity

Use FFUF for subdomains-list batch fuzzing ๐Ÿ‘‡

Windows PowerShell
Save the code in the pic below as "script.ps1"

Linux
Save this as "script.sh" 

[#!/bin/bash
for URL in $(&lt;subs.txt); do ffufโ€ฆ-u "$URL/FUZZ" โ€ฆ
done]

#bugbountytips 
#BugBounty
#CyberSecurity
Mohamed Fodil (@_public_void) 's Twitter Profile Photo

WOW ๐Ÿคฉ Triage, Fix and Retest were done in less than 24h I was invited to this PBBP at HackerOne since a month ago, (launched in 2020 with only 2 domains in-scope) ๐Ÿคทโ€โ™‚๏ธ Simple, no freaking tip ๐Ÿ™ƒ "api/vx/me/" => "api/vx/other_usrid/" #bugbountytips #BugBounty #CyberSecurity

WOW ๐Ÿคฉ Triage, Fix and Retest were done in less than 24h

I was invited to this PBBP at <a href="/Hacker0x01/">HackerOne</a> since a month ago, (launched in 2020 with only 2 domains in-scope) ๐Ÿคทโ€โ™‚๏ธ

Simple, no freaking tip ๐Ÿ™ƒ
"api/vx/me/" =&gt; "api/vx/other_usrid/"

#bugbountytips 
#BugBounty 
#CyberSecurity
Mohamed Fodil (@_public_void) 's Twitter Profile Photo

Yay, I was awarded a $1,000 bounty on HackerOne! #TogetherWeHitHarder This was really fast โšก๏ธ๐Ÿ˜ƒ Reported + Triaged on 17/04/2024 Retested on 18/04/2024 Resolved + Awarded on 19/04/2024 #BugBounty #CyberSecurity x.com/_public_void/sโ€ฆ

Yay, I was awarded a $1,000 bounty on <a href="/Hacker0x01/">HackerOne</a>! #TogetherWeHitHarder 

This was really fast โšก๏ธ๐Ÿ˜ƒ

Reported + Triaged on 17/04/2024
Retested on 18/04/2024
Resolved + Awarded on 19/04/2024

#BugBounty 
#CyberSecurity 

x.com/_public_void/sโ€ฆ
Mohamed Fodil (@_public_void) 's Twitter Profile Photo

While I was performing a retest for my report to a program on HackerOne , Iโ€™ve noticed an extra security layer was added, after testing it separately, I found it vulnerable to something ๐Ÿคทโ€โ™‚๏ธ I reported it and got it Triaged ๐Ÿ™ƒ #CyberSecurity #BugBounty

While I was performing a retest for my report to a program on <a href="/Hacker0x01/">HackerOne</a> , Iโ€™ve noticed an extra security layer was added, after testing it separately, I found it vulnerable to something ๐Ÿคทโ€โ™‚๏ธ 

I reported it and got it Triaged ๐Ÿ™ƒ

#CyberSecurity 
#BugBounty
Mohamed Fodil (@_public_void) 's Twitter Profile Photo

I find it really fun targeting and bypassing fixes of "Duplicated/Resolved" reports ๐Ÿ˜ #BugBounty #CyberSecurity #bugbountytips

I find it really fun targeting and bypassing fixes of "Duplicated/Resolved" reports ๐Ÿ˜

#BugBounty 
#CyberSecurity 
#bugbountytips
Mohamed Fodil (@_public_void) 's Twitter Profile Photo

I earned $$$ for my submission on @bugcrowd #ItTakesACrowd ๐Ÿ˜ 2FA Bypass [Duplicate > Resolved > FIX-Bypass] Neither BC Triage nor the Program Team were able to reproduce. Finally, a Team Member have figured out why the issue wasnโ€™t reproducible โœ… #BugBounty #CyberSecurity

I earned $$$ for my submission on @bugcrowd #ItTakesACrowd  ๐Ÿ˜

2FA Bypass
[Duplicate &gt; Resolved &gt; FIX-Bypass]

Neither BC Triage nor the Program Team were able to reproduce. Finally, a Team Member have figured out why the issue wasnโ€™t reproducible โœ…

#BugBounty
#CyberSecurity
Mohamed Fodil (@_public_void) 's Twitter Profile Photo

Lesson Learned: To avoid Self-Dulplicate, when you discover the same vulnerability across different domains/endpoints, report just one and wait for it to be Resolved, then do the same for the others. #bugbountytips #BugBounty #CyberSecurity

Lesson Learned:

To avoid Self-Dulplicate, when you discover the same vulnerability across different domains/endpoints, report just one and wait for it to be Resolved, then do the same for the others.

#bugbountytips 
#BugBounty 
#CyberSecurity