KaafUzair (@kaafuzair) 's Twitter Profile
KaafUzair

@kaafuzair

~Hack€r •Security-Researcher •Bug-Hunter

ID: 1235280880605605888

linkhttps://kaafhack.com calendar_today04-03-2020 19:08:40

1,1K Tweet

328 Followers

584 Following

Security Bsides Mussoorie (@bsidesmussoorie) 's Twitter Profile Photo

🎙️ Meet Our Technical Speakers | BSides Mussoorie 🏔️ We’re excited to unveil an incredible lineup of technical speakers who are bringing deep expertise across research, bug bounty, offensive security, cloud, and critical infrastructure security. 🔐💥 From independent

🎙️ Meet Our Technical Speakers | BSides Mussoorie 🏔️

We’re excited to unveil an incredible lineup of technical speakers who are bringing deep expertise across research, bug bounty, offensive security, cloud, and critical infrastructure security. 🔐💥

From independent
KaafUzair (@kaafuzair) 's Twitter Profile Photo

They pay me to break into systems for a living, But Security Bsides Mussoorie just silently hacked my entire wardrobe with this hoodie.😎 0day comfort. No patch needed.🔥 Thank you Security Bsides Mussoorie ❤️ #CyberSec #hoodie #BugBounty

They pay me to break into systems for a living, But <a href="/BsidesMussoorie/">Security Bsides Mussoorie</a> just silently hacked my entire wardrobe with this hoodie.😎
0day comfort. No patch needed.🔥
Thank you <a href="/BsidesMussoorie/">Security Bsides Mussoorie</a> ❤️
#CyberSec #hoodie #BugBounty
Soroush Dalili (@irsdl) 's Twitter Profile Photo

Slides for "ToolShell Patch Bypass and the AI That Might Have Seen It Coming" at NDC Conferences {Manchester} 2025. github.com/irsdl/sharepoi… Bonus: WAF & workarounds bypass! #AppSec #SharePoint #TolShell

Slides for "ToolShell Patch Bypass and the AI That Might Have Seen It Coming" at <a href="/NDC_Conferences/">NDC Conferences</a> {Manchester} 2025.

github.com/irsdl/sharepoi…

Bonus: WAF &amp; workarounds bypass!
#AppSec #SharePoint #TolShell
Altered Security (@alteredsecurity) 's Twitter Profile Photo

Final Black Friday Giveaway! Win FREE access to: • 1 CRTP seat • 1 CRTE seat How to participate: 1. Like 2. Comment which course you’re interested in and why 3. Repost If you've already availed the Black Friday offer, you're still eligible. Winners will be announced on Dec

Final Black Friday Giveaway!

Win FREE access to:
• 1 CRTP seat
• 1 CRTE seat

How to participate:
1. Like
2. Comment which course you’re interested in and why
3. Repost

If you've already availed the Black Friday offer, you're still eligible.
Winners will be announced on Dec
Ben Sadeghipour (@nahamsec) 's Twitter Profile Photo

Only 5 days left until NahamCon Winter Edition ❄️ Workshops, deep dives, live Q&A, and fresh research coming your way 🚀 📆 December 17 to 18 ℹ️ Check out what’s happening 👉🏼 nahamcon.com

Only 5 days left until NahamCon Winter Edition ❄️
Workshops, deep dives, live Q&amp;A, and fresh research coming your way 🚀

📆 December 17 to 18
ℹ️ Check out what’s happening 👉🏼 nahamcon.com
Security Bsides Mussoorie (@bsidesmussoorie) 's Twitter Profile Photo

🚨 BSides Mussoorie Early Bird Tickets for Conference and Trainings Are Live now🚨 Join the cybersecurity community in the hills for talks, hands-on sessions, CTFs, and real-world learning. 🎟️ Early Bird Sale ends: 15 January 2026 💸 Grab early bird discounts 👥 Extra 5% off on

🚨 BSides Mussoorie Early Bird Tickets for Conference and Trainings Are Live now🚨

Join the cybersecurity community in the hills for talks, hands-on sessions, CTFs, and real-world learning.

🎟️ Early Bird Sale ends: 15 January 2026
💸 Grab early bird discounts
👥 Extra 5% off on
André Baptista (@0xacb) 's Twitter Profile Photo

This is really cool writeup. Self-XSS + Login CSRF + SSO gadget to ATO Nice find Lauritz! security.lauritz-holtmann.de/post/xss-ato-g…

Security Bsides Mussoorie (@bsidesmussoorie) 's Twitter Profile Photo

📢 Call for Papers | BSides Mussoorie 2026 📢 Have original security research, real-world attack techniques, or defensive insights to share? Security BSides Mussoorie 2026 is now accepting talk submissions from the global InfoSec community. 📝 Submit your CFP here: 👉

dawgyg - WoH (@thedawgyg) 's Twitter Profile Photo

One of the ways that I am going to get myself back into bug hunting, is to start actually automating some things. Simple things like the content discovery, subdomain discovery, testing for xss, mapping sites out etc. All of this is time consuming, and I plan to use scripts,

One of the ways that I am going to get myself back into bug hunting, is to start actually automating some things. Simple things like the content discovery, subdomain discovery, testing for xss, mapping sites out etc. All of this is time consuming, and I plan to use scripts,
Security Bsides Mussoorie (@bsidesmussoorie) 's Twitter Profile Photo

📢 Call for Papers | BSides Mussoorie 2026 Have original security research, real-world attack techniques, or defensive insights to share? Security BSides Mussoorie 2026 is now accepting talk submissions from the global InfoSec community. bsidesmussoorie.in/event-details/… Please

📢 Call for Papers | BSides Mussoorie 2026 

Have original security research, real-world attack techniques, or defensive insights to share?  

Security BSides Mussoorie 2026 is now accepting talk submissions from the global InfoSec community. bsidesmussoorie.in/event-details/… 

Please
Abdelrhman Allam 🇵🇸 (@sl4x0) 's Twitter Profile Photo

How I turned a single leaked JS file on a dev server into a CVSS 10.0 Critical Account Takeover on a live production backend. Full technical breakdown here: medium.com/p/1912857037dc #bugbountytips #api_security #sanity

the_IDORminator (@the_idorminator) 's Twitter Profile Photo

Lets learn Auth Bypass via Session Stuffing! Easy P1s to find if the target is susceptible. Ok, so what's "Session Stuffing"? In the wonderful land of server-side code, developers can use session variables to store information. These variables can be things like your username,

Jenish Sojitra (@_jensec) 's Twitter Profile Photo

Sharing my Burp Extension that earned me $200k in 2025 while API testing heavy JS-rich targets. github.com/jenish-sojitra… The tool helps find endpoints, files, internal emails, and some secrets from minified JS. Its goal is to achieve maximum efficiency with reduced noise in

Sharing my Burp Extension that earned me $200k in 2025 while API testing heavy JS-rich targets.

github.com/jenish-sojitra…

The tool helps find endpoints, files, internal emails, and some secrets from minified JS. 

Its goal is to achieve maximum efficiency with reduced noise in
KaafUzair (@kaafuzair) 's Twitter Profile Photo

I'm excited to join Security BSides Mussoorie happening on April 9th, 2026, organized through KonfHub. Don't miss your chance to attend! konfhub.com/bsidesmussoorie Security Bsides Mussoorie

Security Bsides Mussoorie (@bsidesmussoorie) 's Twitter Profile Photo

⏳ TIME IS RUNNING OUT 📷Early Bird tickets are ending soon, and you don’t want to miss this . Book your tickets fast before the prices go up See you at BSides Mussoorie . 📷bsidesmussoorie.in/passes Follow us like our posts and share the updates to stay connected.

Farhan Khan (@one33se7en) 's Twitter Profile Photo

Yay, I was awarded another $10,000 bounty on HackerOne ! hackerone.com/one33se7en #TogetherWeHitHarder 2026 is off to a great start, Let’s go!.

Yay, I was awarded another $10,000 bounty on
<a href="/Hacker0x01/">HackerOne</a>
! hackerone.com/one33se7en #TogetherWeHitHarder

2026 is off to a great start, Let’s go!.
Jason Haddix (@jhaddix) 's Twitter Profile Photo

Day TWO of FIVE days of celebrating our 2 year ARCANUM-VERSARY! Arcanum Information Security 3rd Giveaway = FOUR seats to our new course by the_IDORminator "Zero to [BAC] Hero" ! 👍 1 Like = 1 Entry! ♻️ 1 Share = 2 Entries! Winners announced 1/21! Syllabus link below 👇

Day TWO of FIVE days of celebrating our 2 year ARCANUM-VERSARY! <a href="/arcanuminfosec/">Arcanum Information Security</a> 

3rd Giveaway = FOUR seats to our new course by <a href="/the_IDORminator/">the_IDORminator</a>  "Zero to [BAC] Hero" !

👍 1 Like = 1 Entry!
♻️ 1 Share =  2 Entries!

Winners announced 1/21!  Syllabus link below 👇
Security Bsides Mussoorie (@bsidesmussoorie) 's Twitter Profile Photo

FINAL CALL: Early Bird Discount Ending in a Few Hours! 🚨 This is not a reminder. This is not a teaser. This is the last alert The Early Bird window for BSides Mussoorie is closing in just a few hours. bsidesmussoorie.in/passes 👉 Act now. Don’t wait for “later.” Early