osama_alaa (@osama_hroot) 's Twitter Profile
osama_alaa

@osama_hroot

#eWPTX #CRTP #eCPPTv2 #eMAPT #eWPT

ID: 983435771184078848

calendar_today09-04-2018 20:05:33

44 Tweet

801 Followers

102 Following

Ahmed Aboul-Ela (@aboul3la) 's Twitter Profile Photo

This will have huge impact!, another great example on how RCE can be achieved on OWA easily through ViewState deserialization attack. Red Teamers it's your chance now :) thezdi.com/blog/2020/2/24…

RedForce (@redforcesec) 's Twitter Profile Photo

Attacking Helpdesks (Part 1): Remote Code Execution (#RCE) chain on #Deskpro with #Bitdefender as a case study. Full technical details to #exploit RCE inside. blog.redforce.io/attacking-help… #BugBounty #websecurity #infosecwriteup

Attacking Helpdesks (Part 1): Remote Code Execution (#RCE) chain on #Deskpro with #Bitdefender as a case study. Full technical details to #exploit RCE inside.
blog.redforce.io/attacking-help…

#BugBounty #websecurity  #infosecwriteup
Ahmed Sultan 🇪🇬🇵🇸 (@0x4148) 's Twitter Profile Photo

Me and the folks RedForce just finalized the 1st part of the Windows authentication attacks series. blog.redforce.io/windows-authen… The series suppose to cover the NTLM/Kerberos authentication in detail as well as how their attacks work. Happy reading, and stay tuned for part 2.

Me and the folks <a href="/RedForceSec/">RedForce</a>  just finalized the 1st part of the Windows authentication attacks series.
blog.redforce.io/windows-authen…
The series suppose to cover the NTLM/Kerberos authentication in detail as well as how their attacks work.
Happy reading, and stay tuned for part 2.
Abood Nour 🇵🇸 (@aboodnour) 's Twitter Profile Photo

An easy catch! 😅 Pentest with tight schedule, No publicly-known vulns? Download firmware -> extract binary -> strings -> find low hanging fruits -> Win :))

osama_alaa (@osama_hroot) 's Twitter Profile Photo

Bug Poc LFI Challenge Writeup - Stealing /etc/passwd , AWS Metadata , and source code. - Makeing quick source code analysis Thanks BugPoC medium.com/@osama.alaa/ss… #lfi #ssrf

osama_alaa (@osama_hroot) 's Twitter Profile Photo

Finally finished HackerOne ctf individually with a hint in challenge 11 , it wasn't a human challenge :D Thanks Adam Langley for this wonderful ctf especially Evil Quiz and attack-box challenges #ctf

Finally finished <a href="/Hacker0x01/">HackerOne</a> ctf individually with a hint in challenge 11 , it wasn't a human challenge :D

Thanks <a href="/adamtlangley/">Adam Langley</a> for this wonderful ctf especially Evil Quiz and attack-box challenges

#ctf
osama_alaa (@osama_hroot) 's Twitter Profile Photo

Write-up of #hackyholidays CTF , Thanks Adam Langley for the challenges. osama-alaa.medium.com/h1-ctf-grinch-… #bugbounty #bugbountytips #infosec #hackerone #ctf

osama_alaa (@osama_hroot) 's Twitter Profile Photo

Cloudflare XSS bypass in input tag : Payload : onfocus=alert&#x00000000028;1&#x00000000029; autofocus> Don't rely on public payloads to bypass WAFs , as most of them won't work :D You have to craft your own payload . #xss #bypass #bugbountytip #BugBounty

Cloudflare XSS bypass in input tag :
Payload :
 onfocus=alert&amp;#x00000000028;1&amp;#x00000000029; autofocus&gt;

Don't rely on public payloads to bypass WAFs , as most of them won't work :D 

You have to craft your own payload .

#xss #bypass #bugbountytip #BugBounty
Kha1i (@kha1ifuzz) 's Twitter Profile Photo

Insecure Java Deserialization leading to RCE (CVE-2021-27335) in one of the common Banking Applications discovered by one of Malcrove - Next Generation Security team members: malcrove.com/kollectapps-in…

osama_alaa (@osama_hroot) 's Twitter Profile Photo

الحمد لله VMware fixed two vulnerabilities in vCenter server: CVE-2021-21992 >> XML parsing denial-of-service vulnerability CVE-2021-21993 >> SSRF vulnerability For more info vmware.com/security/advis…