Eman Elyazji (@eman_yazji) 's Twitter Profile
Eman Elyazji

@eman_yazji

Bug hunter @Hacker0x01 ,,, @bugcrowd

ID: 738007362481618945

linkhttps://instagram.com/eman_elyazjii?igshid=e26850bbu3fo calendar_today01-06-2016 14:00:41

1,1K Tweet

2,2K Followers

177 Following

Intigriti (@intigriti) 's Twitter Profile Photo

Can you spot the vulnerability? ๐Ÿ”Ž Show us how you'd be able to read ANY local file you want in the comments ๐Ÿ‘‡ The best explanation gets a 25โ‚ฌ SWAG voucher! ๐Ÿ‘•

Can you spot the vulnerability? ๐Ÿ”Ž

Show us how you'd be able to read ANY local file you want in the comments ๐Ÿ‘‡

The best explanation gets a 25โ‚ฌ SWAG voucher! ๐Ÿ‘•
Abdulrahman Makki | ุนุจุฏุงู„ุฑุญู…ู† ู…ูƒูŠ (@amakki1337) 's Twitter Profile Photo

ุงู„ุญู…ุฏู„ู„ู‡ ุญุตู„ุช ุนู„ู‰ ุงู„ู…ุฑูƒุฒ ุงู„ุซุงู†ูŠ ููŠ ูƒุฃุณ ู…ู†ุตุฉ ู…ูƒุงูุขุช ุงู„ุซุบุฑุงุช ููŠ ุญุฏุซ ุจู„ุงูƒ ู‡ุงุช๐Ÿฅˆ I placed 2nd place in Bug Bounty Cup during Black Hat MEA event๐Ÿฅˆ #bugbountytips #bugbountytip #bugbounty #BHMEA22 #ุจู„ุงูƒ_ู‡ุงุช22 Faisal ู…ุชุนุจ ุงู„ู‚ู†ูŠMuteb ุงู„ุงุชุญุงุฏ ุงู„ุณุนูˆุฏูŠ ู„ู„ุฃู…ู† ุงู„ุณูŠุจุฑุงู†ูŠ ูˆุงู„ุจุฑู…ุฌุฉ ูˆุงู„ุฏุฑูˆู†ุฒ ู…ู†ุตุฉ ู…ูƒุงูุขุช ุงู„ุซุบุฑุงุช Black Hat MEA

ุงู„ุญู…ุฏู„ู„ู‡ ุญุตู„ุช ุนู„ู‰ ุงู„ู…ุฑูƒุฒ ุงู„ุซุงู†ูŠ ููŠ ูƒุฃุณ ู…ู†ุตุฉ ู…ูƒุงูุขุช ุงู„ุซุบุฑุงุช ููŠ ุญุฏุซ ุจู„ุงูƒ ู‡ุงุช๐Ÿฅˆ

I placed 2nd place in Bug Bounty Cup during Black Hat MEA event๐Ÿฅˆ

#bugbountytips #bugbountytip #bugbounty #BHMEA22 #ุจู„ุงูƒ_ู‡ุงุช22 

<a href="/Faisal/">Faisal</a> <a href="/malobeiwi/">ู…ุชุนุจ ุงู„ู‚ู†ูŠMuteb</a> <a href="/SAFCSP/">ุงู„ุงุชุญุงุฏ ุงู„ุณุนูˆุฏูŠ ู„ู„ุฃู…ู† ุงู„ุณูŠุจุฑุงู†ูŠ ูˆุงู„ุจุฑู…ุฌุฉ ูˆุงู„ุฏุฑูˆู†ุฒ</a> <a href="/BugBountySA/">ู…ู†ุตุฉ ู…ูƒุงูุขุช ุงู„ุซุบุฑุงุช</a> <a href="/Blackhatmea/">Black Hat MEA</a>
Eman Elyazji (@eman_yazji) 's Twitter Profile Photo

Sometimes parameter pollutions can also lead to IDORS: if GET/api_v1/docs? user_id=youruserid Send it like this: GET /api_v1/docs? user_id=youruserid&user_id=anotheruserid or, GET /api_v1/docs? user_id=anotheruserid&user_id=youruserid Rare but can be tried:) #bugbountytips

Eman Elyazji (@eman_yazji) 's Twitter Profile Photo

When you hunt on a shopping website try this trick: Add these items to your cart Item 1: 50$ Item 2: 49$ Change the quantity of Item 2 to -1 (negative amount) Subtotal: 1$ With this trick you can buy Item 1 for 1$ #bugbountytips #bugbountytip #bugbounty

Abdulrahman Makki | ุนุจุฏุงู„ุฑุญู…ู† ู…ูƒูŠ (@amakki1337) 's Twitter Profile Photo

#bugbountytips Sometimes when you visit a website using burp suite cloudflare stops you, but when you disable the proxy it works. here is how to bypass it using burp suite โœ๏ธ Enable match and replace with the following: pastebin.com/raw/HRZzeZLJ #Cloudflare #BugBounty

#bugbountytips

Sometimes when you visit a website using burp suite cloudflare stops you, but when you disable the proxy it works. here is how to bypass it using burp suite โœ๏ธ

Enable match and replace with the following:
pastebin.com/raw/HRZzeZLJ

 #Cloudflare #BugBounty
Eman Elyazji (@eman_yazji) 's Twitter Profile Photo

#bugbountytips Account takeover by bypassing rate limit When you try to brute force the OTP rate limit will stop you, try to add this header to bypass it โœ๏ธ X-Forwarded-For: 127.0.0.1

HackerOne (@hacker0x01) 's Twitter Profile Photo

Today marks the start of the 2023 #AmbassadorWorldCup! 29 teams, and over 600 hackers are taking on the challenge to help our AWC partners @OpenSea, Shopify Engineering, Epic Games, The Paranoids and Stripe strengthen their security. Who will come out on top? bit.ly/400LpGY

Today marks the start of the 2023 #AmbassadorWorldCup! 29 teams, and over 600 hackers are taking on the challenge to help our AWC partners @OpenSea, <a href="/ShopifyEng/">Shopify Engineering</a>, Epic Games, <a href="/TheParanoids/">The Paranoids</a> and <a href="/stripe/">Stripe</a> strengthen their security. Who will come out on top? bit.ly/400LpGY
Abdulrahman Makki | ุนุจุฏุงู„ุฑุญู…ู† ู…ูƒูŠ (@amakki1337) 's Twitter Profile Photo

ุงู„ุญู…ุฏู„ู„ู‡ ุชุฃู‡ู„ู†ุง ู…ู† ุฏูˆุฑ ุงู„ู…ุฌู…ูˆุนุงุช ุจุฃุตุนุจ ู…ุฌู…ูˆุนุฉ ููŠ ูƒุฃุณ ุงู„ุนุงู„ู… 2023 ู‡ูƒุฑ ูˆู† ๐Ÿ”ฅ๐Ÿ’ช๐Ÿ‡ธ๐Ÿ‡ฆ ุดูƒุฑุง ู„ูƒู„ ุงู„ู„ูŠ ุดุงุฑูƒ ู…ุนู†ุง ููŠ ุงู„ู…ุณุงุจู‚ุฉ ูˆุชู…ู†ูŠุงุชูƒู… ู„ู†ุง ุจุงู„ุชูˆููŠู‚ ููŠ ุงู„ู…ุจุงุฑูŠุงุช ุงู„ู‚ุงุฏู…ุฉ. Abdulrahman Makki | ุนุจุฏุงู„ุฑุญู…ู† ู…ูƒูŠ (C) Eman Elyazji 0xRAYAN ๐Ÿ‡ธ๐Ÿ‡ฆ Ahmed Makki ๐Ÿ‡ธ๐Ÿ‡ฆ ุฃุญู…ุฏ ู…ูƒู€ูŠ Abdulaziz @leetibrahim 0xRaw ุนุจุฏุงู„ุฑุญู…ู† ๐Ÿ‡ธ๐Ÿ‡ฆ Murtada Bin Abdullah (Rood) @0xNasser_

ุงู„ุญู…ุฏู„ู„ู‡ ุชุฃู‡ู„ู†ุง ู…ู† ุฏูˆุฑ ุงู„ู…ุฌู…ูˆุนุงุช ุจุฃุตุนุจ ู…ุฌู…ูˆุนุฉ ููŠ ูƒุฃุณ ุงู„ุนุงู„ู… 2023 ู‡ูƒุฑ ูˆู† ๐Ÿ”ฅ๐Ÿ’ช๐Ÿ‡ธ๐Ÿ‡ฆ

ุดูƒุฑุง ู„ูƒู„ ุงู„ู„ูŠ ุดุงุฑูƒ ู…ุนู†ุง ููŠ ุงู„ู…ุณุงุจู‚ุฉ ูˆุชู…ู†ูŠุงุชูƒู… ู„ู†ุง ุจุงู„ุชูˆููŠู‚ ููŠ ุงู„ู…ุจุงุฑูŠุงุช ุงู„ู‚ุงุฏู…ุฉ.

<a href="/AMakki1337/">Abdulrahman Makki | ุนุจุฏุงู„ุฑุญู…ู† ู…ูƒูŠ</a> (C) 
<a href="/eman_yazji/">Eman Elyazji</a>
<a href="/0xRAYAN7/">0xRAYAN ๐Ÿ‡ธ๐Ÿ‡ฆ</a>
<a href="/Ahmed0Makki/">Ahmed Makki ๐Ÿ‡ธ๐Ÿ‡ฆ ุฃุญู…ุฏ ู…ูƒู€ูŠ</a>
<a href="/stuipds/">Abdulaziz</a>
@leetibrahim
<a href="/0xRaw/">0xRaw</a>
<a href="/aa_8989/">ุนุจุฏุงู„ุฑุญู…ู†</a>
<a href="/0x_rood/">๐Ÿ‡ธ๐Ÿ‡ฆ Murtada Bin Abdullah (Rood)</a>
@0xNasser_
Abdulrahman Makki | ุนุจุฏุงู„ุฑุญู…ู† ู…ูƒูŠ (@amakki1337) 's Twitter Profile Photo

ุฌุงู‡ุฒูŠู† ู„ูƒุฃุณ ุงู„ุนุงู„ู… ู‡ูƒุฑ ูˆู† ูขู ูขูค ๐Ÿ”ฅ ๐Ÿ† ู„ู„ู…ุดุงุฑูƒุฉ ูˆุชู…ุซูŠู„ ุงู„ู…ู…ู„ูƒุฉ ุงู„ุนุฑุจูŠุฉ ุงู„ุณุนูˆุฏูŠุฉ ๐Ÿ‡ธ๐Ÿ‡ฆ ูŠุฑุฌู‰ ุชุนุจุฆุฉ ุงู„ู†ู…ูˆุฐุฌ: docs.google.com/forms/d/e/1FAIโ€ฆ

ุฌุงู‡ุฒูŠู† ู„ูƒุฃุณ ุงู„ุนุงู„ู… ู‡ูƒุฑ ูˆู† ูขู ูขูค ๐Ÿ”ฅ ๐Ÿ†

ู„ู„ู…ุดุงุฑูƒุฉ ูˆุชู…ุซูŠู„ ุงู„ู…ู…ู„ูƒุฉ ุงู„ุนุฑุจูŠุฉ ุงู„ุณุนูˆุฏูŠุฉ ๐Ÿ‡ธ๐Ÿ‡ฆ

ูŠุฑุฌู‰ ุชุนุจุฆุฉ ุงู„ู†ู…ูˆุฐุฌ:
docs.google.com/forms/d/e/1FAIโ€ฆ
Abdulrahman Makki | ุนุจุฏุงู„ุฑุญู…ู† ู…ูƒูŠ (@amakki1337) 's Twitter Profile Photo

ุงู„ุญู…ุฏู„ู„ู‡ ุชุฃู‡ู„ู†ุง ู…ุน ุงู„32 ูุฑูŠู‚ ุงู„ู‰ ุฏูˆุฑ ุงู„ู…ุฌู…ูˆุนุงุช ูˆุถู…ู† ุงู„ูุฑู‚ ุงู„ุงุณุงุณูŠุฉ (ุงูุถู„ 8 ูุฑู‚) ููŠ ู…ุณุงุจู‚ุฉ ูƒุฃุณ ุงู„ุนุงู„ู… ู‡ูƒุฑ ูˆู† 2024 ๐Ÿ‡ธ๐Ÿ‡ฆ๐Ÿ’ช Saudi Arabia qualified to group stage with 32 teams and as one of the main teams for the next round (Top 8) ๐Ÿ‡ธ๐Ÿ‡ฆ๐Ÿ’ช #AWC2024

ุงู„ุญู…ุฏู„ู„ู‡ ุชุฃู‡ู„ู†ุง ู…ุน ุงู„32 ูุฑูŠู‚ ุงู„ู‰ ุฏูˆุฑ ุงู„ู…ุฌู…ูˆุนุงุช ูˆุถู…ู† ุงู„ูุฑู‚ ุงู„ุงุณุงุณูŠุฉ (ุงูุถู„ 8 ูุฑู‚) ููŠ ู…ุณุงุจู‚ุฉ ูƒุฃุณ ุงู„ุนุงู„ู… ู‡ูƒุฑ ูˆู†  2024 ๐Ÿ‡ธ๐Ÿ‡ฆ๐Ÿ’ช

Saudi Arabia qualified to group stage with 32 teams and as one of the main teams for the next round (Top 8)  ๐Ÿ‡ธ๐Ÿ‡ฆ๐Ÿ’ช

#AWC2024