Ahmed Tarek (@0x_xnum) 's Twitter Profile
Ahmed Tarek

@0x_xnum

⚛️

ID: 1675100760508452866

linkhttp://0xxnum.fun calendar_today01-07-2023 11:15:52

38 Tweet

606 Followers

57 Following

Ahmed Tarek (@0x_xnum) 's Twitter Profile Photo

I found a sensitive data exposure TIP: Always check JS files for endpoints using linkfinder or you also try this regex: (?<=(\"|\'|\`))\/[a-zA-Z0-9_?&=\/\-\#\.]*(?=(\"|\'|\`)) if you didn't find much, don't forget to fuzz #BugBounty #bugbountytips

I found a sensitive data exposure 

TIP: Always check JS files for endpoints using linkfinder or you also try this regex: 
(?&lt;=(\"|\'|\`))\/[a-zA-Z0-9_?&amp;=\/\-\#\.]*(?=(\"|\'|\`))
if you didn't find much, don't forget to fuzz #BugBounty #bugbountytips
Ahmed Tarek (@0x_xnum) 's Twitter Profile Photo

I found a Full Account Takeover via Facebook OAuth Misconfiguration More details: medium.com/@0x_xnum/full-… #BugBounty #bugbountytip #bugbountytips #bugcrowd

Ahmed Tarek (@0x_xnum) 's Twitter Profile Photo

Just added a new section to my GitBook: "Attack Vectors by Port" – a quick methodology on what you can do with each open port and its services. Check it out : ahmed-tarek.gitbook.io/sec-notes/net-… #bugbountytips #BugBounty #CyberSecurity

Ahmed Tarek (@0x_xnum) 's Twitter Profile Photo

Just dropped a new write-up about the latest privilege escalation I found check it out : medium.com/@0x_xnum/privi… #bugbountytips #bugbounty #bugcrowd #hackerone

Ahmed Tarek (@0x_xnum) 's Twitter Profile Photo

hunting solo gets kinda boring. So if anyone's up for a collab to share tips or whatever just hit me up #BugBounty #bugbountytips #bugcrowd

Ahmed Tarek (@0x_xnum) 's Twitter Profile Photo

Been studying Active Directory attacks lately and wrote some notes. Hope it helps someone out there ahmed-tarek.gitbook.io/0x_xnum/ad-pen #BugBounty #BugBountytip #bugcrowd #hackerone #pentesting

Ahmed Tarek (@0x_xnum) 's Twitter Profile Photo

Got back after a break TIP : If UI says no, Intercept the request, backend might say yes. #BugBounty #bugbountytip #bugcrowd

Got back after a break  

TIP : If UI says no, Intercept the request, backend might say yes.
#BugBounty #bugbountytip #bugcrowd
Ahmed Tarek (@0x_xnum) 's Twitter Profile Photo

I earned $700 for my submission on @bugcrowd #ItTakesACrowd TIP: Don't assume UUIDs are secure, check if it's using UUIDv1 you can easily brute force it

I earned $700 for my submission on @bugcrowd #ItTakesACrowd
TIP: Don't assume UUIDs are secure, check if it's using UUIDv1 you can easily brute force it