Ayubali (@0xayub) 's Twitter Profile
Ayubali

@0xayub

Security Enthusiast | Web and Mobile Apps | Open Source ❣️

ID: 1275062276790218762

linkhttps://0xayub.gitbook.io/blog/ calendar_today22-06-2020 13:45:28

335 Tweet

311 Followers

232 Following

­Mathias Karlsson (@avlidienbrunn) 's Twitter Profile Photo

After being nerd sniped by this, and discussion with Frans Rosén, heres two alternative ways: x(""+{a:location=name}+"") x(""+new class b{toString=e=>location=name}+"")

ProjectDiscovery (@pdiscoveryio) 's Twitter Profile Photo

Despite what many think, Nuclei isn't limited to basic HTTP requests. In fact, it's not even limited to HTTP! ⚛️ 🌀 Using its features effectively allows for broader scans beyond web servers. Learn how to go beyond HTTP 👇 #HackwithAutomation blog.projectdiscovery.io/nuclei-beyond-…

Jason Haddix (@jhaddix) 's Twitter Profile Photo

Check out my friend Lupin and his new 🔥 video going over attacking UUIDs and the "Sandwich Attack" youtube.com/watch?v=Wgo3bG… 💪

payloadartist (@payloadartist) 's Twitter Profile Photo

🔥 OAuth "token reuse" vulnerability An interesting OAuth attack technique by Aviad Carmel that reused OAuth tokens from a different app to fully takeover victim's account in many popular apps like Grammarly salt.security/blog/oh-auth-a… #bugbountytips #bugbounty #cybersecurity

🔥  OAuth "token reuse" vulnerability 

An interesting OAuth attack technique by <a href="/AviadCarmel/">Aviad Carmel</a> that reused OAuth tokens from a different app to fully takeover victim's account in many popular apps like Grammarly  

salt.security/blog/oh-auth-a…

#bugbountytips #bugbounty #cybersecurity
Majd (@majd_alfhaily) 's Twitter Profile Photo

Bhavuk Jain Yep, it’s a pretty neat feature offered by GitHub as part of the Secret Scanning Partner Program. AWS, Microsoft, Google and Slack are part of it. docs.github.com/en/code-securi…

Lupin (@0xlupin) 's Twitter Profile Photo

If you ever do static analysis on Android applications that are compiled with React you'll need to read the code of the assets/index.​android.​bundle file. However this file is a Hermes JavaScript binary that needs to be decompiled. This tool saved my life:

OSINT 🪙 (@0xtechrock) 's Twitter Profile Photo

OSINT TIP #246 🐛 Tired of googling for #BugBounty writeups, payloadartist made a little tool "Bug Bounty Hunting Search Engine" that lets you search writeups easily. BugBountyHunting.com Thanks for tip Rohit Kumar 👏🏻 #OSINT #cybersecurity #bugbountytips #infosec

OSINT TIP #246 🐛

Tired of googling for #BugBounty writeups,  <a href="/payloadartist/">payloadartist</a> made a little tool "Bug  Bounty Hunting Search Engine" that lets you search writeups easily.

BugBountyHunting.com

Thanks for tip <a href="/0xloooser/">Rohit Kumar</a> 👏🏻

#OSINT #cybersecurity #bugbountytips #infosec
7h3h4ckv157 (@7h3h4ckv157) 's Twitter Profile Photo

Hey, hackers! 👋🏻 I hope this note is bookmarked on your belt! It contains awesome pdfs including: - Red team Operations - Reverse engineering content - Red Team x Blue team - Practical social engineering - Windows Privilege escalation - AD, & Road to OSCP - JR to

Hey, hackers! 👋🏻

I hope this note is bookmarked on your belt! 
It contains awesome pdfs including: 

- Red team Operations
- Reverse engineering content
- Red Team x Blue team
 - Practical social engineering
- Windows Privilege escalation 
- AD, &amp; Road to OSCP 
- JR to
shubs (@infosec_au) 's Twitter Profile Photo

Over 400 stars on Surf (github.com/assetnote/surf) - thank you so much for the support! I find that this tool leads to critical SSRF discoveries, despite its simplicity. I hope everyone has a happy holidays. I can't wait to release even more tooling and research in 2024.

Brut 🇮🇳 (@wtf_brut) 's Twitter Profile Photo

🚨40,000+ Nuclei templates for security scanning and detection across diverse web applications and services🚨 📥github.com/linuxadi/40k-n… #bugbountytip #bugbountytips #ethicalhacking #CyberSecurity #Pentesting #sqli #xss #CyberSecurityAwareness #bugbounty #ssrf #AEM

iFenix (@dlymension) 's Twitter Profile Photo

puaf_landa, a new kfd Exploit..!! 🔥🔥 iOS 16.6.1 and 17.0 betas! ✅ "This exploit is useful for jailbreaks as well as a trollstore installation method." github.com/felix-pb/kfd #Jailbreak #iOS16 #iOS17 #kfd #exploit #puaf_landa

shubs (@infosec_au) 's Twitter Profile Photo

At Assetnote, we focused on building a comprehensive set of exploits for the recent Ivanti Pulse Connect Secure vulnerabilities (CVE-2023-46805 & CVE-2024-21887. We found an additional auth bypass payload that works on older versions of the software: assetnote.io/resources/rese…

At <a href="/assetnote/">Assetnote</a>, we focused on building a comprehensive set of exploits for the recent Ivanti Pulse Connect Secure vulnerabilities (CVE-2023-46805 &amp; CVE-2024-21887. We found an additional auth bypass payload that works on older versions of the software: assetnote.io/resources/rese…