Firas 🐘 (@retkoussa) 's Twitter Profile
Firas 🐘

@retkoussa

The Cyber Lieutenant. πŸ‡±πŸ‡§ SecOps @Fortinet

ID: 1430278299926810630

calendar_today24-08-2021 21:18:22

335 Tweet

331 Followers

102 Following

Firas 🐘 (@retkoussa) 's Twitter Profile Photo

IDOR triaged around one month later πŸš€ Tip: exhaust all your options on a single program if the scope is big enough πŸ•Ί #BugBounty #idor

IDOR triaged around one month later πŸš€ 

Tip: exhaust all your options on a single program if the scope is big enough πŸ•Ί

#BugBounty #idor
Firas 🐘 (@retkoussa) 's Twitter Profile Photo

I have wrote a comprehensive source code review and exploitation, delving into the details of - CVE-2023-32243: WordPress Account Takeover via Essential Addons Plugin for Elementor Thanks to RandomRobbieBF for the script πŸƒβ€β™‚οΈ Enjoy! medium.com/@retkoussa/cve… #cve_2023_32243

Jason Haddix (@jhaddix) 's Twitter Profile Photo

OWASP LLM Top Ten v.1: πŸš€ Prompt Injections πŸ’§ Data Leakage πŸ–οΈ Inadequate Sandboxing πŸ“œ Unauthorized Code Execution 🌐 SSRF Vulnerabilities βš–οΈ Overreliance on LLM-generated Content 🧭 Inadequate AI Alignment 🚫 Insufficient Access Controls ⚠️ Improper Error Handling πŸ’€ Training

Firas 🐘 (@retkoussa) 's Twitter Profile Photo

I've seen a lot of posts recently about the DuckDuckGo tracker radar. Here's a POC that will help you pull up subdomains for domains in their records, or pull the domains with their subdomains. Code is still a POC - feel free to modify it. #bugbounty github.com/retkoussa/ddg-…

Firas 🐘 (@retkoussa) 's Twitter Profile Photo

🚨Resolving domains in an ASN Sharing useful snippets I develop when hunting. github.com/retkoussa/asn2… #bugbounty #bugbountytips #pentesting #recon #enumeration

🚨Resolving domains in an ASN
Sharing useful snippets I develop when hunting.

github.com/retkoussa/asn2…

#bugbounty #bugbountytips #pentesting #recon #enumeration
Firas 🐘 (@retkoussa) 's Twitter Profile Photo

If you don't know, I've been developing SaaS with AI (oooh, buzz word) for around 1-2 years now. 17 failed products. 2 with steady MRR and 1 free one. They all run on 95% autopilot. Here's the free one I built. islamdaily.app #microsaas #saas #nocode #ai #mrr

Firas 🐘 (@retkoussa) 's Twitter Profile Photo

450+ members in 2 days. 99% automated software with a huge audience Speaking of organic.. lol! islamdaily.app #saas #nocode #ai #automation #bots

450+ members in 2 days. 

99% automated software with a huge audience

Speaking of organic.. lol!

islamdaily.app

#saas #nocode #ai #automation #bots
shubs (@infosec_au) 's Twitter Profile Photo

IP whitelisting is fundamentally broken. At Assetnote, we've successfully bypassed network controls by routing traffic through a specific location (cloud provider, geo-location). Today, we're releasing Newtowner, to help test for this issue: github.com/assetnote/newt…

BREAD | βˆ‘: (@0xbreadguy) 's Twitter Profile Photo

> Hack X account > Open large short on token > Announce the blockchain is shutting down (???) > Profit Easier than drainer links in 2025

> Hack X account
> Open large short on token
> Announce the blockchain is shutting down (???)
> Profit

Easier than drainer links in 2025
GangExposed RU (@gangexposed_ru) 's Twitter Profile Photo

🚨 Devman RaaS leak. Internal affiliate chats, victim access, micromanagement β€” and classic bad OPSEC πŸ€¦β€β™‚οΈ Analysis: ctrlaltint3l.github.io/threat%20resea…