Sayedv2 🕷️ (@sayed_v2) 's Twitter Profile
Sayedv2 🕷️

@sayed_v2

Bug Bounty Hunter 🐞 | @hacker0x01

ID: 1734643320452694016

linkhttps://bugcrowd.com/sayedv2 calendar_today12-12-2023 18:36:22

59 Tweet

585 Takipçi

125 Takip Edilen

Sayedv2 🕷️ (@sayed_v2) 's Twitter Profile Photo

I Just Found a Critical Privilege Escalation That Leads to Workspace Takeover From the Owner Hope It will Not be a Duplicate 🫠 #BugBounty

I Just Found a Critical Privilege Escalation That Leads to Workspace Takeover From the Owner 

Hope It will Not be a Duplicate 🫠

#BugBounty
Sayedv2 🕷️ (@sayed_v2) 's Twitter Profile Photo

If i found a pdf that contains Customer name , Full address and his Flight details Is this considered as Sensitive data exposure and the program will accept it ? #hackerone #bugbounty #bugcrowd

If i found a pdf that contains  Customer name , Full address and his Flight details  

Is this considered as Sensitive data exposure and the program will accept it ?

#hackerone #bugbounty #bugcrowd
Sayedv2 🕷️ (@sayed_v2) 's Twitter Profile Photo

I just published How I Discovered Authentication Bypass That Blocks Users from Accessing the Website ? Check it now 🔥🔥 link.medium.com/x3FfaaKwWKb #bugbountytips #BugBounty

Sayedv2 🕷️ (@sayed_v2) 's Twitter Profile Photo

How I Got Easy Account Take Over ? 1- I went to web.archive.org 2. Put the domain i have and search for urls 3. Type in the filter ( %40 ) and search 4. I got a lot of urls that have a parameter leaks the email and password of the users #BugBounty #bugbountytips

How I Got Easy Account Take Over ?

1- I went to web.archive.org 
2. Put the domain i have and search for urls
3. Type in the filter  ( %40 )  and search
4. I got a lot of urls that have a parameter leaks the email and password of the users

#BugBounty #bugbountytips
Sayedv2 🕷️ (@sayed_v2) 's Twitter Profile Photo

- Replace the id in the delete request and send it >> 500 internal server error - Check the victim's account , and the content has been deleted - Don't rely on the status code or the response 🧐 #BugBounty #bugcrowd

- Replace the id in the delete request and send it  >> 500 internal server error 

- Check the victim's account , and the content has been deleted 

- Don't rely on the status code or the response 🧐

#BugBounty #bugcrowd
conqueror - Ahmed Qaramany (@c0nqr0r) 's Twitter Profile Photo

It’s been a while since I last posted any write-ups. I felt there was value in focusing on manual testing for IDOR and Access Control bugs, so I quickly put this one together. #bugbounty #bugbountytips c0nqr0r.medium.com/idor-and-broke…

It’s been a while since I last posted any write-ups. I felt there was value in focusing on manual testing for IDOR and Access Control bugs, so I quickly put this one together. #bugbounty #bugbountytips 

c0nqr0r.medium.com/idor-and-broke…
Sayedv2 🕷️ (@sayed_v2) 's Twitter Profile Photo

I'm excited to share a recent business logic vulnerability I discovered in a public bug bounty program. Here is the writeup : sayedv2.medium.com/business-logic… #bugbounty #cybersecurity

conqueror - Ahmed Qaramany (@c0nqr0r) 's Twitter Profile Photo

الحلقة الرابعه مع Souhaib Naceri H4x0r.DZ 🇰🇵 واتكلمنا فيها عن حاجات كتير وتجربتة في الوصول لـ LHE بتاع هاكرون وفيه نصايح جداً مهمة لتطوير مستواك، وحاجات تانية كتير تقدر تشوفها من هنا : youtu.be/uuxACNbB6Zk #BugBounty

الحلقة الرابعه مع Souhaib Naceri  <a href="/h4x0r_dz/">H4x0r.DZ 🇰🇵</a>  واتكلمنا فيها عن حاجات كتير وتجربتة في الوصول لـ LHE بتاع هاكرون وفيه نصايح جداً مهمة لتطوير مستواك، وحاجات تانية كتير تقدر تشوفها من هنا : 
youtu.be/uuxACNbB6Zk

#BugBounty
Sayedv2 🕷️ (@sayed_v2) 's Twitter Profile Photo

I just published a write-up on how I bypassed team member limits on a bug bounty program by exploiting two race conditions! 💥 Writeup link : sayedv2.medium.com/double-race-co… #BugBounty #bugbountytips

I just published a write-up on how I bypassed team member limits on a bug bounty program by exploiting two race conditions! 💥

Writeup link : sayedv2.medium.com/double-race-co…

#BugBounty #bugbountytips
Sayedv2 🕷️ (@sayed_v2) 's Twitter Profile Photo

Is this normal ? I can do unauthorized actions even after being logged out and the request is valid for 24 hours before the token expiration. And this is their response after the report being triaged from bug crowd staff and they marked this as NA . bugcrowd #bugbounty

Is this normal ? 
I can do unauthorized actions even after being logged out and the request is valid for 24 hours before the token expiration.

And this is their response after the report being triaged from bug crowd staff and they marked this as NA . 

<a href="/Bugcrowd/">bugcrowd</a> 

#bugbounty
dia2diab (@dia2diab) 's Twitter Profile Photo

A few shots from our latest HackerOne Egypt 🇪🇬 Club meetup! Amazing turnout, great hacking sessions, career discussions, and tons of knowledge sharing. Thanks to everyone who showed up!

A few shots from our latest <a href="/Hacker0x01/">HackerOne</a> Egypt 🇪🇬 Club meetup! Amazing turnout, great hacking sessions, career discussions, and tons of knowledge sharing.

Thanks to everyone who showed up!