Shebiiiii (@xshebix) 's Twitter Profile
Shebiiiii

@xshebix

Cyber Security Researcher - Red Team Member at Synack

ID: 802627943235289089

calendar_today26-11-2016 21:39:48

3,3K Tweet

671 Takipçi

3,3K Takip Edilen

Lupin (@0xlupin) 's Twitter Profile Photo

XSS with no parenthesis 🔥 Thanks to Justin Gardner for sending me this target with a really weird filter. It was a fun challenge 🤟 Btw I'm not the one that discovered the use of instanceof for XSS ;) #bugbountytips

XSS with no parenthesis 🔥

Thanks to <a href="/Rhynorater/">Justin Gardner</a> for sending me this target with a really weird filter. It was a fun challenge 🤟

Btw I'm not the one that discovered the use of instanceof for XSS ;)

#bugbountytips
Mohamed Anani (@0xm5awy) 's Twitter Profile Photo

Good morning! I've been using this payload for over a year to discover XSS via open redirect vulnerabilities that bypass WAF. It works great: :DD Payload: javascript%3avar{a%3aonerror}%3d{a%3aalert}%3bthrow%2520document.cookie #BugBounty #bugbountytips #bugbountytip

Good morning! I've been using this payload for over a year to discover XSS via open redirect vulnerabilities that bypass WAF. It works great: :DD

Payload: javascript%3avar{a%3aonerror}%3d{a%3aalert}%3bthrow%2520document.cookie

#BugBounty #bugbountytips #bugbountytip
🇸🇦 ROOD | GOAT (@0x_rood) 's Twitter Profile Photo

If you found /actuator/jolokia/ endpoint in your target you can escalate it to LFI POC: https://target[.]com/actuator/jolokia/exec/com.sun.management:type=DiagnosticCommand/compilerDirectivesAdd/!/etc!/passwd

Abdullah Nawaf (HackerX007)🇯🇴 (@xhackerx007) 's Twitter Profile Photo

we earned $20,000 for Our submission on @bugcrowd Tuan Anh Nguyen⚡️ 🇻🇳 Godfather Orwa 🇯🇴 It's nice to work with you guys :) #Tip: Always check `viewstate` In Asp. Net More Info : notsosecure.com/exploiting-vie… bugcrowd.com/hackerx007 #ItTakesACrowd

Rana Khalil 🇵🇸 (@rana__khalil) 's Twitter Profile Photo

It’s been tough being on social media the past couple of days. My own family, like thousands of Palestinians, was ethnically cleansed by Israel 75 years ago, and was denied the right of return to Palestine. For 75 years, Israel has forcibly displaced entire Palestinian

Ayoub FATHI 阿尤布 (@_ayoubfathi_) 's Twitter Profile Photo

I’ve published the slides for my Security BSides Ahmedabad closing keynote: bit.ly/pwning-cloud-c… In this talk, I shared: “Lateral movement brute forcing” — a new technique that I covered and used against different targets to go, eg. From a limited GitHub token to achieve multi-lateral

Godfather Orwa 🇯🇴 (@godfatherorwa) 's Twitter Profile Photo

مات الطبيب و المسعف و الجريح كل ذنبك يا فلسطين انك جميله كسيدنا يوسف و العالم خانك مثل اخوته

مات الطبيب  و المسعف و الجريح 

كل ذنبك يا فلسطين انك جميله كسيدنا يوسف 
و العالم خانك مثل اخوته
Vitor Falcão "busfactor" (@busf4ctor) 's Twitter Profile Photo

Most people believe SQL injections are in the past. They say it's hard to find them. The main issue is the use of automated tools like SQLMap. I'll go through the reasons in this thread so you can give your opinions.

0xblackbird (@0xblackbird) 's Twitter Profile Photo

Still haven't found your first SSRF vulnerability? Or only found a useless blind SSRF somewhere but couldn't get to escalate it? You're probably looking at the wrong place... Here, a mega-thread on Server-Side Request Forgeries (SSRF) vulnerabilities👇️

Still haven't found your first SSRF vulnerability?

Or only found a useless blind SSRF somewhere but couldn't get to escalate it?

You're probably looking at the wrong place...

Here, a mega-thread on Server-Side Request Forgeries (SSRF) vulnerabilities👇️
shay (@shaybt12) 's Twitter Profile Photo

you found Jfrog URL and you get 403 / 401 ? try to add /ui/repos/tree/General mabye you get lucky and found nuget / other compile customer source code :)

you found Jfrog URL
and you get 403 / 401 ?
try to add

/ui/repos/tree/General

mabye you get lucky and found nuget / other compile customer source code :)
Paul Seekamp (@nullenc0de) 's Twitter Profile Photo

TanmayLP If you are running automated scanners. This is about 95-98% of the things that are missed. Also, if you want to make a name for yourself in BB or web app pentest world. Get really good at these.

<a href="/TanmayLP7/">TanmayLP</a> If you are running automated scanners. This is about 95-98% of the things that are missed. 

Also, if you want to make a name for yourself in BB or web app pentest world. Get really good at these.
Lu3ky13 ⚡️⚡️ (@lu3ky13) 's Twitter Profile Photo

Bypass Reset Password Code Lead to Account Takeover hackerone.com/reports/2383052 GitHub python script github.com/Lu3ky13/Bypass… #bugbountytips #bugbounty

Ahmed Elmorsi 🇵🇸 (@0xhunterx) 's Twitter Profile Photo

This Writeup exaplains how we got ATO from Android Application medium.com/@ahmedelmorsy3… #BugBounty #bugbountytip #cybersecuritytips #hackerone

Nikhil Mittal (@nikhil_mitt) 's Twitter Profile Photo

🚨 I am giving away 1 seat each of our June Red team (CRTP) and Azure (CARTP) bootcamps. 🚨 Repost, like and reply to this tweet to participate. I will announce the winners on Monday (27th May). alteredsecurity.com/bootcamps #redteam #pentest #giveaway

🚨 I am giving away 1 seat each of our June Red team (CRTP) and Azure (CARTP) bootcamps. 🚨

Repost, like and reply to this tweet to participate. I will announce the winners on Monday (27th May). 

alteredsecurity.com/bootcamps

#redteam #pentest #giveaway
KNOXSS (@kn0x55) 's Twitter Profile Photo

🚨 KNOXSS GIVEAWAY July 2025 ✅ Follow us ✅ Like and share this 🎁 Prize: KNOXSS Pro for 1 Month 🏆 Results: July 7th (3 winners) Want to find some vulns? Get one of our plans and test for #XSS consistently. Sign up now! 😀 knoxss.pro #BugBounty #PenTesting

🚨 KNOXSS GIVEAWAY July 2025

✅ Follow us
✅ Like and share this

🎁 Prize: KNOXSS Pro for 1 Month 

🏆 Results: July 7th (3 winners)

Want to find some vulns?
Get one of our plans and test for #XSS consistently.

Sign up now! 😀 knoxss.pro

#BugBounty #PenTesting