Jafar Abo Nada (@jafar_abo_nada) 's Twitter Profile
Jafar Abo Nada

@jafar_abo_nada

information security specialist
Co-founder & CEO at @Updatelap

hackerone.com/Updatelap
bugcrowd.com/Updatelap

ID: 1056005681134923776

linkhttps://www.youtube.com/c/Updatelap calendar_today27-10-2018 02:12:28

194 Tweet

1,1K Followers

321 Following

Ahmad Halabi (@ahmad_halabi_) 's Twitter Profile Photo

I released an article talking about my bug bounty journey, how I ranked 1st in U.S. DoD and how I reached top 100 hackers on HackerOne. Sharing also resources, tips and advices to become a better bug bounty hunter. medium.com/@ahmdhalabi/my…

Jafar Abo Nada (@jafar_abo_nada) 's Twitter Profile Photo

Thanks God, I Got Acknowledgement by Apple Security Team After discovering a security issue in one of the Apple site. بفضل من الله، حصلت على أعتراف من الفريق الامني في شركة Apple بعد أبلاغي عن خلل أمني في أحد تطبيقات شركة Apple. Apple HOF: support.apple.com/en-us/HT201536 #BugBounty

Thanks God, I Got Acknowledgement by Apple Security Team After discovering a security issue in one of the Apple site.

بفضل من الله، حصلت على أعتراف من الفريق الامني في شركة Apple بعد أبلاغي عن خلل أمني في أحد تطبيقات شركة Apple.

Apple HOF: support.apple.com/en-us/HT201536

#BugBounty
Jafar Abo Nada (@jafar_abo_nada) 's Twitter Profile Photo

Thanks god, Extremely happy and Proud to Announce that listed me at 8 in the world the "bugcrowd Leaderboard" for the month of december/2020. #bugbounty

Thanks god, Extremely happy and Proud to Announce that listed me at 8 in the world the "<a href="/Bugcrowd/">bugcrowd</a> Leaderboard" for the month of december/2020. 

#bugbounty
Jafar Abo Nada (@jafar_abo_nada) 's Twitter Profile Photo

Thank God, I Got Acknowledgement by HackerOne After I discovered a bug in the integration process on H1 platform. The #bug found as a result of a mistake in authorizations configuration. which leads to the leakage of the JWT Token to unauthorized user Big Thanks: Jobert Abma

Thank God, I Got Acknowledgement by <a href="/Hacker0x01/">HackerOne</a> After I discovered a bug in the integration process on  H1 platform. The #bug found as a result of a mistake in authorizations configuration. which leads to the leakage of the JWT Token to unauthorized user

Big Thanks: <a href="/jobertabma/">Jobert Abma</a>
Jafar Abo Nada (@jafar_abo_nada) 's Twitter Profile Photo

Thanks god, Extremely happy and Proud to Announce that Listed on #TOP_10 at bugcrowd Leaderboard for the month of March/2020. الحمد لله، بعد توفيق من الله وشهر مليء بالمنافسة، فخور بإدراجي ضمن ال Top_10 في [Bugcrowd Leaderboard] لشهر مارس bugcrowd.com/leaderboard

Thanks god, Extremely happy and Proud to Announce that Listed on #TOP_10 at <a href="/Bugcrowd/">bugcrowd</a> Leaderboard for the month of March/2020.

الحمد لله، بعد توفيق من الله وشهر مليء بالمنافسة، فخور بإدراجي ضمن ال Top_10 في [Bugcrowd Leaderboard] لشهر مارس 

bugcrowd.com/leaderboard
Jafar Abo Nada (@jafar_abo_nada) 's Twitter Profile Photo

HackerOne Jira integration plugin Leaked JWT to unauthorized Jira users. Bounty: $3,000 #hackerone #bugbounty hackerone.com/reports/1103582

Jafar Abo Nada (@jafar_abo_nada) 's Twitter Profile Photo

This is exploit bug that I discovered in jira PoC CVE-2020-36287 Brute Force <GadgetId> start from 10000 to 19999 {BaseUrl}/rest/dashboards/1.0/10000/gadget/<GadgetId>/prefs If server response 401 bug Fixed, If the server's response is 200, the response will contain XML data

This is exploit bug that I discovered in jira

PoC CVE-2020-36287 

Brute Force &lt;GadgetId&gt; start from 10000 to 19999

{BaseUrl}/rest/dashboards/1.0/10000/gadget/&lt;GadgetId&gt;/prefs

If server response 401 bug Fixed, If the server's response is 200, the response will contain XML data
Jafar Abo Nada (@jafar_abo_nada) 's Twitter Profile Photo

Rank 5th at🛡️[Atlassian bug bounty program]🛡️ Thanks god, Extremely happy and Proud to Announce that I have been listed at the #TOP_10 security researchers in the world on [Atlassian Hall Of Fame] MY BC Account: bugcrowd.com/UpdateLap #BugBounty #bug

Rank 5th at🛡️[Atlassian bug bounty program]🛡️

Thanks god, Extremely happy and Proud to Announce that I have been listed at the #TOP_10 security researchers in the world on [<a href="/Atlassian/">Atlassian</a> Hall Of Fame]

MY BC Account: bugcrowd.com/UpdateLap

#BugBounty #bug
Jafar Abo Nada (@jafar_abo_nada) 's Twitter Profile Photo

Thank god, I am proud to be [Ranked 5th] in the world among the #Top_10 security researchers in the month of [May/2021] on the [Bugcrowd Leaderboard] Check out the bugcrowd top 10: bugcrowd.com/leaderboard MY BC Account: bugcrowd.com/UpdateLap #kickass #ItTakesACrowd

Thank god, I am proud to be [Ranked 5th] in the world among the #Top_10 security researchers in the month of [May/2021] on the [Bugcrowd Leaderboard]

Check out the <a href="/bugcrowd/">bugcrowd</a> top 10: bugcrowd.com/leaderboard
MY BC Account:
bugcrowd.com/UpdateLap

#kickass #ItTakesACrowd
bugcrowd (@bugcrowd) 's Twitter Profile Photo

Congratulations to October's Top 10 Hackers! 🏆 1️⃣ mert 2️⃣ private user 3️⃣ todayisnew 4️⃣ ZwinK 5️⃣ UpdateLap 6️⃣ sws_jk 7️⃣ vfial 8️⃣ DDV_UA 9️⃣ m0x_noob 🔟 VINOTHKUMAR Can't stop, won't stop 😎

Congratulations to October's Top 10 Hackers! 🏆

1️⃣ mert
2️⃣ private user 
3️⃣ todayisnew
4️⃣ ZwinK
5️⃣ UpdateLap
6️⃣ sws_jk
7️⃣ vfial
8️⃣ DDV_UA
9️⃣ m0x_noob
🔟 VINOTHKUMAR

Can't stop, won't stop 😎
Godfather Orwa 🇯🇴 (@godfatherorwa) 's Twitter Profile Photo

Hello everyone ♥ a little bit write-up of #bugbountytip #bugbountytips I am going to write here ..... Title: getting unauthorized access on 3rd party's/workspaces & and building your checklist for quickly locating bugs there via massive recon we know that its helpful to look

Hello everyone ♥
a little bit write-up of #bugbountytip #bugbountytips I am going to write here ..... 

Title:
getting unauthorized access on 3rd party's/workspaces &amp; and building your checklist for quickly locating bugs there via massive recon

we know that its helpful to look
Abdullah Nawaf (HackerX007)🇯🇴 (@xhackerx007) 's Twitter Profile Photo

My talk at Ahmedabad BSides is now live on YouTube! I hope you find it informative and packed with fresh tips and tricks to support the bug bounty community! #bugbountytips #bsidesahmedabad #AuthenticationBypass #BypassTechniques #WebSecurity #WebAppSec #Vulnerability

Godfather Orwa 🇯🇴 (@godfatherorwa) 's Twitter Profile Photo

Video of my talking in #PHDays at PT Security youtu.be/CJnXjWXXB1Y?si… Hope you like it and enjoy it #bugbounty #bugbountytip #bugbountytips #infosec