Assem Ragab (@marsxc0) 's Twitter Profile
Assem Ragab

@marsxc0

أرق م أني أوصف نفسي في كلمتين🚫

ID: 1633822676023234562

calendar_today09-03-2023 13:31:27

25 Tweet

39 Followers

277 Following

Fady Othman (@fady_othman) 's Twitter Profile Photo

#bugbountytips You don't need to write a bash script to fuzz multiple URLs with ffuf, you can simply do ffuf -w urls.txt:URL -w wordlist:FUZZ -u URL/FUZZ You can also omit the / if your URL list already has slashes ;)

🇸🇦 ROOD | GOAT (@0x_rood) 's Twitter Profile Photo

Sql injection is not necessary inject at payload, You can inject in path Path: /en/gallery/1 POC: en/gallery/1'XOR(if(now()=sysdate(),sleep(3),0))OR' #bugbountytips #bugbounty

Sql injection is not necessary inject at payload,
You can inject in path

Path: /en/gallery/1
POC: en/gallery/1'XOR(if(now()=sysdate(),sleep(3),0))OR'

#bugbountytips #bugbounty
Omar Atallah 🇵🇸 (@omar_j_ahmed) 's Twitter Profile Photo

I just published IDOR vulnerability allow attacker to make a checkout order on behalf of other users link.medium.com/W2D3rlSmVKb #BugBounty #bugbountytip #security #Hacking

RootMoksha Labs (@rootmoksha) 's Twitter Profile Photo

url/?f=etc/passwd ==> 403 encode etc/passwd as base64 url/?f=L2V0Yy9wYXNzd2Q= ==> 200 #note you can use this trick in SQL , SSTI , XSS , LFI , Etc... By:Godfather Orwa 🇯🇴 #bugbountytips #BugBounty

url/?f=etc/passwd ==> 403
encode etc/passwd as base64

url/?f=L2V0Yy9wYXNzd2Q=  ==> 200

#note 
you can use this trick in SQL , SSTI , XSS , LFI , Etc...

By:<a href="/GodfatherOrwa/">Godfather Orwa 🇯🇴</a>

#bugbountytips #BugBounty
🇪🇨🍫 (@bxmbn) 's Twitter Profile Photo

What is this 😭 username=bombon&password=undefined 200 OK username=AnyUser&password=undefined 200 Ok It gives you the access token just by providing the username and requesting the password as ‘undefined’ letting you to basically authenticate to any account..

What is this 😭

username=bombon&amp;password=undefined

200 OK

username=AnyUser&amp;password=undefined

200 Ok

It gives you the access token just by providing the username and requesting the password as ‘undefined’ letting you to basically authenticate to any account..
Muhammed (@muh404med) 's Twitter Profile Photo

@marsxc0 and I found a critical bug in a program with 800+ reports Tip: Study from a user’s perspective and take time to convince the triager of the bug’s priority—it can shift from “Not Applicable” to P1 continued.. @bugcrowd #ItTakesACrowd #bugbountytips #bugbounty #bugcrowd

@marsxc0 and I found a critical bug in a program with 800+ reports

Tip: Study from a user’s perspective and take time to convince the triager of the bug’s priority—it can shift from “Not Applicable” to P1

continued..

@bugcrowd #ItTakesACrowd #bugbountytips #bugbounty #bugcrowd
يـاســـمــين رزق (@yasmeena_rezk) 's Twitter Profile Photo

امبارح كنت بفكر في مدى خطورة إن أولادي إن شاء الله في وقت الغرس بيشوفوا العالم بعيوني أنا أسأل الله أن يهديني ويسددني

Assem Ragab (@marsxc0) 's Twitter Profile Photo

Reached a new achievement 🏆 Top 5 spot on Twilio’s 2024 vulnerability leaderboard with 12 valid submissions! A special thanks to twilio and bugcrowd for their continued support of the security research community. #bugbounty #infosec #cybersecurity #twilio #bugcrowd

Reached a new achievement 🏆
Top 5 spot on Twilio’s 2024 vulnerability leaderboard with 12 valid submissions!

A special thanks to <a href="/twilio/">twilio</a> and <a href="/Bugcrowd/">bugcrowd</a> for their continued support of the security research community.

#bugbounty #infosec #cybersecurity #twilio #bugcrowd