Muhammad Aamir πŸ‡΅πŸ‡° (@muhammad__aamir) 's Twitter Profile
Muhammad Aamir πŸ‡΅πŸ‡°

@muhammad__aamir

CISSP | Cybersecurity | Applications' bug hunter | Info sec researcher | Father | Aiming for more travel and peace!

ID: 952481510241767424

calendar_today14-01-2018 10:04:23

528 Tweet

990 Followers

688 Following

Muhammad Aamir πŸ‡΅πŸ‡° (@muhammad__aamir) 's Twitter Profile Photo

For liked hackers, this kind of misconfig is also a security issue? For any newbie, the same submission would've been marked as NA or at max Informational.

Muhammad Aamir πŸ‡΅πŸ‡° (@muhammad__aamir) 's Twitter Profile Photo

Hi folks! This tip doesn't get old. Recently found RXSS on Password Reset UI of a gaming website πŸ”₯ #bugbountytips #bugbountytip #CyberSecurity #ethicalhacking

Muhammad Aamir πŸ‡΅πŸ‡° (@muhammad__aamir) 's Twitter Profile Photo

AL HAMD U LILLAH bugcrowd Privilege escalation to compromise Confidentiality! While observing account management features, check whether revised permissions of low privileged users continue to access high privileged services. #bugbountytips #ethicalhacking #CyberSecurity

AL HAMD U LILLAH <a href="/Bugcrowd/">bugcrowd</a> 

Privilege escalation to compromise Confidentiality!

While observing account management features, check whether revised permissions of low privileged users continue to access high privileged services.

#bugbountytips #ethicalhacking #CyberSecurity
APIsec University (@apisecu) 's Twitter Profile Photo

10k Followers GIVEAWAY! Thank you to all 10k of our followers for joining us on an API Security journey πŸ’ͺ To celebrate, we will be giving away 5 FREE ASCP exams! All you have to do is retweet this post before Friday πŸ₯³

Muhammad Aamir πŸ‡΅πŸ‡° (@muhammad__aamir) 's Twitter Profile Photo

AL HAMD U LILLAH bugcrowd $200 bounty for a med risk issue found in testing of the site's 2FA authentication. Keep an eye on the gaps of authentication flow. #bugbounty #cybersecurity #ethicalhacking

AL HAMD U LILLAH
<a href="/Bugcrowd/">bugcrowd</a> 

$200 bounty for a med risk issue found in testing of the site's 2FA authentication.

Keep an eye on the gaps of authentication flow.

#bugbounty #cybersecurity #ethicalhacking
Muhammad Aamir πŸ‡΅πŸ‡° (@muhammad__aamir) 's Twitter Profile Photo

BugBounty Tip specially for new hunters; In addition to looking for common vulns, get deep understanding of application's logic & functionalities. You may find logic & flows that carry security risk by design. They're worth reporting :) #bugbountytip #CyberSecurity #bugcrowd

BugBounty Tip specially for new hunters; In addition to looking for common vulns, get deep understanding of application's logic &amp; functionalities. You may find logic &amp; flows that carry security risk by design. They're worth reporting :)
#bugbountytip #CyberSecurity #bugcrowd
Muhammad Aamir πŸ‡΅πŸ‡° (@muhammad__aamir) 's Twitter Profile Photo

New writeup after a long time. I hope that it would be helpful especially for new bug hunters and pen testers! #cybersecurity #ethicalhacking #bugbounty muhammad-aamir.medium.com/2fa-secret-can…

Muhammad Aamir πŸ‡΅πŸ‡° (@muhammad__aamir) 's Twitter Profile Photo

AL HAMD U LILLAH Research bugcrowd ... Finding a valid issue that got rewarded. It's good to be back and starting with some success! πŸ’š Downgraded privilege from admin to normal, some actions could still be performed. #bugbounty #cybersecurity #ethicalhacking #bugbountytips

AL HAMD U LILLAH
Research <a href="/Bugcrowd/">bugcrowd</a> ... Finding a valid issue that got rewarded. It's good to be back and starting with some success! πŸ’š
Downgraded privilege from admin to normal, some actions could still be performed.
#bugbounty #cybersecurity #ethicalhacking #bugbountytips
Jason Haddix (@jhaddix) 's Twitter Profile Photo

⚠️ Giveaway time! ⚠️ πŸ‘‡ πŸ“’ Our new course "Attacking AI" will be Feb 27-28! This two-day course equips security professionals with the tools and methodologies to identify vulnerabilities in AI systems. It's gonna be a BANGER. Syllabus: payhip.com/b/2qPZ1 We are giving

Muhammad Aamir πŸ‡΅πŸ‡° (@muhammad__aamir) 's Twitter Profile Photo

Bounty $200 ✌️ Try accessing all endpoints to find what is different at the backend as compared to the authenticated front end βœ”οΈ #bugbounty #cybersecurity #appsec #ethicalhacking

Bounty $200 ✌️
Try accessing all endpoints to find what is different at the backend as compared to the authenticated front end βœ”οΈ
#bugbounty #cybersecurity #appsec #ethicalhacking
Muhammad Aamir πŸ‡΅πŸ‡° (@muhammad__aamir) 's Twitter Profile Photo

What is the benefit or contribution to community with this kind of hidden disclosure? HackerOne ?? #bugbountytips #CybersecurityNews #Hackerone #Bugcrowd #Intigriti #YesWeHack

What is the benefit or contribution to community with this kind of hidden disclosure?
<a href="/Hacker0x01/">HackerOne</a> ??

#bugbountytips #CybersecurityNews #Hackerone #Bugcrowd #Intigriti #YesWeHack
Muhammad Aamir πŸ‡΅πŸ‡° (@muhammad__aamir) 's Twitter Profile Photo

Thank you bugcrowd. Just earned a bounty for sensitive data disclosure through browser's local storage πŸ’š Sensitivity of data decides whether a program would accept it. I've received the comments "Great find. Thank you!" πŸ™‚ #bugbounty #cybersecurity #appsec