0xf4h1m (@oxf4h1m) 's Twitter Profile
0xf4h1m

@oxf4h1m

Bug bounty hunter | CTF player

ID: 1355951288752562181

calendar_today31-01-2021 18:49:30

20 Tweet

35 Takipçi

192 Takip Edilen

Raiinmaker (@raiinmakerapp) 's Twitter Profile Photo

Earn your share of 25,000 $MATIC in March! Here's How: 1. Download the #RaiinmakerApp: raiinmaker.com 2. Create Content. 3. Share On Social 4. Stack #Crypto #Polygon #Matic #Ethereum #RaiinmakerApp #Web3 #metaverse #MakeItRaiin #MintYourMoment

MetaWear® (@metaweartoken) 's Twitter Profile Photo

MetaWEAR #IDO is coming! Last #Airdrop Before IDO 2,000,000 $WEAR TOKEN IDO AIRDROP 🏅2.000 Winners. Get Your $WEAR Tokens MetaWear | Fashion for Metaverse MetaverseWear.io 👉Join Here: gleam.io/baIUo/metawear…… #NFT #NFT2 #MetaWEAR #Airdrops #NFTs

0xf4h1m (@oxf4h1m) 's Twitter Profile Photo

MetaWEAR #IDO is coming! Last #Airdrop Before IDO 2,000 Winners. Get Your $WEAR Tokens - MetaWear® 🚀🚀🚀 gleam.io/baIUo/metawear… #metaverse #metawear

AirdropDetective (@airdropdet) 's Twitter Profile Photo

🔍 New #Airdrop: HappyLandPlus 💲 Reward: Up to 25 USDT + 2,5K USDT referral pool 🔴 Start the airdrop bot t.me/HappyLandPlusN… 🔘 Do the tasks on the bot & submit your data. 🔘 Details: t.me/AirdropDetecti… #Airdrops #HappyLandPlus #Bitcoin #AirdropDet #ETH #USDT

Godfather Orwa 🇯🇴 (@godfatherorwa) 's Twitter Profile Photo

url/?f=etc/passwd ==> 403 encode etc/passwd as base64 url/?f=L2V0Yy9wYXNzd2Q= ==> 200 #note you can use this trick in SQL , SSTI , XSS , LFI , Etc... #bugbountytips #bugbountytip

url/?f=etc/passwd ==> 403
encode etc/passwd as base64

url/?f=L2V0Yy9wYXNzd2Q=  ==> 200

#note 
you can use this trick in SQL , SSTI , XSS , LFI , Etc...

#bugbountytips #bugbountytip
Daniel Kelley (@danielmakelley) 's Twitter Profile Photo

30 cybersecurity search engines for researchers: 1. Dehashed—View leaked credentials. 2. SecurityTrails—Extensive DNS data. 3. DorkSearch—Really fast Google dorking. 4. ExploitDB—Archive of various exploits. 5. ZoomEye—Gather information about targets.

Justin Gardner (@rhynorater) 's Twitter Profile Photo

I've made over 100k on SSRF vulnerabilities. They aren't always as simple as pointing it at localhost or AWS Metadata service. Here are some tricks I've picked up over the past 5 years of web app testing:

I've made over 100k on SSRF vulnerabilities.

They aren't always as simple as pointing it at localhost or AWS Metadata service. 

Here are some tricks I've picked up over the past 5 years of web app testing:
0xf4h1m (@oxf4h1m) 's Twitter Profile Photo

"Ditch expensive RDP servers! Get your free server now for limitless computing power. 💻💰 Explore #FreeRDP and enjoy an affordable RDP server. Don't miss out! Visit rdphostings.com & follow @RDPHostings. #RDPHostings

0xf4h1m (@oxf4h1m) 's Twitter Profile Photo

I just completed the "Dojo #32 - Security Panel" challenge on @YesWeHack! 🚀 Can you do it?: dojo-yeswehack.com/challenge/play… #ChallengeCompleted #YesWeRHackers #YesWeHackDojo

0xf4h1m (@oxf4h1m) 's Twitter Profile Photo

Alhamdulillah!! Just got a reward ($$$) for a vulnerability submitted on @YesWeHack. It was Cross-site Scripting (XSS) - Stored (CWE-79) vulnerability. #YesWeRHackers #yeswehack #bugbounty #XSS #infosec #cybersecurity #0xf4h1m

Alhamdulillah!! Just got a reward ($$$) for a vulnerability submitted on @YesWeHack.

It was  Cross-site Scripting (XSS) - Stored (CWE-79) vulnerability.

#YesWeRHackers #yeswehack #bugbounty #XSS #infosec #cybersecurity #0xf4h1m
0xf4h1m (@oxf4h1m) 's Twitter Profile Photo

🚀 Exciting News! 🚀 Alhamdulillah!!! I'm thrilled to share that I've received my highest bounty ($$$$) this year for discovering an XXE vulnerability! from YesWeHack ⠵ #cybersecurity #bugbounty #infosec #yeswehack #XXE #vulnerability #securityresearch

🚀 Exciting News! 🚀

Alhamdulillah!!! I'm thrilled to share that I've received my highest bounty ($$$$) this year for discovering an  XXE vulnerability!  from <a href="/YesWeHack/">YesWeHack ⠵</a>

#cybersecurity #bugbounty #infosec #yeswehack #XXE #vulnerability #securityresearch
0xf4h1m (@oxf4h1m) 's Twitter Profile Photo

🚀 Exciting News! 🚀 Alhamdulillah!!! I'm thrilled to share that I've received a bounty ($$$$) for discovering an CSRF vulnerability! from YesWeHack ⠵ #cybersecurity #bugbounty #infosec #yeswehack #XXE #vulnerability #securityresearch

🚀 Exciting News! 🚀

Alhamdulillah!!! I'm thrilled to share that I've received a bounty ($$$$) for discovering an CSRF vulnerability!  from <a href="/YesWeHack/">YesWeHack ⠵</a>

#cybersecurity #bugbounty #infosec #yeswehack #XXE #vulnerability #securityresearch