salman khan ashlor (@salman_ashlor) 's Twitter Profile
salman khan ashlor

@salman_ashlor

Cyber Security Researcher | Penetration Tester at @Pentest People LTD | ISO/IEC 27001 INFORMATION SECURITY ASSOCIATE

ID: 1471168407663951883

linkhttps://medium.com/@salman_ashlor calendar_today15-12-2021 17:21:18

145 Tweet

769 Followers

225 Following

Abhishek Meena - {🔥} (@aacle_) 's Twitter Profile Photo

If a web application allow you to upload a .zip file, zip:// is an interesting PHP wrapper to turn a LFI into a RCE. #BugBounty #BugBountyTips #InfoSec

If a web application allow you to upload a .zip file, zip:// is an interesting PHP wrapper to turn a LFI into a RCE.

#BugBounty #BugBountyTips #InfoSec
Ankita Dhakar (@expankita) 's Twitter Profile Photo

Hello Hackers 🥷🏾 Want to know how to Bypass Cross-Site Scripting (XSS) Filters with practical examples? Read and Bookmark 🧵

salman khan ashlor (@salman_ashlor) 's Twitter Profile Photo

Hello everyone, I wanted to share my discovery of GHAURI, an exceptional SQL injection tool that I find to be even better than sqlmap. I'd like to extend my heartfelt gratitude to Nasir Khan (r0ot h3x49) for crafting this incredible tool. #SQL #bugbountytips #hackerone #synack

Hello everyone,
I wanted to share my discovery of GHAURI, an exceptional SQL injection tool that I find to be even better than sqlmap. I'd like to extend my heartfelt gratitude to Nasir Khan (<a href="/r0oth3x49/">r0ot h3x49</a>)  for crafting this incredible tool.

#SQL #bugbountytips #hackerone #synack
salman khan ashlor (@salman_ashlor) 's Twitter Profile Photo

For the first time in history, a press conference is being held amid 500 casualties. Israel's actions are deeply concerning, and the U.S. must reconsider its support. Let's strive for a world where the U.S. truly champions humanity. #shamelessUs #hospital #IsraelAttack #Iran

For the first time in history, a press conference is being held amid 500 casualties. Israel's actions are deeply concerning, and the U.S. must reconsider its support. Let's strive for a world where the U.S. truly champions humanity.

#shamelessUs  #hospital
#IsraelAttack #Iran
salman khan ashlor (@salman_ashlor) 's Twitter Profile Photo

Alhamdulillah! 🌟 Grateful for the overwhelming love and support for my writeup. 📝 Now, I'm seeking your input for the next topic. Which one would you like to explore: 1️⃣ HTTP Request Smuggling 2️⃣ Web Cache Deception or Poisoning #bugbountytip #Hacking #Pentesting #article #xss

Alhamdulillah! 🌟 Grateful for the overwhelming love and support for my writeup. 📝 Now, I'm seeking your input for the next topic. Which one would you like to explore:
1️⃣ HTTP Request Smuggling
2️⃣ Web Cache Deception or Poisoning
#bugbountytip #Hacking #Pentesting #article #xss
salman khan ashlor (@salman_ashlor) 's Twitter Profile Photo

Thrilled to have achieved the 50 Penetration Assessment milestone! 🎉 Grateful for the journey and the opportunity to enhance cybersecurity defenses 🛡️. Looking forward to more challenges and discoveries ahead! 🚀 #PenetrationTesting #Cybersecurity #bughunting #pentesting

salman khan ashlor (@salman_ashlor) 's Twitter Profile Photo

Have you ever tried to brute force `victim+§1§Gmail.com`? Create multiple email variations using Gmail by adding "+AnyNumber" before the '@' sign to generate distinct email addresses all routed to your primary inbox. ⚠️ Brute force scenario: victimusername+§1§Gmail.com 💡🛡️

Have you ever tried to brute force `victim+§1§<a href="/gmail/">Gmail</a>.com`?

Create multiple email variations using Gmail by adding "+AnyNumber" before the '@' sign to generate distinct email addresses all routed to your primary inbox.

⚠️ Brute force scenario:

victimusername+§1§<a href="/gmail/">Gmail</a>.com 💡🛡️
salman khan ashlor (@salman_ashlor) 's Twitter Profile Photo

Where are human rights organizations. It's time to unite against Israel and the hypocrisy of the US to protect the innocent humans.😞 Here US is just pretending to be the champ of human rights. Ao All Muslim umma unit #ghazah #RafahUnderAttack‌ #Rafa_Crossing #RafahBombing

salman khan ashlor (@salman_ashlor) 's Twitter Profile Photo

Grateful to receive such positive feedback from a valued client on my penetration testing efforts! Alhamdulillah❤️ . It's a pleasure to work with such a nice and appreciative client like Alex. #xss #idor #bugbounty #Penetrationtesting #testing #ClientSuccess #CyberSecurity

Grateful to receive such positive feedback from a valued client on my penetration testing efforts! Alhamdulillah❤️ .

It's a pleasure to work with such a nice and appreciative client like Alex.

#xss #idor #bugbounty #Penetrationtesting #testing #ClientSuccess #CyberSecurity
salman khan ashlor (@salman_ashlor) 's Twitter Profile Photo

Alhamdulillah ❤️ Found an amazing Web Cache Deception vulnerability. Remedy report status update: r.xyz/confirmed-as-v… #bugbounty #Hacking #Pentesting #testing #bounty #bugcrowd #hackerone #follow #vulnerable

Alhamdulillah ❤️
Found an amazing Web Cache Deception vulnerability.

<a href="/xyz_remedy/">Remedy</a> report status update:
r.xyz/confirmed-as-v… 

#bugbounty #Hacking #Pentesting #testing #bounty #bugcrowd #hackerone #follow #vulnerable
salman khan ashlor (@salman_ashlor) 's Twitter Profile Photo

Happy Feb-March ٱلْحَمْدُ لِلَّٰهِ, again back towards bug bounty. #bug #bugbounty #bugcrowd #hacking #report #vulnerability #vapt #VAPT

Happy Feb-March ٱلْحَمْدُ لِلَّٰهِ, again back towards bug bounty.

#bug #bugbounty #bugcrowd #hacking #report #vulnerability #vapt #VAPT
salman khan ashlor (@salman_ashlor) 's Twitter Profile Photo

New article: How I Earned $650 by Exploiting Web Cache Deception! 🚀💰 A small caching misconfiguration led to data exposure—read my full write-up here: medium.com/@salman-ashlor… #bugbounty #bugbountytips #hacking #VAPT #testing #bug #vulnerability #hackers medium.com/@salman-ashlor…

New article: How I Earned $650 by Exploiting Web Cache Deception! 🚀💰
A small caching misconfiguration led to data exposure—read my full write-up here: 
medium.com/@salman-ashlor…
#bugbounty #bugbountytips #hacking #VAPT #testing #bug #vulnerability #hackers medium.com/@salman-ashlor…
Rishi (@rxerium) 's Twitter Profile Photo

🚨 Critical RCE (CVSS 10) vulnerability affecting n8n instances: CVE-2025-68613 I've created a vulnerability detection script here: github.com/rxerium/CVE-20… No signs of active exploitation, yet. Patches are available and users are strongly advised to upgrade to version

🚨 Critical RCE (CVSS 10) vulnerability affecting n8n instances: CVE-2025-68613

I've created a vulnerability detection script here: 
github.com/rxerium/CVE-20…

No signs of active exploitation, yet. 

Patches are available and users are strongly advised to upgrade to version
salman khan ashlor (@salman_ashlor) 's Twitter Profile Photo

Pentest #68: Just wrapped up a deep dive into a new environment. this engagement proved once again why manual testing is irreplaceable. Key findings: IDOR: leak sensitive data Privilege Escalation Total Findings: 18 On to the next one. 🛡️ #Pentesting #Hacking #CybersecurityNews

Pentest #68:
Just wrapped up a deep dive into a new environment. this engagement proved once again why manual testing is irreplaceable.
Key findings:
IDOR: leak sensitive data
Privilege Escalation
Total Findings: 18

On to the next one. 🛡️
#Pentesting #Hacking #CybersecurityNews