🇪🇬 المحترف 🇸🇦 (@sec_bug) 's Twitter Profile
🇪🇬 المحترف 🇸🇦

@sec_bug

ID: 772720549294465025

calendar_today05-09-2016 08:58:30

4,4K Tweet

204 Followers

1,1K Following

Saad Ahmed (@xsaadahmedx) 's Twitter Profile Photo

Ghauri - An Advanced SQL Injection Automation Plugin-In By Security Foster. 💫💫 Latest Acunetix VS Ghauri 🧐🧐 Coded By: r0ot h3x49 🎩 #Cybersecurity #automationtesting #BugBounty #bugbountytips

Ghauri - An Advanced SQL Injection Automation Plugin-In By <a href="/SecurityFoster/">Security Foster</a>. 💫💫
Latest Acunetix VS Ghauri 🧐🧐

Coded By: <a href="/r0oth3x49/">r0ot h3x49</a> 🎩
#Cybersecurity #automationtesting #BugBounty #bugbountytips
Khaled Samy (@khaleedsamy12) 's Twitter Profile Photo

"Don't ignore 403 subdomains" Try to bypass or fuzz more. Also, always check Symfony targets for these directories: /_profiler. You might find phpinfo containing Symfony secrets, which can lead to RCE. Great tip by Godfather Orwa 🇯🇴! ❤️❤️ #BugBounty #SecurityTips

"Don't ignore 403 subdomains"
Try to bypass or fuzz more. 
Also, always  check Symfony targets for these directories: /_profiler. 
You might find  phpinfo containing Symfony secrets, which can lead to RCE.
 Great tip by <a href="/GodfatherOrwa/">Godfather Orwa 🇯🇴</a>! ❤️❤️ 
#BugBounty #SecurityTips
sa||am (@0x88__) 's Twitter Profile Photo

I'm thrilled to introduce Recon88r, a Python script designed to streamline and automate the reconnaissance process # Features: Subdomain Enumeration Live Results in Discord Perform XSS scans JS Exposures Port scanning Full nuclei scanning Panels #bugbounty t.ly/FfmSP

N$ (@nav1n0x) 's Twitter Profile Photo

A less known CVE-2023-3793 - Weaver E-Cology SQL Injection. Nuclei Template Link Link: github.com/UltimateSec/ul… #BugBounty #SQLInjection

A less known CVE-2023-3793 - Weaver E-Cology SQL Injection.  Nuclei Template Link Link: github.com/UltimateSec/ul… 

#BugBounty #SQLInjection
Harsh vardhan Singh (@root_lucky_) 's Twitter Profile Photo

1/7 Web Application Recon Tips 1 : Resolution # github.com/projectdiscove… cat subdomains/subdomains.txt | httpx -follow-redirects -random-agent -status-code -silent -retries 2 -title -web-server -tech-detect -location -no-color -o websites.txt #bugbountytips #BugBounty #Hacking

Mustafa Adam Qamar El-Din (@wadgamaraldeen) 's Twitter Profile Photo

To who asked about the vulnerability type, i wrote this writeup about it before period of time, enjoy reading it :- medium.com/@wadqamar10/ho…

H4x0r.DZ (@h4x0r_dz) 's Twitter Profile Photo

Ok, here is another #bugbountytip You can find this issue with “login with Google ” too, or any other Idp providers During the signup process, delete the email value from the scope 💣

🇪🇨🍫 (@bxmbn) 's Twitter Profile Photo

Wanna know How I prevented a Mass Data Breach? Go Read: medium.com/@bxmbn/how-i-p… Wanna know How a Bank offer led to PII Leak? Go Read: medium.com/@bxmbn/i-recei… More writeups coming soon 🖤

zack0x01 (@zack0x01) 's Twitter Profile Photo

This tool ( unisub ) , its one of the best option for you to bypass WAF's and filters .🙂 by TomNomNom #bugbountytips #bugbounty #Hackingtime

This tool ( unisub ) , its one of the best option for  you to bypass WAF's and filters .🙂

by <a href="/TomNomNom/">TomNomNom</a> 
#bugbountytips #bugbounty #Hackingtime
Het Mehta (@hetmehtaa) 's Twitter Profile Photo

Some Shodan Dorks that might be useful in Bug Bounty. 1. org:"http://target. com" 2. http.status:"<status_code>" 3. product:"<Product_Name>" 4. port:<Port_Number> “Service_Message” 5. port:<Port_Number> “Service_Name” 6. http.component:"<Component_Name>" 7.

X (@themsterdoctor1) 's Twitter Profile Photo

🔖Penetration Testing, Beginner To Expert! Massive Web Application Penetration Testing & Bug Bounty Notes📚 github: github.com/xalgord/Massiv… #web #pentest

/usr/bin/fares (@sirbagoza) 's Twitter Profile Photo

شكرًا لعبدالرحمن ذكي، لخص فيديو الرود ماب ف تكست ❤️ للي مش حيقدر يتفرج عالفيديو او معندهوش وقت، دقيقه اقرا الاتي: ——————————— 1. html | elzero.org 2. css ازاي تعمل تزيين بس كدا وخلاص | elzero.org 3. js | elzero.org 4. php |

Mcerfa11l | Sultan Al-Abdali (@7evv1) 's Twitter Profile Photo

THREAD How did I find 2 DOM XSS by hacking Swagger-UI? 1-Do a subdomain enum to find subs that use Swagger Ui 2-Get the live subs 3-Run Nuclei in all the live subs using the (-tags swagger) 4-Find Swagger Ui endpoints #BugBounty #bugbountytip #bugbountytips #Cybersecurity

THREAD
 How did I find 2 DOM XSS by hacking Swagger-UI?

1-Do a subdomain enum to find subs that use Swagger Ui 
2-Get the live subs 
3-Run Nuclei in all the live subs using the (-tags swagger)
4-Find Swagger Ui endpoints
#BugBounty  #bugbountytip  #bugbountytips #Cybersecurity
m0uka_Dz 🇩🇿 (@m0uka_dz) 's Twitter Profile Photo

- Simple tip for port scan 1) after enumerat your subdomains save in subs.txt 2) run this command "cat subs.txt | dnsx -a -ro | naabu -silent -top-ports 1000 -exclude-ports 80,443,21,22,25 -o ports.txt" #bugbountytips #bugbounty #infosec #cybersec

- Simple tip for port scan 
1) after enumerat your subdomains save in  subs.txt
2) run this command 
"cat subs.txt | dnsx -a -ro | naabu -silent  -top-ports 1000 -exclude-ports 80,443,21,22,25 -o ports.txt"

#bugbountytips #bugbounty #infosec #cybersec
Mustafa Adam Qamar El-Din (@wadgamaraldeen) 's Twitter Profile Photo

Thanks to Allah always and forever ♥️ First Triage in 2024, HTML Injection on Login Page #Tips :- 1- site:*[.]redacted[.]com login.php 2- arjun -u .../login.php -> parameters with body length reflection (username) 3- Test for :- SQLi, LFI, XSS, HTML inj,..etc #bugbountytips

Thanks to Allah always and forever ♥️

First Triage in 2024, HTML Injection on Login Page

#Tips :-

1- site:*[.]redacted[.]com login.php
2- arjun -u .../login.php -&gt; parameters with body length reflection (username)
3- Test for :- SQLi, LFI, XSS, HTML inj,..etc

#bugbountytips
Brut 🇮🇳 (@wtf_brut) 's Twitter Profile Photo

🌟Subdominator🌟 is a powerful tool for passive subdomain enumeration during bug hunting and reconnaissance processes. 📥github.com/sanjai-AK47/Su… #bugbountytip #bugbountytips #ethicalhacking #CyberSecurity #Pentesting #sqli #xss #CyberSecurityAwareness #bugbounty #GitHub #offsec

🌟Subdominator🌟 is a powerful tool for passive subdomain enumeration during bug hunting and reconnaissance processes.

📥github.com/sanjai-AK47/Su…

#bugbountytip #bugbountytips #ethicalhacking #CyberSecurity #Pentesting #sqli #xss #CyberSecurityAwareness #bugbounty #GitHub #offsec
Het Mehta (@hetmehtaa) 's Twitter Profile Photo

An automation tool for enumerating subdomains, filtering out XSS, SQLI, Open Redirect, LFI, SSRF, and RCE parameters, and scanning for vulnerabilities. github.com/h4r5h1t/webcop…

Jayesh Madnani (@jayesh25_) 's Twitter Profile Photo

🚀Bug Bounty Tips: Act quickly to report issues related to CVE-2020-27838, as many vulnerable instances are still out there. I've identified over 100+ instances vulnerable to CVE-2020-27838 so far. A flaw was found in Keycloak in versions prior to 13.0.0. The client registration

🚀Bug Bounty Tips: Act quickly to report issues related to CVE-2020-27838, as many vulnerable instances are still out there. I've identified over 100+ instances vulnerable to CVE-2020-27838 so far.

A flaw was found in Keycloak in versions prior to 13.0.0. The client registration
Ben Sadeghipour (@nahamsec) 's Twitter Profile Photo

🚨 I convinced my team to do one last giveaway! Options: hhub.io/eu2wxGj 🏆 Full Access: $199 💻 Lifetime Course: $39 (includes updates) 🎯 1-Month trial (no updates): $19 TWO WINNERS (1 each): - Full cert bundle - Lifetime access Enter: ↪️ RT + Reply with 🎯

🚨 I convinced my team to do one last giveaway!

Options: hhub.io/eu2wxGj
🏆 Full Access: $199 
💻 Lifetime Course: $39 (includes updates)
 🎯 1-Month trial (no updates): $19

TWO WINNERS (1 each):
- Full cert bundle
- Lifetime access

Enter: ↪️ RT + Reply with 🎯