MOHAMED TAREK (@timooon107) 's Twitter Profile
MOHAMED TAREK

@timooon107

Penetration tester | BugBounty Hunter | CTF Player ♥

ID: 1268498655390191617

calendar_today04-06-2020 11:03:54

636 Tweet

673 Followers

856 Following

Mohamed Anani (@0xm5awy) 's Twitter Profile Photo

Good morning! I've been using this payload for over a year to discover XSS via open redirect vulnerabilities that bypass WAF. It works great: :DD Payload: javascript%3avar{a%3aonerror}%3d{a%3aalert}%3bthrow%2520document.cookie #BugBounty #bugbountytips #bugbountytip

Good morning! I've been using this payload for over a year to discover XSS via open redirect vulnerabilities that bypass WAF. It works great: :DD

Payload: javascript%3avar{a%3aonerror}%3d{a%3aalert}%3bthrow%2520document.cookie

#BugBounty #bugbountytips #bugbountytip
Intigriti (@intigriti) 's Twitter Profile Photo

A quick and easy way to find forgotten hosts that are still exposed to the internet is by checking the SSL/TLS certificate! 🤑 Here's how you can filter by expired SSL certificates in Shodan! 👇 org:"<company>" ssl.cert.expired:true #bugbountytips

A quick and easy way to find forgotten hosts that are still exposed to the internet is by checking the SSL/TLS certificate! 🤑 

Here's how you can filter by expired SSL certificates in Shodan! 👇

org:"&lt;company&gt;" ssl.cert.expired:true

#bugbountytips
mpgn (@mpgn_x64) 's Twitter Profile Photo

So you want to exploit ADCS ESC8 with only netexec and ntlmrelayx ? Fear not my friend, I will show you how to do it 👇 NetExec now supports "Pass-the-Cert" as an authentication method, thanks to Dirk-jan original work on PKINITtools ⛱️

So you want to exploit ADCS ESC8 with only netexec and ntlmrelayx ? Fear not my friend, I will show you how to do it 👇 

NetExec now supports "Pass-the-Cert" as an authentication method, thanks to <a href="/_dirkjan/">Dirk-jan</a> original work on PKINITtools ⛱️
Ben Sadeghipour (@nahamsec) 's Twitter Profile Photo

Very cool write up on a journey to getting RCE through a number of different bugs by Abdullah Nawaf (HackerX007)🇯🇴 and Godfather Orwa 🇯🇴: medium.com/@HX007/a-journ… We made a FREE hub out of it for everyone to try: app.hackinghub.io/hubs/path-to-r…

Ankit Singh (@ankitcuriosity) 's Twitter Profile Photo

Jobs & Internship opportunities -: ->jobs.null.community (For technical and non-technical infosec jobs/internship) by null - The Open Security Community -> isecjobs.com by @infosec_jobsCOM

Coffin (@coffinxp7) 's Twitter Profile Photo

ffuf -w subdomains.txt:SUB -w payloads/backup_files_only.txt:FILE -u https://SUB/FILE -mc 200 -rate 50 -fs 0 -c -x http://localip:8080 payload:github.com/coffinxp/paylo…

Congressman Greg Casar (@repcasar) 's Twitter Profile Photo

The Israeli government has started bombing Gaza again, in violation of the negotiated ceasefire, after blocking food, water, and aid for weeks. We must stop sending offensive weapons to the Israeli government. We cannot continue to be complicit in Netanyahu's assault on

GiuseppeDeLaZara (@windhustler) 's Twitter Profile Photo

💡I’ve been asked numerous times to provide a checklist for auditing a LayerZero integration. ⚡️You asked, so here it is: github.com/windhustler/In… 🧠 I’ve dumped everything I could think of that can go wrong and more. Goran spent years building and breaking the core

💡I’ve been asked numerous times to provide a checklist for auditing a LayerZero integration.

⚡️You asked, so here it is: github.com/windhustler/In…

🧠 I’ve dumped everything I could think of that can go wrong and more. 

<a href="/g_vladika/">Goran</a> spent years building and breaking the core
s1r1us (@s1r1u5_) 's Twitter Profile Photo

I've created benchmark to test LLM capabilities. HackBench tests LLMs' cybersecurity skills using CTF challenges modeled on real-world vulnerabilities. Starting with 16 Security Intern-level tasks, it scales as models improve proving real skill even with test-set contamination

HAHWUL (@hahwul) 's Twitter Profile Photo

Urx (short for "Extracts URLs") is a Rust-based tool I built to collect URLs from various OSINT archives. Inspired by Gau, it’s designed with the features I needed. I’d love to hear your ideas for improvements! Feel free to share them via GitHub issues or leave a comment

Urx (short for "Extracts URLs") is a Rust-based tool I built to collect URLs from various OSINT archives. Inspired by Gau, it’s designed with the features I needed.

I’d love to hear your ideas for improvements! Feel free to share them via GitHub issues or leave a comment
عبدالله العطار abdallah alattar (@abdallahatar) 's Twitter Profile Photo

نناديكم من تحت القصف الجنوني نُقسمُ لكم اننا نُحرق الان تكلموا عنا لعل هذا يشفع لكم

infosecresearcher (@infoscresearchr) 's Twitter Profile Photo

Bug-Bounty Tip for new hunters Use subfinder + dnsx to detect potential subdomain takeover candidates with unresolvable records (NXDOMAIN). subfinder -d target.com -silent | dnsx -a -resp | grep -i "NXDOMAIN" Peace✌️ #bugbountytips #streakammo #bugbounty