
Walid Hossain
@walidhossain_
Web app tester || Everything is vulnerable! || bugcrowd.com/walidhossain For pentest: DM! 👆
ID: 904037554386681856
http://localhost.com 02-09-2017 17:45:23
2,2K Tweet
2,2K Takipçi
450 Takip Edilen


This email domain confusion technique from Gareth Heyes \u2028 is so cool! Some really weird behavior can be found between different mail agents and the right characters/symbols 🤔










I love bug bounty data like this. So insightful, especially from rising star in the community like Evan Connelly evanconnelly.com/post/my-first-…

How did we (AmirMohammad Safari) earn $50k using the Punycode technique? I’ve published a detailed blog post about our recent talk, we included 3 attack scenarios, one of which poses a high risk of account takeover on any "Login with GitLab" implementation blog.voorivex.team/puny-code-0-cl…



Slides of the talk in #PHDays PT Security docs.google.com/presentation/d… hoping be very helpful for all of you ♥ #bugbounty #bugbountytips #bugbountytip If you didn't check the video of the talk , then its time ===>
