Muhammad Zohaib
141 posts

Muhammad Zohaib
@zabhack0r
Penetration Tester | Bug Bounty Hunter
Karachi, Pakistan Se unió Eylül 2024
558 Siguiendo202 Seguidores

5th on @vii_finance contest on @cantinaxyz competition. That was my last competition before I switched to Bug Bounty. I hope I will have a nice finding in bounties soon !

English

🦖
Day 275 of learning blockchain👾
Got a bug confirmed on Immunefi today.
But here’s the truth no one talks about…
If you don’t make it, there will be no evidence you ever tried.
All the sleepless nights, staring at code until your eyes hurt
All the self-doubt when nothing clicks
All the silent losses no one sees
It will all mean nothing to the world.
That’s the painful part.
This path doesn’t reward effort — it only rewards outcomes.
So you either win…
or your struggle disappears like it never existed.
And that’s exactly why I’m not stopping.

English

🦖
Day 271 of learning blockchain
Small payout — but honestly, the money doesn’t matter right now.
Skill does. The grind does.
The Panoptic contest report just dropped:
• 1 valid medium finding
• 50th place finish
• First step on the leaderboard
Behind this small line in the report are hundreds of hours of reading code, questioning assumptions, getting things wrong, and trying again.
Audit contests are painful in a good way.
No shortcuts.
No overnight success.

English

Excited to share that another Reflected Cross-Site Scripting (rXSS) vulnerability I discovered has been accepted by Synack, earning a $330 bounty.
Grateful for the opportunity .
#CyberSecurity #BugBounty #AppSec #EthicalHacking #Synack

English

Patch said “fixed.” HTML injection said “not today.” Reported responsibly 😎🔍
#Bugcrowd #ResponsibleDisclosure #CybersecurityNews

English

Don’t lose hope if you’re on this path — the pain means you’re building something real
Day 207 of learning blockchain 🚀
• This was my 3rd contest
• Valid High severity finding but (still under review)
• Jump into hard codebases even when they make no sense
• If you don’t step in, you’ll always be afraid
Pain is the tuition. Consistency is the reward. 💪

English

Hey #BugBounty hunters
🚨 Published my new bug bounty write-up.
A Broken Activation Links Leading to Full ATO by Zabhack0r.
@zabhack0r/when-account-activation-becomes-account-takeover-200705780b38" target="_blank" rel="nofollow noopener">medium.com/@zabhack0r/whe…

English

Hey #BugBounty hunters
🚨 Published my first bug bounty write-up!
Account Takeover via Password Reset Logic Flaw by Zabhack0r.
#bugbountytips #ato #hacking
medium.com/p/account-take…
English














