Ali Hz me-retweet
Ali Hz
316 posts

Ali Hz me-retweet

🔁 JWT vulnerabilities remain a critical attack surface in modern web applications... 🧐
Many applications properly validate JWT signatures but overlook cases such as algorithm confusion attacks, JWK spoofing and other scenarios that can lead to complete authentication bypass! 😎
Our comprehensive guide covers 5+ common JWT misconfigurations, including step-by-step exploitation techniques and practical examples.
Read the article today (link in post below) 👇

English
Ali Hz me-retweet

Web-Fuzzing-Box by @VulkeyChen is a massive collection of pre-built wordlists and payloads covering everything from content discovery to XSS, SQL injection, 403 bypasses, and brute force attacks! 🤠
Check it out! 👇
github.com/gh0stkey/Web-F…

English
Ali Hz me-retweet

Ali Hz me-retweet
Ali Hz me-retweet

@AliHzSec مرز نوردوز؛ جایی که اینترنتش انگار فقط یک مرحله از تدفین فنی فاصله داره :)) کی قرار این وضعیت داغون درست بشه؟
فارسی
Ali Hz me-retweet
Ali Hz me-retweet

@morteza_pn کلا تفکرتون اینه هر کی زحمتی میکشه و پول میگیره باید «چشم ارباب» بگه؟ همه مثل تو جیره خور نیستن که یه خط سفید گرفتی گردن خم کردی
فارسی
Ali Hz me-retweet
Ali Hz me-retweet

Polished the MongoBleed PoC a bit to make it more useful. "--auto --decode" is always a good start, if you're not sure.
github.com/Hamid-K/mongob…
English
Ali Hz me-retweet

🧨 9. Upload + Preview = Stored XSS / Sandbox Escape
site:domain.com "Preview uploaded file"
site:domain.com "View uploaded document"
site:domain.com "Open uploaded file"
site:domain.com "Download your file"
🔥 Why critical:
→ SVG / PDF / HTML polyglots
→ Admin-side XSS
→ CSP bypass opportunities
⸻
☠️ 10. Internal / Forgotten Uploads (Highest ROI)
site:domain.com inurl:admin upload
site:domain.com inurl:dashboard upload
site:domain.com inurl:internal upload
site:domain.com inurl:beta upload
site:domain.com inurl:test upload
🔥 Why critical:
→ Old code
→ No WAF
→ No monitoring
→ Legacy frameworks
— @themasterdoctor1 🧠💻💀
English

خطاب به تابستون فن ها : از لحظه لحظه سگ لرز زدن دارم لذت میبرم
sogand@So0gandd
الان خوشحالید داریم یخ میزنیم؟
فارسی
Ali Hz me-retweet

Since a lot of you wanted to see @XHackerx007 at #NahamCon2025 Winter edition, we made it happen! 😉

English










