Sayedv2 ๐ท๏ธ
66 posts

Sayedv2 ๐ท๏ธ
@Sayed_v2
Bug Bounty Hunter ๐ | @hacker0x01
Ismalia, Egypt ๊ฐ์
์ผ Aralฤฑk 2023
137 ํ๋ก์564 ํ๋ก์
Sayedv2 ๐ท๏ธ ๋ฆฌํธ์ํจ

My first Write-up
How I broke the logic of invitation with Race condition and got 4 bugs
@raslanco/one-invite-endpoint-one-race-condition-4-bugs-later-b48de71b280c" target="_blank" rel="nofollow noopener">medium.com/@raslanco/one-โฆ
#bugbountytips #bugbountytip #bugbounty #writeups

English

@Mo_AboAlezz ุงูู ู
ุจุฑูู ูุงุญุจูุจ ููุจู โค๏ธโค๏ธ
ุงูุนุฑุจูุฉ

Happy to secure #AirBNB
High-severity bug allows me to get unlimited free hotel reservations
#HackerOne #H1

English
Sayedv2 ๐ท๏ธ ๋ฆฌํธ์ํจ

A few shots from our latest @Hacker0x01 Egypt ๐ช๐ฌ Club meetup! Amazing turnout, great hacking sessions, career discussions, and tons of knowledge sharing.
Thanks to everyone who showed up!




English
Sayedv2 ๐ท๏ธ ๋ฆฌํธ์ํจ

Happy to keep @Meta platforms secure by finding and reporting a 2FA bypass vulnerability
#Meta #BugBounty

English
Sayedv2 ๐ท๏ธ ๋ฆฌํธ์ํจ

GraphQL Penetration Testing Guide & Common Attacks
deepstrike.io/blog/graphql-aโฆ
#penetration_testing
#BugBounty
English

@Sayed_v2 I don't know when I will get this kind of privilege ๐ฅ
English

ูุญุทูุง ู ุชุงุฑุฌุช
ุงูู
ู ููุจ ูุงุจูุง ุชููู ู
ุฌูุญ ููู (ุฅู ุดุงุก ุงููู)
ุงุฌูุจ bugs
ุงุฐุงูุฑ ุฑูููุฑุณ ูุงุจุตูู ุจุตู ุนู malware analysis
ุงุฌูุจ bugs
ุงุฎูุต ุงูุงูุฏุฑููุฏ
ุงูุฒู ุงูุชุฑู
ุงุฌูุจ bugs
ููุงุฑุจ ุงุณุงูุฑ ุงุฒุงู ู
ุนุฑูุด
Rodina Mo'men@MobarkRodina
ุงุตุฏูุงุฆู ุงูู ุจุฑู ุฌููุ ุนุงูุฒูู ุชุญูููุง/ ุชุฐุงูุฑูุง ุงูู ุงูุณูุฉ ุงูุฌุฏูุฏุฉุ
ุงูุนุฑุจูุฉ

@ElGOHAR18038201 @Abdulluuuu ู
ุด ุชุณุฃููู ุงูุง ูุตุญุจู
ุงูุนุฑุจูุฉ

@Abdulluuuu ููุณ ุงูุชุงุฑุฌุช ู
ุน ุดููู ุจูุงุฑุงุช
ูุชุฐุงูุฑ ุงูุฏุฑููุฏ ู
ูููุ
ุงูุนุฑุจูุฉ

@19whoami19 @Eyax0 ุจุชุถุญู ุนูู ุงูู ูุง ุดูุจูุฑ
ุงูุนุฑุจูุฉ

Is this normal ?
I can do unauthorized actions even after being logged out and the request is valid for 24 hours before the token expiration.
And this is their response after the report being triaged from bug crowd staff and they marked this as NA .
@Bugcrowd
#bugbounty

English

@Sayed_v2 ู
ู
ูู ุชุจุนุชูู ุงู ุทุฑููุฉ ุชูุงุตู ุนุงูุฒ ุงููู
ู
facebook.com/xetrr
ุงุจุนุช ููุง
ุงูุนุฑุจูุฉ

I just published a write-up on how I bypassed team member limits on a bug bounty program by exploiting two race conditions! ๐ฅ
Writeup link : sayedv2.medium.com/double-race-coโฆ
#BugBounty #bugbountytips

English
Sayedv2 ๐ท๏ธ ๋ฆฌํธ์ํจ

ุงูุญููุฉ ุงูุฑุงุจุนู ู
ุน Souhaib Naceri @h4x0r_dz ูุงุชููู
ูุง ูููุง ุนู ุญุงุฌุงุช ูุชูุฑ ูุชุฌุฑุจุชุฉ ูู ุงููุตูู ูู LHE ุจุชุงุน ูุงูุฑูู ูููู ูุตุงูุญ ุฌุฏุงู ู
ูู
ุฉ ูุชุทููุฑ ู
ุณุชูุงูุ ูุญุงุฌุงุช ุชุงููุฉ ูุชูุฑ ุชูุฏุฑ ุชุดูููุง ู
ู ููุง :
youtu.be/uuxACNbB6Zk
#BugBounty

YouTube

ุงูุนุฑุจูุฉ

