0xmust4fa
81 posts

0xmust4fa
@313MMustafa
Learning in process...
EVERY-WHERE! Katılım Haziran 2023
160 Takip Edilen34 Takipçiler

I earned $750 for my submission on @bugcrowd bugcrowd.com/h/{id: "rahmatqurishi"} #ItTakesACrowd
Bug-type: idor
English

@agent_num_48 @voorivex با singlarity برو dns rebinding انجام بده نتیجه میگیری

@soda688541 @M_mahdii_R @voorivex طبق همین چیزی که گفتم بری جلو میشه ولی اگر نتونستی بیا پی وی بهت بگم
فارسی

@M_mahdii_R @voorivex داداش پایین درخواست signin
Role رو اضافه کن کنار پسورد
و بعدش کوشش کن بایپس کنی
اگر نشد بیا پی وی
فارسی

@313MMustafa @voorivex داداش لول 30 چجوری زدی، انقدر با jwt ور رفتم سرگیجه گرفتم😐
فارسی

I earned $750 for my submission on @bugcrowd bugcrowd.com/h/{id: "rahmatqurishi"} #ItTakesACrowd
Bug: privilege escalation
English

@RahmatQurishi @Bugcrowd Wish you more big successes Rahmat jan 🤍👌
English

I earned $1,500 for my submission on @bugcrowd bugcrowd.com/h/{id: "rahmatqurishi"} #ItTakesACrowd
it was admin account takeover team changed the severity from p1 to p2😒
English

6 months hacking on HackerOne, Proud to be ranked #1 Top Hacker from Afghanistan in 2025 🇦🇫
#BugBounty #HackerOne #CyberSecurity

English

2025 summary on @Hacker0x01
1- Ranked 43rd globally for highest critical reputation (27 Critical, 37 High)
2- 130 reports Average bounty: $1k (122 BBP, 8 VDP, 20 duplicates)
3- Top reported weaknesses:
•IDOR / Access Control: 40+
•XSS: 40+
•Auth Bypass: 10
4- Ranked #1 in my main program




Sky Desperados@skydesperados
Q2 summary on @Hacker0x01 1- ranked 80 in global leaderboard 2- ranked 52 in highest critical reputation 3- $41k ( Most of IDOR & XSS & Auth) 4- 31 submission ( 4 critical , 7 high, 10 medium, 4 low , 3 duplicates) some of still PPR
English

🚨 CORS Exploit Unlocked
Trusted origin + creds = Admin API Key stolen 😎
📚 PoC & write-up:
🔗 github.com/0xmust4fa/port…
#CORS #BugBounty #WebSecurity #InfoSec #EthicalHacking #0xmust4fa #PortSwigger #WebSecurityLabs

English

Yay, I was awarded a $500 bounty on @Hacker0x01! hackerone.com/nischalxd
Tip: Some apps use custom headers that are sometimes disclosed in response headers, JS code, docs, etc. If these headers are unkeyed, they can lead to a simple CP-DoS.
#TogetherWeHitHarder #BugBouty

English

3 SSTI labs → 3 RCEs. 💥
{{7*7}} → Handlebars {{#with}} chains → rm morale.txt
PortSwigger owned. Full writeups:github.com/0xmust4fa/Inje…
#SSTI #BugBounty #Infosec #Hacking

English

خب ایونت 30 روزمون تموم شد🏁
یسری تجربه ها داد و کلی جا برای بهتر شدن داریم مرسی که دنبال کردین
@bitati8
instagram.com/reel/DS0RFGYjR…

فارسی

7 Labs. 7 RCEs. 0 Excuses. 💀
Just cleared the PortSwigger File Upload series, including the Expert-level Race Condition! From metadata injection to breaking blacklists, it’s all about the bypass.
Repo updated with the full writeups. github.com/0xmust4fa/Inje… 🏹
#BugBounty #RCE

English







