Ali Hz retweetledi
Ali Hz
316 posts

Ali Hz retweetledi

🔁 JWT vulnerabilities remain a critical attack surface in modern web applications... 🧐
Many applications properly validate JWT signatures but overlook cases such as algorithm confusion attacks, JWK spoofing and other scenarios that can lead to complete authentication bypass! 😎
Our comprehensive guide covers 5+ common JWT misconfigurations, including step-by-step exploitation techniques and practical examples.
Read the article today (link in post below) 👇

English
Ali Hz retweetledi

Web-Fuzzing-Box by @VulkeyChen is a massive collection of pre-built wordlists and payloads covering everything from content discovery to XSS, SQL injection, 403 bypasses, and brute force attacks! 🤠
Check it out! 👇
github.com/gh0stkey/Web-F…

English
Ali Hz retweetledi

Ali Hz retweetledi
Ali Hz retweetledi

@AliHzSec مرز نوردوز؛ جایی که اینترنتش انگار فقط یک مرحله از تدفین فنی فاصله داره :)) کی قرار این وضعیت داغون درست بشه؟
فارسی
Ali Hz retweetledi
Ali Hz retweetledi

@morteza_pn کلا تفکرتون اینه هر کی زحمتی میکشه و پول میگیره باید «چشم ارباب» بگه؟ همه مثل تو جیره خور نیستن که یه خط سفید گرفتی گردن خم کردی
فارسی
Ali Hz retweetledi
Ali Hz retweetledi

Polished the MongoBleed PoC a bit to make it more useful. "--auto --decode" is always a good start, if you're not sure.
github.com/Hamid-K/mongob…
English
Ali Hz retweetledi

🧨 9. Upload + Preview = Stored XSS / Sandbox Escape
site:domain.com "Preview uploaded file"
site:domain.com "View uploaded document"
site:domain.com "Open uploaded file"
site:domain.com "Download your file"
🔥 Why critical:
→ SVG / PDF / HTML polyglots
→ Admin-side XSS
→ CSP bypass opportunities
⸻
☠️ 10. Internal / Forgotten Uploads (Highest ROI)
site:domain.com inurl:admin upload
site:domain.com inurl:dashboard upload
site:domain.com inurl:internal upload
site:domain.com inurl:beta upload
site:domain.com inurl:test upload
🔥 Why critical:
→ Old code
→ No WAF
→ No monitoring
→ Legacy frameworks
— @themasterdoctor1 🧠💻💀
English

خطاب به تابستون فن ها : از لحظه لحظه سگ لرز زدن دارم لذت میبرم
sogand@So0gandd
الان خوشحالید داریم یخ میزنیم؟
فارسی
Ali Hz retweetledi

Since a lot of you wanted to see @XHackerx007 at #NahamCon2025 Winter edition, we made it happen! 😉

English










