MdHak
225 posts


One value, read two ways. When a function is overloaded, the argument's type picks which version runs, and a validator and a sink don't have to agree on what that value is. That gap is the bug.
Full writeup + three pwnbox challenges to practice
blog.voorivex.team/javascript-fun…

English

این ویدیویی بود که خیلی براش زحمت کشیدم و سوال خیلیا بود، امیدوارم تا حدی نتونسته باشم تو پیدا کردن جوابش کمک کنم کنم، دمتون گرم
youtu.be/gR2OCyKBF7Y?si…

YouTube

فارسی

Amir (@AmirMSafari) and I found a CVE in the latest version of Tomcat. It was an easy bug. It's a winning strategy: 0day discovery -> scanning all BB programs -> easy and certain triage
This also works for newcommers, not all 0days are hard to find
herodevs.com/vulnerability-…

English

If a website uploads your pictures to S3 as public objects and serves them through a reverse proxy, you have XSS even if the website's implementation is safe! I wrote about this in full in this post:
blog.voorivex.team/content-type-o…

AmirMohammad Safari@AmirMSafari
Can you spot the XSS vulnerability? 👀 Test it out live at: pwnbox.io/challenges/mim…
English

Congratulations, @H4cktus, on being the latest researcher to celebrate the $1 million earnings milestone!
From quitting his restaurant job at 19 to 1500 bugs later and a million dollars, Hacktus shares his story.
Read the blog to hear about how he got started, what his take on AI really is, and his advice for those starting out.
bit.ly/3SA5s0E

English

It’s been almost a year since I decided, with the help of @YShahinzadeh, to step into bug bounty.
Since then, I’ve earned more than $14k in bounties($10K in H1, €4700 in Intigirti), Get my first CVE, and collaborated with highly skilled people who taught me a lot along the way.


English

My First RCE by Reverse Engineering an EXE File With the Help of AI
A secure web app → a JS file leaking a download endpoint → a .NET binary → AI-assisted reverse engineering → a localhost WebSocket with no origin check → RCE
Write-up: blog.voorivex.team/first-rce-via-…
English

برای بچههایی که هانت میکنن و حوصله ندارن توی js دنبال endpointها بگردن یه اکستنشن Burp نوشتم که امیدوارم خوشتون بیاد.
github.com/maverick0o0/E2…

فارسی

People who think this isn’t accepted in bug bounty programs should check this out. Someone actually got paid using this method, even though they only reported the available models exposed by the API key and didn’t abuse file uploads or other advanced features.
At the end of the day, it totally depends on the target program and whether they consider it impactful or not.
I’d still recommend reporting these findings, especially on platforms like Intigriti, YesWeHack, and self-hosted programs. Your chances of getting accepted are usually much higher there.
Shad0w@Itx_Shad0w
For years, Google API keys (AIza...) had little to no real-world impact. But recently, many of them unexpectedly gained access to Google Gemini. curl "generativelanguage.googleapis.com/v1/models?key=…" This appears to be a widespread misconfiguration that can be hunted in the wild.
English

For years, Google API keys (AIza...) had little to no real-world impact.
But recently, many of them unexpectedly gained access to Google Gemini.
curl "generativelanguage.googleapis.com/v1/models?key=…"
This appears to be a widespread misconfiguration that can be hunted in the wild.

English

Here's a story from a rough experience working with cPanel. We found XSS in cPanel in a bunch of places, and a lot of bug bounty programs are still vulnerable to it. You can use the Nuclei template to scan widely. Happy hacking ;)
Yasho@YShahinzadeh
I just dropped a new blog post, happy hacking :) blog.voorivex.team/two-cpanel-zer…
English

I earned $1,500 for my submission on @bugcrowd bugcrowd.com/h/{id: "rahmatqurishi"} #ItTakesACrowd
Bug: privilege escalation
English

It's time for sharing, this is not a simple write-up, we are sharing our methodology and reasoning, detailing how we approached and hunted the flaw, I hope you like it :]
blog.voorivex.team/uxss-on-samsun…

Omid Rezaei@omidxrz
We got permission from the Samsung Security team to disclose this uXSS that we found in Samsung Browser, it was assigned a CVE (CVE-2025-58485) and patched. Here is the PoC, expect the write-up in the next upcoming days.
English












