MdHak

225 posts

MdHak banner
MdHak

MdHak

@Hack1Tak

Javascript:alert(../../../etc/{{💣}})

Katılım Ekim 2024
126 Takip Edilen107 Takipçiler
Yasho
Yasho@YShahinzadeh·
One value, read two ways. When a function is overloaded, the argument's type picks which version runs, and a validator and a sink don't have to agree on what that value is. That gap is the bug. Full writeup + three pwnbox challenges to practice blog.voorivex.team/javascript-fun…
Yasho tweet media
English
3
20
147
4.9K
 یاشو
 یاشو@voorivex·
این ویدیویی بود که خیلی براش زحمت کشیدم و سوال خیلیا بود، امیدوارم تا حدی نتونسته باشم تو پیدا کردن جوابش کمک کنم کنم، دمتون گرم youtu.be/gR2OCyKBF7Y?si…
YouTube video
YouTube
 یاشو tweet media
فارسی
18
21
252
30.1K
Yasho
Yasho@YShahinzadeh·
Amir (@AmirMSafari) and I found a CVE in the latest version of Tomcat. It was an easy bug. It's a winning strategy: 0day discovery -> scanning all BB programs -> easy and certain triage This also works for newcommers, not all 0days are hard to find herodevs.com/vulnerability-…
Yasho tweet media
English
6
17
163
9.9K
HackerOne
HackerOne@Hacker0x01·
Congratulations, @H4cktus, on being the latest researcher to celebrate the $1 million earnings milestone! From quitting his restaurant job at 19 to 1500 bugs later and a million dollars, Hacktus shares his story. Read the blog to hear about how he got started, what his take on AI really is, and his advice for those starting out. bit.ly/3SA5s0E
HackerOne tweet media
English
68
31
640
55.2K
Muntrive
Muntrive@Muntrive·
It’s been almost a year since I decided, with the help of @YShahinzadeh, to step into bug bounty. Since then, I’ve earned more than $14k in bounties($10K in H1, €4700 in Intigirti), Get my first CVE, and collaborated with highly skilled people who taught me a lot along the way.
Muntrive tweet mediaMuntrive tweet media
English
19
4
227
9.8K
Yasho
Yasho@YShahinzadeh·
My First RCE by Reverse Engineering an EXE File With the Help of AI A secure web app → a JS file leaking a download endpoint → a .NET binary → AI-assisted reverse engineering → a localhost WebSocket with no origin check → RCE Write-up: blog.voorivex.team/first-rce-via-…
English
7
62
461
19.4K
Erfan Tavakoli
Erfan Tavakoli@Maverick_0o0·
برای بچه‌هایی که هانت میکنن و حوصله ندارن توی js دنبال endpointها بگردن یه اکستنشن Burp نوشتم که امیدوارم خوشتون بیاد. github.com/maverick0o0/E2…
Erfan Tavakoli tweet media
فارسی
13
81
580
28.5K
Ho3ein
Ho3ein@0xHo3ein0xploit·
It’s been about a year since I started grinding bug bounty seriously. Over this journey I’ve made $12,000+ in bounties, found impactful bugs, and spent countless nights hunting after work while still having a full-time job. Nothing happened overnight.
English
11
7
296
8.7K
MdHak
MdHak@Hack1Tak·
@nahan_hamdi قتل چون اگر خودکشی بود خونش رو دیوار نمیریخت
فارسی
0
0
0
1.1K
نَهان
نَهان@nahan_hamdi·
کارآگاهای تایملاین این صحنه قتله یا خودکشی؟؟
نَهان tweet media
فارسی
79
0
80
45.3K
Coffin
Coffin@lostsec_·
People who think this isn’t accepted in bug bounty programs should check this out. Someone actually got paid using this method, even though they only reported the available models exposed by the API key and didn’t abuse file uploads or other advanced features. At the end of the day, it totally depends on the target program and whether they consider it impactful or not. I’d still recommend reporting these findings, especially on platforms like Intigriti, YesWeHack, and self-hosted programs. Your chances of getting accepted are usually much higher there.
Shad0w@Itx_Shad0w

For years, Google API keys (AIza...) had little to no real-world impact. But recently, many of them unexpectedly gained access to Google Gemini. curl "generativelanguage.googleapis.com/v1/models?key=…" This appears to be a widespread misconfiguration that can be hunted in the wild.

English
4
15
230
16.8K
Shad0w
Shad0w@Itx_Shad0w·
For years, Google API keys (AIza...) had little to no real-world impact. But recently, many of them unexpectedly gained access to Google Gemini. curl "generativelanguage.googleapis.com/v1/models?key=…" This appears to be a widespread misconfiguration that can be hunted in the wild.
Shad0w tweet media
English
15
49
490
34.7K
MdHak
MdHak@Hack1Tak·
SSTI: Bastards, I'm still alive!!!😈
MdHak tweet media
English
6
10
150
9.6K
Yasho
Yasho@YShahinzadeh·
Venice was amazing
Yasho tweet mediaYasho tweet mediaYasho tweet mediaYasho tweet media
English
4
0
125
5.5K
MdHak
MdHak@Hack1Tak·
@0xkmikze Waiting for write up ❤️‍🔥👏
English
0
0
0
120
Yasho
Yasho@YShahinzadeh·
two more bugs on Google triaged I have two more that I haven’t reported YET, but I’m finalizing them. one is critical, I believe :]
Yasho tweet mediaYasho tweet media
English
16
4
268
9.4K
Yasho
Yasho@YShahinzadeh·
It's time for sharing, this is not a simple write-up, we are sharing our methodology and reasoning, detailing how we approached and hunted the flaw, I hope you like it :] blog.voorivex.team/uxss-on-samsun…
Yasho tweet media
Omid Rezaei@omidxrz

We got permission from the Samsung Security team to disclose this uXSS that we found in Samsung Browser, it was assigned a CVE (CVE-2025-58485) and patched. Here is the PoC, expect the write-up in the next upcoming days.

English
12
55
335
26.3K