MahDi Dm
11 posts


الحمد لله ♥️
⬇️
POC:
1-attacker signs up using the victim’s email + any password on site.com.
2-The account is created and marked as Unverified.
3-Attacker does not verify the email.
4-Victim later signs up using Sign in with Google with the same email address.

English

@metwallysec congrats , which program is this can u send it to me in private
English

الحمد لله 🌟
Vulnerability: Logic Bug – Privilege Escalation (Invitation Links) rated High 🔥
Tip :
Always treat invitation links as a danger zone.
Test them with different roles, sessions, and UI vs backend behavior.
#CyberSecurity #BugBounty #PrivilegeEscalation #LogicBug


English

@dennis_malware @Olamdeen bro can u told me the name of program in chat
English

@Olamdeen Hey I know this bug bounty program it's that German company anyways. Which vuln type
English

And it finally happened
Alhamdulillahi

OlamDeen@Olamdeen
It can still happen before the year runs out
English


🚀 My FIRST @Bugcrowd bounty on 26/09/25! 💰 Plus 2 bugs triaged & live. This is just MONTH 1 of bug hunting—and I've already snagged 3 bugs in ~30-40 hours.
But it's NOT just the hours—it's consistent learning since 2021 + hardcore effort paying off!


English

Alhamdulillah, I was awarded a $450 bounty on @Hacker0x01!
#Bug: Privilege escalation
#TogetherWeHitHarder #hackerone #bugbountyhunting #bugbounty

English

From learning recon to landing my first bounties — it feels real now.
Found the same vuln on 2 different assets of a private program on @Hacker0x01. Got rewarded $550 in total.
First win of many.
#BugBounty #HackerOne


English




