Mahmoud Abd Alkarim

548 posts

Mahmoud Abd Alkarim banner
Mahmoud Abd Alkarim

Mahmoud Abd Alkarim

@Maakthon

Offensive Security. https://t.co/M7y291h01j https://t.co/lR72Jri5fU I could be in your computer and you wouldn't know. #OSINT_بالعربي

bаϲƙɡ𝗋𝗈υոԁ Katılım Kasım 2013
383 Takip Edilen749 Takipçiler
Mahmoud Abd Alkarim
Mahmoud Abd Alkarim@Maakthon·
March results: 7 vulnerabilities reported in @Swisscom * 2 Account Takeover (OAuth)+2 fix bypasses * 1 SSRF (internal systems) * 1 Broken Access Control (delete any account) * 1 Stored XSS * 1 Reflected XSS * 1 Credential Disclosure Thanks to Swisscom security team #bugbounty
Mahmoud Abd Alkarim tweet media
English
0
2
36
1.6K
James Kettle
James Kettle@albinowax·
I've just submitted my latest research to Black Hat USA! This one has been cooking since last June, can't wait to share it with the world... in fact I'm quite excited just to see the community reaction to the title reveal.
James Kettle tweet media
English
18
22
398
15.3K
Mahmoud Abd Alkarim
Mahmoud Abd Alkarim@Maakthon·
Any update? --> × Any update before world war 3 --> ✓
English
0
0
2
251
Mahmoud Abd Alkarim
Mahmoud Abd Alkarim@Maakthon·
Lately, I don’t have the patience to read long articles anymore. Instead, I collect multiple articles on a single topic (like SSRF vulnerabilities), feed them into #NotebookLM, and it generates an audio discussion with two speakers. This feels absolutely insane 🤯
Mahmoud Abd Alkarim tweet media
English
0
0
4
120
Mahmoud Abd Alkarim
Mahmoud Abd Alkarim@Maakthon·
🚀 Built GoTel Cloud - a free platform for devs & security researchers to capture, inspect & analyze web requests in real-time. Now in beta → gotel.cloud
Mahmoud Abd Alkarim tweet media
English
0
0
1
196
Sam Curry
Sam Curry@samwcyo·
Coming back from a bit of a hacking break and have a few blog post drafts written up. Would anyone be interested in reading about hacking online gambling companies, even if the bugs are super simple? So many actuators/easy findings with crazy impact, but nothing very complicated.
English
62
17
445
24.8K
Mohamed Sayed (ret2flex) 🇵🇸
I was working on a device in Egypt that allowed me to control a car using this device. Here are the details: كنت شغال علي جهاز ف مصر منه كنت بقدر اتحكم ف العربية اللي بتستخدم الجهاز دة ودي التفاصيل: fahemsec.com/blog/devicex-s…
Mohamed Sayed (ret2flex) 🇵🇸 tweet media
1
6
77
2.9K
James Kettle
James Kettle@albinowax·
This research forcibly taught me just how valuable collaboration is! You probably already knew that but it was eye opening for me! Excited to try more in future…
sw33tLie@sw33tLie

Super glad to have collaborated on @albinowax’s research this year with @bsysop and @_medusa_1_. Funny enough, it all started with a random Slack DM that revealed a potential research collision with James, and things took off from there.

English
1
4
81
6.2K
James Kettle
James Kettle@albinowax·
The whitepaper is live! Learn how to win the HTTP desync endgame... and why HTTP/1.1 needs to die: http1mustdie.com
English
19
241
750
85.5K
BSidesCanberra
BSidesCanberra@BSidesCbr·
KEYNOTE: Not All Vulnerabilities Are The Same 10 years ago, @infosec_au spoke at the first BSidesCbr. Now Australia’s top bug bounty hunter, he’s back to unpack enterprise zero-days, building Assetnote’s team, and what makes a vuln actually matter. cfp.bsidescbr.com.au/bsides-canberr…
English
3
14
75
6.5K
djurado
djurado@djurado9·
I still see a lot of people who think anything involving AI is just marketing hype. Over the past few weeks, I’ve seen @Xbow exploit RCEs (among other critical bugs) in core production apps across many top-tier bug bounty programs. And I’m not talking about random targets, these are the kind of programs that pay huge bounties for critical vulnerabilities. I’ve been in the bug bounty scene for a long time, and honestly, this is mind-blowing. It's hard to see this level of success even among well-known hackers. If you want to learn more, come find us next week at @BlackHatEvents (Booth #3257) and @BugBountyDEFCON/@defcon. We will be more than happy to showcase some cool traces and talk more about AI and security!
English
13
8
167
21.2K
Intigriti
Intigriti@intigriti·
You've identified a possible SQLi 🤑 But Cloudflare WAF is in the way... 😓 What if you could just entirely bypass this firewall and get your payload through? 🤠 In our latest article, we documented several ways to identify the origin IP of your target behind popular CDNs and firewalls! Read the article today! 👇 intigriti.com/researchers/bl…
Intigriti tweet media
English
4
47
209
12.9K
Lupin
Lupin@0xLupin·
In a few hours I'm going to release my first video on Youtube ! 🔥 The title: Bypassing a WAF by Finding the Origin IP Hope you'll enjoy the video 🤟
Lupin tweet media
English
33
264
1.4K
0
XBOW
XBOW@Xbow·
XBOW is now the #1 hacker on HackerOne, globally. For the first time, our autonomous AI pentester tops the worldwide leaderboard. Next week at #BlackHat, we’re taking it live: We’ll run real-time on HackerOne programs—come see XBOW find vulnerabilities. 📍 Booth 3257
XBOW tweet media
English
30
68
656
302.4K
James Kettle
James Kettle@albinowax·
Not at Black Hat / DEF CON? You can still join the mission to kill HTTP/1.1: - Watch the livestream from #DEFCON at 16:30 on 8th - Read the whitepaper on our website - Grab the HTTP Request Smuggler update & @WebSecAcademy lab Follow for updates & links. It's nearly time!
English
10
17
179
10.3K