Sadra

559 posts

Sadra banner
Sadra

Sadra

@MrMSA16

18 y/o, Bug Hunter, Security Researcher

Katılım Ekim 2020
501 Takip Edilen3.3K Takipçiler
Sadra retweetledi
Noah Zweben
Noah Zweben@noahzweben·
Announcing a new Claude Code feature: Remote Control. It's rolling out now to Max users in research preview. Try it with /remote-control Start local sessions from the terminal, then continue them from your phone. Take a walk, see the sun, walk your dog without losing your flow.
English
1.5K
1.3K
16.9K
4.5M
Sadra retweetledi
23
23@0X23XO·
Voorivex's classes aren't just classes there's a smth BEYOND class. Special tnx 2 Sadra 4 this gifts hope to more bugs and more bounties 4 u, I love these books 🩷🫶🏿 @MrMSA16 @voorivex I wanna mention one of ma classmates who gave me his gift but don't have his ID :(
English
7
4
75
6K
AmirMohammad Safari
AmirMohammad Safari@AmirMSafari·
Nicely crafted payload for the onbeforematch event handler with @nowaskyjr. I used it to build a payload that bypasses Cloudflare WAF. The interesting part? If you remove }_, the payload stops working :D
AmirMohammad Safari tweet media
Nowasky@nowaskyjr

Combining two techniques I recently showed: attribute merging of <html>/<body> tags and using hidden=until-found to trigger onbeforematch via fragment navigation in Firefox. #xss" target="_blank" rel="nofollow noopener">storage.googleapis.com/nowaskyjr/poc_… #xss

English
7
9
118
8.3K
Amirabbas Ataei
Amirabbas Ataei@ImAyrix·
For the past year, I've been using a private wordlist generated from actual bug bounty reports. I grabbed disclosed report texts by simply appending .json to the report URLs (as shown below) and fed them into fallparams to mine parameters from the included requests and snippets.
Amirabbas Ataei tweet mediaAmirabbas Ataei tweet media
English
11
27
291
19.8K
YS
YS@YShahinzadeh·
this one is brilliant! you may have seen GIS OAuth during hunting (I have, many times), XSS + ATO. I recommend reading and studying this write-up (author does not have X acc)✌🏻 blog.voorivex.team/not-so-dirty-d…
English
10
44
300
15.6K
 یاشو
 یاشو@voorivex·
یالله بچه‌های Voorivex. تاریخ تاریخ تکرار میشه 😎
 یاشو tweet media یاشو tweet media
فارسی
10
1
184
9.9K
Sadra retweetledi
YS
YS@YShahinzadeh·
new to Google VRP, seems google does not define the bounty amount right after triage, the bug is on an AI product (I cannot name it here), I'm not sure how much bounty should I expect here
YS tweet media
English
15
8
313
18.4K
Sadra retweetledi
AmirMohammad Safari
AmirMohammad Safari@AmirMSafari·
If a CSPT bug can't be exploited on the same origin, you can pivot it to another one. Cloudflare Image Transform can act as a cross‑origin gadget to reach more sensitive endpoints on different origins - you can read more about it here ;) blog.voorivex.team/cloudflare-ima…
English
26
43
288
19.9K
Sadra retweetledi
Youssef Sammouda (sam0)
Youssef Sammouda (sam0)@samm0uda·
Due to the repeated screw-ups and zero transparency around bans by @Hacker0x01, I’ve chosen to leave with dignity. My account is now fully deactivated and to be removed. If you need my services, I’m still available at @Bugcrowd @intigriti @immunefi @HackenProof @StandoffBB
YS@YShahinzadeh

I’ve been hunting on H1 for almost 3 years, ranked #18 in 2025, have always tried to contribute positively to the hacker community. I’ve earned around $500k in bounties and was on the road to $1M. Yet I don’t even have HSM, and I feel I haven’t been recognized as I should 1/4

English
13
34
529
55K
Sadra retweetledi
YS
YS@YShahinzadeh·
I’ve been hunting on H1 for almost 3 years, ranked #18 in 2025, have always tried to contribute positively to the hacker community. I’ve earned around $500k in bounties and was on the road to $1M. Yet I don’t even have HSM, and I feel I haven’t been recognized as I should 1/4
YS tweet media
Youssef Sammouda (sam0)@samm0uda

@Hacker0x01 is now banning people without explanation or providing how the terms and conditions were violated. While other platforms are advancing, H1 revolutionary new vision is to track hackers on social media, make assumptions and ban them without a real proof.

English
40
126
795
255.6K
Sadra retweetledi
Youssef Sammouda (sam0)
Youssef Sammouda (sam0)@samm0uda·
@Hacker0x01 is now banning people without explanation or providing how the terms and conditions were violated. While other platforms are advancing, H1 revolutionary new vision is to track hackers on social media, make assumptions and ban them without a real proof.
English
14
76
501
128.4K
YS
YS@YShahinzadeh·
just crossed 10k on H1
YS tweet media
English
24
1
320
11.3K
Sky Desperados
Sky Desperados@jusxing·
Last month, I found a 0-click account takeover with a very simple match-and-replace trick Sometimes applications have different API endpoints for different functions. For authentication, developers often use session cookies or exchange tokens. In some cases, if the main session is deleted, the application falls back to using another cookie or a unique ID in the headers for authentication By inspecting the JavaScript and requests, I noticed this behavior. If the main session wasn’t available, the app would accept the unique ID in the header and automatically set new cookies So, I deleted the main session and simply replaced the header with the unique ID — which led to account takeover
Sky Desperados tweet media
English
63
66
868
41K
Sadra retweetledi
Omid Rezaei
Omid Rezaei@omidxrz·
after a long time, I decided to write a blog post about one of the old bugs I found in an Android app, which finally led me to achieve 0-Click Mass Account TakeOver it's now published, you can read it here : blog.voorivex.team/0-click-mass-a…
English
23
51
347
26K
Sadra retweetledi
Omid Rezaei
Omid Rezaei@omidxrz·
after many unlucky moments in bug bounty, july was fun with interesting findings, I made around $30k bounty, mostly from XSS and OAuth in august, I've planned to dive deeper into client-side stuff
Omid Rezaei tweet mediaOmid Rezaei tweet mediaOmid Rezaei tweet mediaOmid Rezaei tweet media
English
66
23
630
32.3K