Shehzad Ali

1.3K posts

Shehzad Ali

Shehzad Ali

@ShehSec

Penetration Tester || Security Researcher

169.254.169.254 Katılım Temmuz 2019
764 Takip Edilen916 Takipçiler
Shehzad Ali retweetledi
the_IDORminator
the_IDORminator@the_IDORminator·
I spent a great deal of time #hacking Salesforce Lightning and have learned quite a bit about it. If you ever see endpoints that end in "/aura", you are probably on one. They are almost always vulnerable to some kind of information leak, due to poor configuration. Poorly secured classes, controllers, methods, and input parameters can lead to so many problems. This one dumped out full order information by orderId only, no authentication. Salesforce IDs look random, but they are not. That 8016T0000020JQsQAZ can be easily iterated as the first bit just refers to an order object. OK BYE
the_IDORminator tweet media
English
7
50
570
22.4K
Shehzad Ali retweetledi
Shehzad Ali retweetledi
Mohsin Khan
Mohsin Khan@tabaahi_·
I asked 10+ top bug hunters who made over $500k+ about their secrets. Here’s what they said: 1. They work insanely hard (280+ hrs/month) even after earning millions. 2. They master 1–3 programs deeply. 3. Speed matters. Never break your momentum. 1/n
English
1
168
972
68.4K
Shehzad Ali retweetledi
Critical Thinking - Bug Bounty Podcast
Prompt injection works a lot better if your message sounds like the data the model was trained on. Some prompt formats that have worked in real bugs:
Critical Thinking - Bug Bounty Podcast tweet media
English
1
18
129
11.4K
Shehzad Ali
Shehzad Ali@ShehSec·
@ghostlulz1337 Would be great if you start Thick Client Apps pentesting or game hacking
English
1
0
1
104
ghostlulz
ghostlulz@ghostlulz1337·
Sometimes I get tired of only posting bugbounty and web app hacking content. I might start posting more stuff related to internal hacking, game cheats, , maldev, and hacking AI. Hopefully you all like these topics as well.
English
2
1
36
2.4K
Shehzad Ali retweetledi
Het Mehta
Het Mehta@hetmehtaa·
BRUTAL TRUTH: 83% of Pentest candidates fail interviews despite having solid technical skills After conducting 50+ security interviews and helping dozens land their dream roles, here's why most fail (and the exact fix) 🧵 #CyberSecurity #InfoSec #TechCareers
English
9
102
603
76.9K
Abdullah Nawaf (HackerX007)🇯🇴
A little story I hope will motivate you: I hadn’t been hunting for almost two months. I was busy with house repairs and building my new setup. As a full-time bug bounty hunter, it was super hard for me because I depend on bug bounty to live! Last week, I felt really down. I was depressed and scared. I kept thinking, "What if I go back to hunting and find nothing? What if I’ve lost my skills?" Two months felt like a long time away from the game. But today, my new setup was finally done. I turned on my PC, still scared of failing, still unsure. To get back into it, I decided to start by retesting some of my old bugs and the subdomains where I found them before. For me, this is always the best way to start after a break. And guess what? Just two hours in, I found a P1 Account Takeover! I was shocked! What I want to say is simple: * Never give up. * Always re-test your old bugs and the subdomains where you found them. * Always try response manipulation on password reset functions that use security questions. (I just changed the API JSON response from 403 to 200, which bypassed the security question and let me change the admin’s password!) This new setup was powered by gifts from @Bugcrowd ! Thanks, and good hunting! #BugBounty #BugBountyTip #BugBountyTips #Bugcrowd #HackerOne #SOC #CyberSecurity #infosec
Abdullah Nawaf (HackerX007)🇯🇴 tweet mediaAbdullah Nawaf (HackerX007)🇯🇴 tweet media
English
23
20
272
9.3K
Shehzad Ali
Shehzad Ali@ShehSec·
@dersonxyz Yes, OTP was checking only at the front end
Peshawar, Pakistan 🇵🇰 English
0
0
2
114
Derson
Derson@dersonxyz·
@TheRoyHunter313 Looks good, but in this case, the OTP bypass only affects the frontend, right?
English
2
0
3
198