X0Dzeko

2.8K posts

X0Dzeko

X0Dzeko

@X0Dzeko

Katılım Nisan 2024
881 Takip Edilen45 Takipçiler
X0Dzeko retweetledi
Faiyaz Ahmad
Faiyaz Ahmad@thehacktivator·
What if I told you that a seemingly secure endpoint returning 403 Forbidden could still expose another user's data? In my latest video, I demonstrate a lesser-known IDOR bypass technique that can sometimes slip past authorization mitigations implemented by developers. You'll see: • A practical exploitation demo • Why the mitigation fails • A source code walkthrough • The underlying security concepts behind the issue • How developers can properly fix it One of the biggest mistakes in web application security is assuming that a blocked request automatically means the underlying authorization logic is secure. This video shows why that's not always the case. Watch here: youtu.be/lUqj1ekvf1E
YouTube video
YouTube
Faiyaz Ahmad tweet media
English
2
9
75
2.1K
X0Dzeko retweetledi
encodedguy - jsmon.sh
encodedguy - jsmon.sh@3nc0d3dGuY·
🚨Bug bounty hunters - radar.jsmon.sh is live! Free Vertical Reconnaissance on any target. Headers, JS files, endpoints, secrets, GraphQL operations, parameters, cloud assets, all in one place. Retweet to share it with the security community!
English
3
18
133
6.8K
X0Dzeko retweetledi
shaimaa hafez
shaimaa hafez@shimaah42·
كان معايا واحد في الشغل حقيقي كل كلمه كان بيقولها ب نكته كل كلمه بيقولها بتضحكنا، دمه خفيف لدرجه انه كان فعلا مبيبطلش يخلينا نضحك فاكره مره جه الشيفت لقيته بيقولي انا عاوز احكيلك حاجه قولتله اتفضل، قالي انا امبارح اتشخصت أن عندي اكتئاب
العربية
2
337
6.6K
545.5K
X0Dzeko retweetledi
Het Mehta
Het Mehta@hetmehtaa·
Someone made a website that discloses every scam done by a bug bounty program bugbountyscam.com
Het Mehta tweet media
English
36
173
1.3K
61.8K
X0Dzeko retweetledi
Cyber Detective💙💛
Cyber Detective💙💛@cyb_detective·
DARKWEB & DATA BREACH OSINT Tor, IP2, FreeNet and other platforms Clearnet and onion search engines How to scrape Darkweb Darkweb news Tutorials, web sites and blogs start.me/p/xjvDyJ/dark-…
Cyber Detective💙💛 tweet media
English
3
51
213
12.6K
bugcrowd
bugcrowd@Bugcrowd·
If your hands are full of PoCs, payloads, and half-finished writeups… Ours are full of Bugcrowd swag for you 🎁🧡 Tag a hacker who’s been working hard lately. We’ll randomly pick two of you to each win a Bugcrowd t-shirt!
English
46
0
74
8.3K
X0Dzeko retweetledi
YesWeHack ⠵
YesWeHack ⠵@yeswehack·
LLMs are becoming integral to #BugBounty workflows – but without real human expertise, the result is just AI slop 🗑️ Our latest guide covers agentic CLIs, MCP servers and why manual PoC validation is still non-negotiable 👇 yeswehack.com/learn-bug-boun…
English
1
30
132
5K
X0Dzeko retweetledi
obscaries ❘ AppSec
obscaries ❘ AppSec@obscaries·
🕵️‍♂️ graphql-cop: Automated Security Auditing for GraphQL APIs I came across graphql-cop, a Python 🐍 tool that automatically tests GraphQL endpoints for common vulnerabilities. It helps security researchers quickly identify misconfigurations without manually crafting attack queries. 🔍 What it detects: 🧠 Introspection exposure (schema leaks) ⚡ Alias overloading & batching abuse (DoS vectors) 🐛 Debug/tracing modes left enabled 🌐 GET-based query execution (CSRF risks) 💡 Field suggestion leaks & misconfigurations For bug bounty hunters 🏴‍☠️ and pentesters, tools like this provide a fast baseline of GraphQL-specific attack surfaces. But remember—automated scanning is just the first step. The real impact comes from manual testing of authorization logic, query complexity, and business logic flaws 🎯 📦 Source: github.com/dolevf/graphql… #BugBounty #GraphQL #APIsecurity #AppSec #InfoSec
obscaries ❘ AppSec tweet media
English
0
12
73
3.4K
X0Dzeko retweetledi
HackProve
HackProve@hackprove_·
🧠 Bug Bounty in 2025: Hunting Business Logic Flaws the Right Way @kailasv678/bug-bounty-in-2025-hunting-business-logic-flaws-the-right-way-614aba550f7b" target="_blank" rel="nofollow noopener">medium.com/@kailasv678/bu…
English
1
2
20
673
X0Dzeko retweetledi
HackProve
HackProve@hackprove_·
My First 150 Days Bug Bounty Hunting @YourFinalSin/my-first-150-days-bug-bounty-hunting-034623c89836" target="_blank" rel="nofollow noopener">medium.com/@YourFinalSin/…
English
0
2
35
1.6K
X0Dzeko retweetledi
obscaries ❘ AppSec
obscaries ❘ AppSec@obscaries·
🚨 SSRF in Next.js Apps – Interesting Research If you're testing modern web apps, this is a great read from Assetnote on how SSRF can appear in Next.js applications. Key attack surfaces they discuss: 🔹 /_next/image endpoint 🔹 Redirect-based bypass tricks 🔹 Server Actions behavior 🔹 Host header manipulation Modern frameworks = new bug hunting opportunities. 🕵️‍♂️ 🔗 assetnote.io/resources/rese… #BugBounty #AppSec #WebSecurity #NextJS #SSRF
obscaries ❘ AppSec tweet media
English
1
30
142
5.8K
X0Dzeko retweetledi
HackProve
HackProve@hackprove_·
Google Dorks for Bug Bounty Hunting: 25 Powerful Dorks to Find Exposed PDFs, NDAs, and Signatures @hackersatty/google-dorks-for-bug-bounty-hunting-25-powerful-dorks-to-find-exposed-pdfs-ndas-and-signatures-cf8c54e19189" target="_blank" rel="nofollow noopener">medium.com/@hackersatty/g…
English
0
5
54
3.8K