indexe
42 posts

indexe
@_indexe
Cyberbullying and cybersecurity enthusiast
Katılım Eylül 2024
252 Takip Edilen516 Takipçiler

یالااااااااا . اولین RDP
تو بدترین شرایط کاری و روحی زدمش ولی خب تو این شرایط برای اینکه جدا نشم از کار، شده بود روزی ۵ دقیقه هم فقط میخوندم یه رایت آپ خودم رو وصل نگه داشتم .هر چند یه مدتی شده بودم سلطان دوبلیکیت و NA و کلا باگ زدن اوت آف اسکوپ :D
مرسی از @voorivex

فارسی

@Muntrive @Hacker0x01 I had a similar case that took me a month, three disclosed reports, and even a research paper just to explain what OAuth and one-click ATO are—only for it to be triaged as Low. Before that, they even insisted I self-close the report to avoid damaging my reputation.
English

after a long time, I decided to write a blog post about one of the old bugs I found in an Android app, which finally led me to achieve 0-Click Mass Account TakeOver
it's now published, you can read it here :
blog.voorivex.team/0-click-mass-a…
English

Result:
payload from attacker origin executes on target.com.
can be used to bypass WAFs more conveniently since there is no malicious payload in the URL.
English

Found a neat XSS trick chaining two primitives: `javascript:` scheme + `window.name`
English

Nothing like catching a juicy XSS that leads to full ATO Had an awesome time teaming up with my partner in crime @DanialXray on this one — team work pays off!
#BugBounty
@voorivex

English

1 click ATO 👾
Popped my first RDP ! with my bestie @MalekaniPouyan 🔥

idoitbefore2027@intranterr
First blood !🩸Just landed my first bug in the hell 👾🔥 ty to my master @voorivex
English

امروز اولین xss امو زدم و خیلی خوشحالم بااینکه اصن نمیدونم بابتش پول میدن یا نه چون سایت ایرانیه ولی اصن پوله مهم نیست.
مهم اینه که اولین جوونه ی تلاشامو دیدم با اینکه وقت کافی نذاشتم واسش.
مرسی واسه این حس خوب یاشار ❤️
@voorivex
دوس نداره بهش بگیم استاد ولی خفن ترین استاد دنیاس

فارسی












