ali alhassoun

431 posts

ali alhassoun

ali alhassoun

@deepvvm

bug bounty hunter

Katılım Aralık 2023
191 Takip Edilen795 Takipçiler
0xRIXET
0xRIXET@0xRIXET·
الحمدلله Accepted
0xRIXET tweet media
9
0
101
7K
Turki
Turki@0xTurkiNeptune·
الحمدلله
Turki tweet media
العربية
13
2
50
2.3K
ali alhassoun
ali alhassoun@deepvvm·
Quick Shots In One Day at @Hacker0x01 (:" Privilege Escalation : 1 . After removing the user, I found that the JWT can still be used for up to 2 days after the user has been revoked 2 . Unprotected .JSON Endpoint allowed me to Access Earning History and Pending payments
ali alhassoun tweet mediaali alhassoun tweet mediaali alhassoun tweet media
English
6
4
149
9.8K
Z A D D Y
Z A D D Y@Zaddyzaddy·
Wait programs accept jwt not getting revoked on logout? If that’s the case @BugBunny_ai is sitting on a lot of these
ali alhassoun@deepvvm

Quick Shots In One Day at @Hacker0x01 (:" Privilege Escalation : 1 . After removing the user, I found that the JWT can still be used for up to 2 days after the user has been revoked 2 . Unprotected .JSON Endpoint allowed me to Access Earning History and Pending payments

English
2
0
45
4.8K
Suspect
Suspect@0dsuspect·
تم بفضل الله اكتشاف ثغرة (Authentication Bypass) أدت إلى اختراق كامل للحسابات (Full Account Takeover) في احد الـ chat bots المشكلة كانت في كيفية معالجة الـ OAuth لبيانات المستخدمين وتمريرها عن طريق الAPI
Suspect tweet media
العربية
6
1
54
3.3K
the_IDORminator
the_IDORminator@the_IDORminator·
ETSY uses a lot of integers.... go get those #bugbounty payouts people! Holler here when you find a bug. #bugbountytips Actually buy and sell a product to open up more buttons to push and APIs to call! Duh 😜
the_IDORminator tweet media
English
5
2
117
6.8K