Sabitlenmiş Tweet
Al-hassan abbas | الحسن عباس
478 posts

Al-hassan abbas | الحسن عباس
@exploit_msf
Certifed : #Ecptxv2 #Oscp #Ecpptv2 #Ceh11 #Ejpt #ECES #Metasploit_pro_specialist #Ewpt #Ceh_master Snap & instagram : exploit.msf CVE-2021-40303
Iraq Katılım Aralık 2019
55 Takip Edilen3.3K Takipçiler

Just got a reward for a vulnerability submitted on @yeswehack -- Improper Access Control - Generic (CWE-284). yeswehack.com/hunters/exploi… #YesWeRHackers

English

Yay, I was awarded a $500 bounty on @Hacker0x01! hackerone.com/exploitmsf #TogetherWeHitHarder #bugbountytip
Tip: GraphQL Voyager via /api/graphql/voyager

English

Just got a reward for a vulnerability submitted on @yeswehack -- Cross-site Scripting (XSS) - Reflected (CWE-79). yeswehack.com/hunters/exploi… #YesWeRHackers

English

Just scored a reward @intigriti, Bounty+Bouns $500 app.intigriti.com/profile/exploi… #HackWithIntigriti
Tip: Unauthenticated Grafana

English

I earned $300 for my submission on @bugcrowd bugcrowd.com/h/alhasan_abbas #ItTakesACrowd
Tip: CVE-2025-4123

English

Just got a reward for a vulnerability submitted on @yeswehack -- Cross-site Scripting (XSS) - Stored (CWE-79). yeswehack.com/hunters/exploi… #YesWeRHackers

English

@no_zidan @Hacker0x01 Httpbin simple http server for requests and response
English

I was awarded a $300 bounty on @Hacker0x01! hackerone.com/exploitmsf #TogetherWeHitHarder
Tip: 1 XSS via httpbin & 2 Url redirect via httpbin



English

@0xsaiyann @Hacker0x01 Not all programs close url redirect as NA
Httpbin simple http server for requests and response
English

@exploit_msf @Hacker0x01 What is httpbin? And how did they reward you for open redirect? I just get NA for that
English

I earned $200 for my submission on @bugcrowd bugcrowd.com/alhasan_abbas #ItTakesACrowd #bugbountytips
Tip: CVE-2022-46463 Download repo's in harbor

English

@h4x0r_dz @intigriti Yes, it was airflow web app then you need to access to admin airflow then you can read user,pass for jenkins in anothet port then get rce from jenkins then you need get root using python script with rwx permissions
English

Just scored a reward 1875€ @intigriti #HackWithIntigriti #bugbountytips
Tip: I played ctf this year and i found this vulnerability because i solve machine challenge with same bug
If you found apache airflow use flask-unsign to found secret key and generate new jwt for admin

English

@h4x0r_dz @intigriti Thanks
I don't remember name 🥲
English

I was awarded a $290 bounty on @Hacker0x01! hackerone.com/exploitmsf #TogetherWeHitHarder #bugbountytips
Tip: CVE-2025-29927 via /admin

English

I was awarded a $350 bounty on @Hacker0x01! hackerone.com/exploitmsf #TogetherWeHitHarder
Tip: CVE-2025-0133 RXSS

English








