hesar

675 posts

hesar banner
hesar

hesar

@hesar101

Germany Katılım Ocak 2022
772 Takip Edilen936 Takipçiler
hesar retweetledi
PortSwigger Research
PortSwigger Research@PortSwiggerRes·
The voting has concluded, and we're thrilled to announce the top ten web hacking techniques of 2025! Massive thanks to everyone in the community for sharing their hard-earned discoveries, plus the panel and everyone who nominated or voted! portswigger.net/research/top-1…
English
2
75
234
44.2K
hesar retweetledi
OSINTdefender
OSINTdefender@sentdefender·
Footage published by Iran International which appears to show multiple bodies laying on the ground outside Alghadir Hospital in Eastern Tehran, following massive anti-government protests in the capital overnight on Thursday.
English
72
411
1.9K
281.2K
hesar
hesar@hesar101·
As a security professional, I usually don’t tweet about daily news. But this time, it’s about people’s lives. The Islamic Republic has shut down the internet and phone services and is massacring people :))
English
0
0
1
60
hesar retweetledi
Ben Sadeghipour
Ben Sadeghipour@NahamSec·
Really disappointed to see @Hacker0x01 do this. I also had a similar interaction with h1 about a month ago where they questioned my nationality and place of residence after 10+ on the platform.
YS@YShahinzadeh

I’ve been hunting on H1 for almost 3 years, ranked #18 in 2025, have always tried to contribute positively to the hacker community. I’ve earned around $500k in bounties and was on the road to $1M. Yet I don’t even have HSM, and I feel I haven’t been recognized as I should 1/4

English
20
52
630
90K
Youssef Sammouda (sam0)
Youssef Sammouda (sam0)@samm0uda·
Due to the repeated screw-ups and zero transparency around bans by @Hacker0x01, I’ve chosen to leave with dignity. My account is now fully deactivated and to be removed. If you need my services, I’m still available at @Bugcrowd @intigriti @immunefi @HackenProof @StandoffBB
YS@YShahinzadeh

I’ve been hunting on H1 for almost 3 years, ranked #18 in 2025, have always tried to contribute positively to the hacker community. I’ve earned around $500k in bounties and was on the road to $1M. Yet I don’t even have HSM, and I feel I haven’t been recognized as I should 1/4

English
13
34
529
55.1K
hesar
hesar@hesar101·
@samm0uda @Hacker0x01 @Hacker0x01 @jobertabma Yashar is one of the best hunters I know. What you did without transparency is very disappointing and can be discouraging, especially for those who look up to Yashar and other top-ranked hunters on H1 as role models. Please review this matter.
English
0
0
0
316
Youssef Sammouda (sam0)
Youssef Sammouda (sam0)@samm0uda·
@Hacker0x01 is now banning people without explanation or providing how the terms and conditions were violated. While other platforms are advancing, H1 revolutionary new vision is to track hackers on social media, make assumptions and ban them without a real proof.
English
14
75
501
128.8K
nedwill
nedwill@NedWilliamson·
I didn't know how to explain it at the time but we have words for my bug report now: I used the SSDP RFC -> LLM-generated EBNF grammar -> vibe-coded Rust compiler for EBNF to Protobuf -> vibe-coded C++ frontend -> vibe-coded root cause -> vibe-coded report issues.chromium.org/issues/40070891
English
3
7
59
7.4K
hesar
hesar@hesar101·
@deadvolvo Yo congrats bro! 😍 Drop some pics when you set it up 🫠
English
0
0
0
25
hesar retweetledi
James Kettle
James Kettle@albinowax·
HTTP Request Smuggler v3.0.1 is now live! This fixes a false positive in the CL.0 scan caused by pipelining - thanks to @sw33tLie for the report. Note that the new parser discrepancy scan still has superior accuracy. For more info on pipelining check out portswigger.net/research/how-t…
English
4
58
269
12.6K
d3d aka dead (dead, мёртв, 死了)
Today I join @Akamai as a Senior Security Researcher and I am very excited to keep pushing the boundaries of both offensive and defense research to help make the internet a little harder for the bad guys to break. 🔥🥲😜
English
47
8
378
20.2K
hesar
hesar@hesar101·
@safasafari3 یه سینگل پکتمون نشه ؟ جالب تر اینکه خودش صفر میشه ، اسکریپت نوشتن براش ، از روشای کنترل ریس کاندیشنه
hesar tweet media
فارسی
1
0
0
37
Sky Desperados
Sky Desperados@skydesperados·
Last month, I found a 0-click account takeover with a very simple match-and-replace trick Sometimes applications have different API endpoints for different functions. For authentication, developers often use session cookies or exchange tokens. In some cases, if the main session is deleted, the application falls back to using another cookie or a unique ID in the headers for authentication By inspecting the JavaScript and requests, I noticed this behavior. If the main session wasn’t available, the app would accept the unique ID in the header and automatically set new cookies So, I deleted the main session and simply replaced the header with the unique ID — which led to account takeover
Sky Desperados tweet media
English
63
66
864
41K
hesar retweetledi
Gospel
Gospel@4osp3l·
I was expecting this after i saw @albinowax post on HTTP pipelining, haha; btw @intigriti triage team are just nice.
Gospel tweet media
English
6
7
148
10.4K