Ahsan Shahid

3.4K posts

Ahsan Shahid banner
Ahsan Shahid

Ahsan Shahid

@hunter0x8

🏆 Top 100 Ethical Hacker on @YesWeHack 🛡️ Synack Red Team %3d, %26%2340%3b, ( <<%0a%0d%26lt%3B $$ x=1 $$

Faisalabad, Punjab Katılım Kasım 2019
1.5K Takip Edilen2.2K Takipçiler
Sabitlenmiş Tweet
Ahsan Shahid
Ahsan Shahid@hunter0x8·
My first Writeup @ahsan.shahid/resolveuri-rxss-imperva-waf-bypass-c834ca573bd4" target="_blank" rel="nofollow noopener">medium.com/@ahsan.shahid/… #BugBounty #wafbypass
English
9
48
146
0
Biscuit
Biscuit@OreoB1scuit·
did you guys find Arjun tool ever useful ? #bugbounty
English
12
0
35
6.7K
Damian Strobel
Damian Strobel@damian_89_·
@OreoB1scuit In the beginning, later got bad because of too many not well designed features.
English
1
0
1
670
Ahsan Shahid retweetledi
Renwa
Renwa@RenwaX23·
I have been using AIs to find bugs recently and came across a cool site-wide DOM-XSS using Cookie Injection, here is the story of the finding and current state of bug hunting... @renwa/site-dom-xss-using-cookie-injection-the-ai-hackers-are-coming-faster-than-you-think-3ef82f2a991d" target="_blank" rel="nofollow noopener">medium.com/@renwa/site-do…
English
5
53
373
25.3K
Ahsan Shahid retweetledi
DinDinDin
DinDinDin@comores_11·
🔥 XSS Tip: Unicode Normalization Don't give up if <, >, " or ' are filtered ! Many apps normalize Unicode after the WAF/security layer. Some bypass variants (URL-encoded): 🔹 < ➔ %EF%BC%9C 🔹 > ➔ %EF%BC%9E 🔹 " ➔ %EF%BC%A2 🔹 ' ➔ %EF%BC%87 🔹 ` ➔ %EF%BD%80 For example, inject %EF%BC%9Cscript%EF%BC%9E and check if it reflects as