Ahmed🇵🇸𓋹𓆃

671 posts

Ahmed🇵🇸𓋹𓆃 banner
Ahmed🇵🇸𓋹𓆃

Ahmed🇵🇸𓋹𓆃

@junior0x01

Your limit is where you decide to stop𓆃 https://t.co/qpDDQlJ0MH

Katılım Temmuz 2019
2.2K Takip Edilen95 Takipçiler
Sabitlenmiş Tweet
Ahmed🇵🇸𓋹𓆃
Ahmed🇵🇸𓋹𓆃@junior0x01·
@souljamusicc بشتغل رسم وجداريات وهاوي في التصوير ودا شغلي
Ahmed🇵🇸𓋹𓆃 tweet mediaAhmed🇵🇸𓋹𓆃 tweet mediaAhmed🇵🇸𓋹𓆃 tweet mediaAhmed🇵🇸𓋹𓆃 tweet media
العربية
3
6
23
8.4K
Ahmed🇵🇸𓋹𓆃 retweetledi
Tur.js
Tur.js@Tur24Tur·
I just earned $9,000 from a single @Bugcrowd target. 2x P2 Broken Access Control on a 7-year-old public program. To anyone hunting for bugs don't skip old programs. The surface changes, APIs get updated, new endpoints get deployed Fresh bugs appear on old targets all the time. #bugbounty #infosec #bugcrowd
Tur.js tweet media
English
48
29
742
45.7K
Ahmed🇵🇸𓋹𓆃 retweetledi
JS0N Haddix
JS0N Haddix@Jhaddix·
A thread🧵 💸Secrets of automation-kings in bug bounty💸 Finding 1day (or 1month) web exploits that haven't made their into scanners yet can make you big money. Read more to understand where and how to get an edge in this area! 🚨Retweet, follow, & like for more! 🚨 1/x
English
68
543
1.6K
0
Ahmed🇵🇸𓋹𓆃
Ahmed🇵🇸𓋹𓆃@junior0x01·
@the_IDORminator Hello there Just i want to say that u can select one column from any page by pressing **Ctrl** and while that start selecting and dragging the mouse to select that column all then **Ctrl+c** 🙊🔥🔥
Ahmed🇵🇸𓋹𓆃 tweet media
English
0
0
0
482
the_IDORminator
the_IDORminator@the_IDORminator·
Let's talk manual testing for IDORs. I have pasted a payload from a redacted T-Mobile API below. It does not have a bug (that I am aware of) on it, I want to use this for educational purposes because its a great teaching opportunity. A: This is a URI path parameter representing an organization ID. You need to tinker with this. B: The request does not ask for URI parameters, but what if you give it some anyway and something changes? C: Changing things like usernames or ID values in cookies can result in behavioral changes. D: Play with the Authorization Bearer token. Does it check signature? Can you change data in it and it still works? If so... very bad. Is it even using the token, or does it use a cookie instead? E: Its saying this is "upgrade-app". What does that mean? What are other values? What does changing it do? F: This is the organization ID. Its the same as in the URI path. If you change both at the same time, does it work? If you change one but not the other, does it work? Are they checked against each other? G: What does this header mean? It has a JWT format in it? Tinker. H: The API type is declared. Can it be changed? If so, can we alter the backend destination? Hrmm. I: Why is my email address in a header? Can I change it to someone else's? Does it check it? J: IDP type, interesting. What are the other values it accepts? K: You get the idea by now, the app name needs to be tinkered with. What does it do? L: Oh look, my user ID. I wonder if its validated against the organization in the URI or header, or payload body? M: My user ID again. What happens if I change M but not L, or L but not M, or change both, or leave both, or one blank, or null? N: Account number. Is this validated against org, user, neither, both? O: OrgID again, also in F and A. 3 places. Are all 3 checked? Is only 1 checked? Are any checked? Why is life so hard? If you take nothing else away from this, understand the complexity in possible combinations/permutations of potential testing for a SINGLE POST on a SINGLE API end point. This is the way. Oh, yea, and you have to check every single one for SQLi, SSRF, and code execution. Duh. 🤣 #hacking #bugbounty #infosec
the_IDORminator tweet media
English
12
171
794
70.9K
إياد الحمود
إياد الحمود@Eyaaaad·
هكذا بدت حركة الطائرات خلال الساعات الماضية فوق قارة آسيا وأفريقيا وأوروبا. بالنسبة لأوكرانيا والمنطقة بين إيران وفلسطين معروف سبب خلو الطائرات فوقها... لكن الذكي يجيب على هذا السؤال: هناك منطقة كبيرة في الصين لا تطير فوقها الطائرات طوال العام... لماذا؟
إياد الحمود tweet media
العربية
607
389
4.9K
4.3M
Emelia
Emelia@emy21S·
May 26th 2025
Emelia tweet media
English
526
15.1K
33.5K
497.8K