Ali Kareem

263 posts

Ali Kareem banner
Ali Kareem

Ali Kareem

@mysanismine

Just a bug bounty hunter :-) https://t.co/5hzbfB7F4c

Katılım Ocak 2020
57 Takip Edilen2.5K Takipçiler
Alex Birsan
Alex Birsan@alxbrsn·
hey @Bugcrowd can we please make this checkbox do something thanks
Alex Birsan tweet media
English
29
27
391
17.9K
Ali Kareem
Ali Kareem@mysanismine·
@Hamadrt عندك كم شخص بالكومنتات دائما يعارضوك وهمة كلهم خطأ اهدافك دائما للمستوى البعيد اثق فيها ولحد هسة اتذكر توقعك بهبوط البتكوين 73 في عز البول ماركت بشهر 1/2025 للبتكوين وكان دقيق جدا حقيقة
العربية
2
0
1
861
Ali Kareem
Ali Kareem@mysanismine·
@h4x0r_dz Wait, you guys really pay for AI? I use it for free.
English
0
0
2
820
H4x0r.DZ 🇰🇵
H4x0r.DZ 🇰🇵@h4x0r_dz·
Goodbye Claude Max Welcome Kimi K2.6 and deepseek-v4
H4x0r.DZ 🇰🇵 tweet media
English
48
31
625
39.1K
Ali Kareem
Ali Kareem@mysanismine·
@krishnsec Yea, until they ban you for no logical reason.
English
0
0
3
377
Kanhaiya Sharma
Kanhaiya Sharma@krishnsec·
One reliable bb program > 100 chaotic programs
English
5
1
99
7.8K
Ali Kareem
Ali Kareem@mysanismine·
@0xMstar What's the benefit? Less usage of resoruces maybe.
English
1
0
0
139
Ali Kareem
Ali Kareem@mysanismine·
@rez0__ Cloud code (AI agents in general) is the new nuclei. If it spreads widely then what the difference between it and nuclei? In the field of bug bounty, if you don't have something unique then you will end by getting more duplicates.
English
0
0
6
602
Ali Kareem
Ali Kareem@mysanismine·
@zhero___ @inzo____ How can I reach you? I can't DM. I need to discuss something really important with you.
English
0
0
2
312
zhero;
zhero;@zhero___·
Happy to publish our first research of the year on the SvelteKit framework, downloaded over 800,000 times per week, which led to CVE-2025-67647 (w/@inzo____): Avoiding the paradox: A native full-read SSRF and one‑shot DoS in SvelteKit zhero-web-sec.github.io/research-and-t… Enjoy the read
zhero; tweet media
English
8
61
344
16.1K
Ali Kareem
Ali Kareem@mysanismine·
@harbihodun2000 @Hacker0x01 I may share some tips from time to another but I've already decided to share everything once I retire from this field.
English
0
0
0
114
Habby
Habby@harbihodun2000·
@mysanismine @Hacker0x01 If you could share a roadmap on how you started from the beginning until not about being a bug hunter, what would it be🙏
English
2
0
3
607
Tomi 🥀
Tomi 🥀@archyxsec·
Last quarter, I reached my peak as a full manual bug hunter, achieving personal goals that I never thought possible when I started my full-time adventure just over a year ago. Cross 3100 reputation and >29 impact reach top 9 globally. Thanks @Hacker0x01
Tomi 🥀 tweet media
English
10
4
152
6.1K
Ali Kareem
Ali Kareem@mysanismine·
@cyberx00t @Masonhck3571 Mostly company work policies. Personally I consider them wrong policies that don't generate positive results with hackers.
English
0
0
1
40
Masonhck357
Masonhck357@Masonhck3571·
I wasn’t going to say anything….but I have to agree with everyone’s sentiment on how long it’s been taking to get payouts going. I have over $20k in subs, between two platforms, that are already fixed and it’s been dead silent on them. Just me asking for updates🤷🏽‍♂️ Platforms, I’ve been asking this for years, but at what point do you hold these program owners accountable? Hell Hackerone has a badge for people who wait over 6 months for a bounty lol. That shouldn’t even be a thing. Researchers don’t bust their ass trying to be the first to find a vulnerability to feel absolutely forgotten. *Opinions are that of my own and do not represent my employer*
English
11
3
139
16.5K
Ali Kareem
Ali Kareem@mysanismine·
@0xMstar @Hacker0x01 Me too actually, no wildcard at all. Most of the invites are on demand and I hate this racing programs. No to mention already milked programs that launched before on H1 and then transfer to Bugcrowd. Also I think lately they've increased the number of hackers who are invited.
English
1
0
2
362
Ali Kareem
Ali Kareem@mysanismine·
@Itx_Shad0w @Linktree_ @Bugcrowd Well, I had the same situation before more than once but Bugcrowd Triagers did their job, so just open appeal and wait. That's all what you can do.
English
0
0
0
247
TESS
TESS@ArmanSameer95·
Oh wow, I’m the top 2nd hacker in the United States on the @Bugcrowd platform.
TESS tweet media
English
9
2
73
3.3K
Ali Kareem
Ali Kareem@mysanismine·
Ranked #8 on the @Bugcrowd P1-P2 Leaderboard for July 2025!
Ali Kareem tweet media
English
3
0
51
3.4K
Ali Kareem
Ali Kareem@mysanismine·
Don't rely always on sqli time based payloads. I came across endpoint, from my experience I was sure that it was vulnerable but I couldn't confirm it using time based payloads. Using "AND" 1=1 or "AND" 1=0 the result was different from "none" to display records. #bugbounty
Ali Kareem tweet media
English
0
0
24
2.2K