Shakbany
30 posts


كيف قدرت اكتشف blind xss تتفعل في لوحه تحكم ادارة الشركة وتسرب بيانات وهويات المستخدمين مع اسمائهم وبعض المعلومات الشخصية وايضاً الكوكي الخاص بموظفين الشركة
الثغرة ماكانت معقده لكن بشرحها للفائده خلال هاذا الثريد البسيط
#bugbountytips
العربية
Shakbany retweetledi

RCE Bug On T-Mobile's Custom Header
Vulnerable Header:
X-Export-Format: pdf ; Payload
Tip:
Always test your payloads on custom headers, as the header may be vulnerable, as in this case
#BugBounty #bugbountytips #redteam #cybersecurity #Developers #pentest
English

@VictoryArena_sa تذاكر الاول برايم وين البوابة المفترض ينزلني السائق فيها؟
العربية

🚨 Microsoft .NET Bounty Program Update – Up to $40,000 Rewards! 🚨
msrc.microsoft.com/blog/2025/07/.…
Great news for security researchers! Microsoft has officially expanded and enhanced the .NET Bounty Program, offering rewards of up to $40,000 USD for critical vulnerabilities.
What’s new?
Broader scope now includes:
✅ All supported versions of .NET & ASP.NET
✅ ASP.NET Core for .NET Framework (including Blazor & Aspire)
✅ F# and other adjacent technologies
✅ Templates provided with .NET & ASP.NET Core
✅ GitHub Actions in .NET and ASP.NET Core repositories
Award structure updated:
Clearer severity levels, higher payouts for impactful findings, and simplified submission evaluations.
This is a major opportunity for researchers to contribute to securing Microsoft technologies while earning substantial rewards. 💰
If you’re a security researcher focusing on .NET applications, now is the perfect time to get involved!
English

EmploLeaksGuardian focuses on finding leaks in repos across multiple platforms + scans JS files for exposed data.
It also resolves short URLs — one led me to a form with employee names, emails, numbers, and addresses.
Launching very soon.
Hope it helps the community.
#BugBounty

English

If your platform offers paid features (like API integrations or premium tools), never rely solely on the UI to enforce access control.
Always validate subscription status on the backend for every request.
Otherwise, attackers might exploit this and gain full access
#BugBounty
English

Got inspired by a tweet where @sardar0x1 a tip:
“Create a wordlist based on the company name.”
That’s when the idea hit me — so I built a GPT called:
SmartWordlistGen
It automatically generates smart wordlists for any company.
URL:👇
#bugbountytips
English






