Djinn

5K posts

Djinn banner
Djinn

Djinn

@top_djinn

I hack for 🍕 | Red Teamer | Author | Speaker | Bug Bounty Hunter @YesWeHack | Whitehat @Immunefi | 😶 🇵🇰 🇵🇸

Planet Earth Katılım Aralık 2021
474 Takip Edilen106 Takipçiler
Djinn retweetledi
Behi
Behi@Behi_Sec·
A few months ago, I found a Prompt Injection vulnerability on Google Tasks. It was simple, yet tricky. Google rewarded me with a $15,000 bounty for it. Here's the full story:
English
13
65
589
26.9K
Djinn retweetledi
Ahmed Elmorsi 🇵🇸
Ahmed Elmorsi 🇵🇸@0Xhunterx·
This might be the best IDOR I achieved so far with $$$$ 1- I tried every possible way to access, edit, or delete the target object but nothing works because the team implemented the proper authorization mechanism for that ----
Ahmed Elmorsi 🇵🇸 tweet media
English
17
13
304
10.2K
Djinn retweetledi
Arshad Kazmi
Arshad Kazmi@arshadkazmi42·
$500 bounty on @Hacker0x01. Found with Claude Code Added a triage step in my prompt that spawns a new agent with no existing context to verify the finding. False positives have dropped a lot got this idea from someone's tweet, can't remember who. If it was you, thanks
Arshad Kazmi tweet media
English
7
3
218
10.1K
Djinn retweetledi
Arshad Kazmi
Arshad Kazmi@arshadkazmi42·
Two bounties on @intigriti. $3000 + $100 Both bypasses of previously resolved reports 1 year ago: ChatGPT + a lot of manual work to find one of these Today: gave the old reports to Claude Code, it confirmed the fixes and found bypasses for both. Fully automated Workflow has changed completely Old writeup: medium.com/bugbountywrite… Old tweet: x.com/arshadkazmi42/…
Arshad Kazmi tweet mediaArshad Kazmi tweet media
English
5
11
207
8.9K
Djinn retweetledi
Godfather Orwa 🇯🇴
Godfather Orwa 🇯🇴@GodfatherOrwa·
@damian_89_ I’ve built a script yesterday for running deepseek 4 pro on a full source code, to do code review I can share the results today with you when it’s done 👍, so far working well
English
1
1
52
2.8K
Djinn retweetledi
cyber_shree
cyber_shree@shreerajaput·
Found that just using a user ID could generate a valid session token, leading to account creation without proper authentication. Simple but high impact → triaged as P1. Good reminder: auth & session logic needs deep testing 🔍 #BugBounty #CyberSecurity #AppSec #AuthBypass #P1
cyber_shree tweet media
English
5
8
206
6.2K
Djinn retweetledi
a7madn1
a7madn1@a7mad__n1·
Second Write up: Yeah I got my second bonus $$$ on a public bug bounty program. (EASY Tecnic). Steps To Reproduce: 1/n 1.Identify multiple contact forms & Observe that all forms are protected by CAPTCHA. 2. The full endpoint /_vcp/test/_test/contactprocess/
a7madn1@a7mad__n1

Alhamdullah, I got my second bonus $$$ on a public bug bounty program at HackerOne. Happy to secure a new BBP. Soon I will share my second write up, and my last bugs on Hackerone in my channel t.me/a7madn1 Stay tuned. #bugbounty #hackerone #infosec #cybersecurity

English
4
8
144
10.9K
Djinn retweetledi
Shivang
Shivang@shivangmauryaa·
Bounty : 250 Euro Well admin can only invite admin and low level user. POST /api/users/invite/ Expected : role":"admin" Changed to : role":"SuperAdmin" I got invited as superadmin. Got Fixed and rewarded in 8 hours haha
Shivang tweet media
English
4
9
235
5.9K
Djinn retweetledi
VIEH Group
VIEH Group@viehgroup·
HTTP Request Smuggling -> Auth Bypass POC -> 1. Found mismatch in frontend & backend parsing 2. Crafted request with conflicting headers 3. Backend processed hidden request 4. Bypassed authentication controls\ #infosec #bugbounty #bugbountytips
VIEH Group tweet media
English
0
3
30
716
Djinn retweetledi
Shad0w
Shad0w@Itx_Shad0w·
For years, Google API keys (AIza...) had little to no real-world impact. But recently, many of them unexpectedly gained access to Google Gemini. curl "generativelanguage.googleapis.com/v1/models?key=…" This appears to be a widespread misconfiguration that can be hunted in the wild.
Shad0w tweet media
English
12
35
423
15.6K
Djinn retweetledi
Ben Sadeghipour
Ben Sadeghipour@NahamSec·
I've been in the bug bounty scene for over a decade now. $2M in bounties later, I figured it was time to sit down and talk about everything I've learned! 👉🏼 youtube.com/watch?v=pbu7El…
YouTube video
YouTube
Ben Sadeghipour tweet media
English
7
32
348
21.8K