yaala

211 posts

yaala

yaala

@yaalaab

bug bounty hunter

Katılım Ağustos 2015
307 Takip Edilen1.7K Takipçiler
yaala
yaala@yaalaab·
@sho3hit @jobertabma Maybe you are testing with a report that doesn’t have a summary ??
English
0
0
1
30
Shobhit Srivastava
Shobhit Srivastava@sho3hit·
@jobertabma I did the same thing in the month of January, and it wasn’t there. I have logs too. So how did it come up in February?
English
2
0
0
335
Ben Sadeghipour
Ben Sadeghipour@NahamSec·
I'm honestly still in disbelief... grateful to receive a $100k bounty from @meta. Feels surreal. Sharing this to show that with time and dedication, it's possible. This was my first and only submission to Facebook - something I've been chasing for a decade! 🙏 Big thank you to @metabugbounty!
Ben Sadeghipour tweet media
English
543
441
12K
1.1M
yaala retweetledi
RyotaK
RyotaK@ryotkak·
I recently developed and posted about a technique called "First sequence sync", expanding @albinowax's single packet attack. This technique allowed me to send 10,000 requests in 166ms, which breaks the packet size limitation of the single packet attack. flatt.tech/research/posts…
English
15
245
797
122.4K
yaala retweetledi
Bhavuk Jain
Bhavuk Jain@bhavukjain1·
Solved! Chrome debugger was enabled and allowed access via http://localhost:9222/json. This allowed exfiltrating data from other users whosoever was hitting this headless chrome browser - more info here - chromedevtools.github.io/devtools-proto… Thanks everyone for the tips :)
Bhavuk Jain@bhavukjain1

Have a full read SSRF via headless chrome, can access GCP metadata but cannot escalate using the creds (highly restricted). Tried finding any internal/external subdomains (reachable via specific IP addresses) but cannot find any. Any thoughts on how this can be escalated?

English
4
26
152
35.4K
yaala
yaala@yaalaab·
@eman_yazji When you hunt yes. but when shopping It is considered Theft
English
0
0
1
497
Eman Elyazji
Eman Elyazji@eman_yazji·
When you hunt on a shopping website try this trick: Add these items to your cart Item 1: 50$ Item 2: 49$ Change the quantity of Item 2 to -1 (negative amount) Subtotal: 1$ With this trick you can buy Item 1 for 1$ #bugbountytips #bugbountytip #bugbounty
English
3
14
79
9.8K
yaala
yaala@yaalaab·
Sometimes going back to old old versions is not a waste of time. A bug was found in 2022. Title : from username all contact points associated with that account were disclosed in the invalid login error message youtu.be/9-FuYzhBGvo
YouTube video
YouTube
English
0
5
35
5.1K
Kieran Claessens
Kieran Claessens@KieranClaessens·
@yaalaab Impressive finding @yaalaab, thanks for publishing this & congratulations on the bounty! Keep up the great work
English
1
0
1
309
yaala
yaala@yaalaab·
@yaala/account-takeover-and-two-factor-authentication-bypass-de56ed41d7f9" target="_blank" rel="nofollow noopener">medium.com/@yaala/account…
ZXX
9
90
249
20.4K
yaala
yaala@yaalaab·
@gfx_shrey Yes, i forget to mention android
English
0
0
1
411
Shrey
Shrey@gfx_shrey·
@yaalaab Insane man! Those endpoints are from fb android app?
English
1
0
0
457