Ali Hz ретвитнул
Ali Hz
316 posts

Ali Hz ретвитнул

🔁 JWT vulnerabilities remain a critical attack surface in modern web applications... 🧐
Many applications properly validate JWT signatures but overlook cases such as algorithm confusion attacks, JWK spoofing and other scenarios that can lead to complete authentication bypass! 😎
Our comprehensive guide covers 5+ common JWT misconfigurations, including step-by-step exploitation techniques and practical examples.
Read the article today (link in post below) 👇

English
Ali Hz ретвитнул

Web-Fuzzing-Box by @VulkeyChen is a massive collection of pre-built wordlists and payloads covering everything from content discovery to XSS, SQL injection, 403 bypasses, and brute force attacks! 🤠
Check it out! 👇
github.com/gh0stkey/Web-F…

English
Ali Hz ретвитнул

Ali Hz ретвитнул
Ali Hz ретвитнул

@AliHzSec مرز نوردوز؛ جایی که اینترنتش انگار فقط یک مرحله از تدفین فنی فاصله داره :)) کی قرار این وضعیت داغون درست بشه؟
فارسی
Ali Hz ретвитнул
Ali Hz ретвитнул

@morteza_pn کلا تفکرتون اینه هر کی زحمتی میکشه و پول میگیره باید «چشم ارباب» بگه؟ همه مثل تو جیره خور نیستن که یه خط سفید گرفتی گردن خم کردی
فارسی
Ali Hz ретвитнул
Ali Hz ретвитнул

Polished the MongoBleed PoC a bit to make it more useful. "--auto --decode" is always a good start, if you're not sure.
github.com/Hamid-K/mongob…
English
Ali Hz ретвитнул

🧨 9. Upload + Preview = Stored XSS / Sandbox Escape
site:domain.com "Preview uploaded file"
site:domain.com "View uploaded document"
site:domain.com "Open uploaded file"
site:domain.com "Download your file"
🔥 Why critical:
→ SVG / PDF / HTML polyglots
→ Admin-side XSS
→ CSP bypass opportunities
⸻
☠️ 10. Internal / Forgotten Uploads (Highest ROI)
site:domain.com inurl:admin upload
site:domain.com inurl:dashboard upload
site:domain.com inurl:internal upload
site:domain.com inurl:beta upload
site:domain.com inurl:test upload
🔥 Why critical:
→ Old code
→ No WAF
→ No monitoring
→ Legacy frameworks
— @themasterdoctor1 🧠💻💀
English

خطاب به تابستون فن ها : از لحظه لحظه سگ لرز زدن دارم لذت میبرم
sogand@So0gandd
الان خوشحالید داریم یخ میزنیم؟
فارسی
Ali Hz ретвитнул

Since a lot of you wanted to see @XHackerx007 at #NahamCon2025 Winter edition, we made it happen! 😉

English










