Ahmed Ezzat
6 posts

Ahmed Ezzat
@BitTheByte
Penetration testing specialist @EG_CERT | Reverse Engineer | Bounty Hunter
Cairo, Egypt เข้าร่วม Eylül 2015
255 กำลังติดตาม324 ผู้ติดตาม

@BitTheByte انت بتزلني يعم.منتا لو صاحب سالك كنت جيت تhunt معايا مش تقولي امتحانات وكلام فارغ😢
العربية

@BitTheByte Parameters. Its a normal get based SSRF, with no host header
English

When testing for SSRF, change the HTTP version from 1.1 to HTTP/0.9 and remove the host header completely. This has worked to bypass several SSRF fixes in the past.
#bugbountytip #bugbountytip #bugbounty
English

Whoops 😎! I've been acknowledge on #Microsoft #Security #Researcher page for my finding! Thanks @msftsecresponse !
portal.msrc.microsoft.com/en-us/security…

English
