𝐴ℎ𝑚𝑒𝑑 𝐺𝑎𝑚𝑖𝑙

649 posts

𝐴ℎ𝑚𝑒𝑑 𝐺𝑎𝑚𝑖𝑙 banner
𝐴ℎ𝑚𝑒𝑑 𝐺𝑎𝑚𝑖𝑙

𝐴ℎ𝑚𝑒𝑑 𝐺𝑎𝑚𝑖𝑙

@algamil7x

bug bounty hunter ⇜

Ismailia شامل ہوئے Ağustos 2017
426 فالونگ4.6K فالوورز
Rodolfo Assis
Rodolfo Assis@RodoAssis·
I'm about to release an open source recon tool on GitHub. Try to get the most URLs out of its testbed with your recon methods (in the shortest time possible) and let me know in the comments! recon.brutelogic.net
English
1
1
9
737
𝐴ℎ𝑚𝑒𝑑 𝐺𝑎𝑚𝑖𝑙 ری ٹویٹ کیا
The Shift Journal
The Shift Journal@TheShiftJournal·
The video i watched at 9 AM for 9 days
English
21
1.4K
8.9K
208.6K
𝐴ℎ𝑚𝑒𝑑 𝐺𝑎𝑚𝑖𝑙
Hey @LinkedInHelp , my account has been restricted for over 6 months. I'm certain I didn't intentionally violate any policies.I've reached out here before but received no response. Also, the help center keeps giving me an error when I try to open a ticket.
English
6
1
11
402
a7madn1
a7madn1@a7mad__n1·
Who Knows this fuck guy? , he are stiling my content on my private channel #bugbounty
X@TheMsterDoctor1

🔐 #BugBountyTips — Advanced Basic Auth Testing (401 ≠ Secure) When you encounter a Basic Authentication (401) prompt, don’t assume it’s properly enforced. Many real-world systems fail at the edges. 🧪 Phase 1: High-Probability Default Credentials Always test logic mistakes and lazy configs first: test:test test:password test:admin admin:admin admin:password admin:root Why this works: •Legacy services •Staging / forgotten admin panels •Auto-generated configs •Dev environments accidentally exposed 👉 These still show up on production more often than people admit. ⸻ 🧠 Phase 2: Zero-Credential Logic Bypass (Underrated) Here’s the part most people skip 👇 Click “Cancel” — submit NO credentials at all. Why? •Some backends incorrectly treat: •empty Authorization headers •missing credentials •malformed auth states as authenticated sessions I’ve personally seen: •Access granted after clicking Cancel •Backend returning 200 OK despite no credentials •App logic assuming “auth already handled by proxy” This often happens behind: •Reverse proxies •Misconfigured middleware •Legacy auth handlers •Bad error-handling logic ⸻ 🧬 Phase 3: Think Like the Backend (Not the UI) Remember: •The browser popup ≠ backend enforcement •UI denial ≠ server-side denial •401 responses are logic opportunities, not dead ends Always: •Observe headers •Compare responses •Check behavior differences with: •valid creds •invalid creds •empty creds •canceled auth ⸻ 🧠 Mindset Shift Authentication bugs are rarely about brute force. They’re about state confusion. Treat every 401 as a logic puzzle, not a wall.

English
12
0
16
3.6K
عزّت
عزّت@Al3zzat·
دا إحنا مدخلناش مدارس يا أم نازلي والله
العربية
77
144
2.5K
627.3K
𝐴ℎ𝑚𝑒𝑑 𝐺𝑎𝑚𝑖𝑙
@AHMEDMELEGY_ طيب لازم توضح ان اذون الخزانه والشهادات والحاجات دي اللي خاصه بالبنوك واللي بتدي نسب ثابته دي حرام
العربية
0
0
0
25
MELEGY 🇱🇧|🇪🇬مَليجي
و طبعاً فيه جوا صناديق علي حسب مستوي المخاطرة فمثلا فيه صناديق بتستثمر في اذون الخزانة و المخاطرة فيها قليلة جدا و فيه صناديق تاني هتلاقي ان المخاطرة فيها اعلي بس قصاد كده ممكن تاخد ربح اعلي بكتير و ممكن تخسر كذلك. ٢
العربية
2
0
17
4K
MELEGY 🇱🇧|🇪🇬مَليجي
نصيحة لما تحول لثاندر اعمل حساب مصاريف ايداع و سحب الفلوس ؛ فمتحولش مبالغ قليلة لأن كده انت محتاج السهم الاول يعوض مصاريف دخولك و خروجك منه و بعدين تبدأ تكسب. كل فترة لما يكون معاك مبلغ كويس ١٠٠٠ او اكتر ممكن تحطهم في البرنامج و شوف سهم او صندوق مناسب لأحتياجك. ١
العربية
19
7
373
53.7K
/usr/bin/fares
/usr/bin/fares@SirBagoza·
الخميس ٨ بليل يشباب كل خميس فيديو بقا
العربية
2
0
25
688
Ashraf Basyoni
Ashraf Basyoni@AshrafBasyoni4·
الحمد لله Tip: If the application allows users to generate personal API keys, create a key, remove the user from the org, then try using that key again, you might find it still works and gives you full control over the organization. #InfoSec #bugbountytips #BugBounty
Ashraf Basyoni tweet media
English
4
6
135
4.4K
Na3em
Na3em@0xNNN_·
{فَرِحِينَ بِمَا آتَاهُمُ اللَّهُ مِنْ فَضْلِهِ} اللهم لك الحمد انجاز جديد يضاف في مسيرتي المهنية قدرت اكتشف ثغرة على وكالة الفضاء الامريكية ناسا وبفضل الله تم قبول الثغرة ومعالجتها الحمدلله دائما وابدا✨
Na3em tweet media
العربية
262
244
13.7K
1.7M
Ashraf Basyoni
Ashraf Basyoni@AshrafBasyoni4·
الحمد لله The application only checks whether an email exists during account creation, not on account modification. Inside my org, there’s an option to add users, when I try to add an existing email, it correctly says “user already exists” and blocks it. But when I add a new user with a non-existing email, it gets created normally and I have full access, I can change the name, email, and password. Then I tried to change that email to one that already exists, and the system didn’t perform any check, allowing me to link it to the victim’s account and take full control #InfoSec #BugBounty #infosecurity
Ashraf Basyoni tweet media
English
4
4
144
6.9K