Kanon

69 posts

Kanon banner
Kanon

Kanon

@xtkanon

Cybersecurity Researcher living in Egypt 🇪🇬

Egypt شامل ہوئے Mart 2024
7 فالونگ373 فالوورز
Kanon
Kanon@xtkanon·
@destro4evr @Deepaksaini7740 I use tools like FFUF and dirsearch, along with wordlists such as SecLists, selecting the appropriate wordlist based on the website’s technology
English
1
1
1
85
Kanon
Kanon@xtkanon·
December achievements finished strong 🥰❤️ I discovered and responsibly disclosed 15 vulnerabilities, including: RCE (Remote Code Execution) 2× IDOR 2× BAC (Broken Access Control) Stored XSS 2× Reflected XSS 4× SQLI Misconfiguration Business Logic flaw Information Disclosure
Kanon tweet media
English
13
8
200
7.5K
Kanon
Kanon@xtkanon·
@haidar_2850 I only performed fuzzing on files and parameters across the websites and found that some hidden parameters are vulnerable
English
1
0
5
261
Haidar
Haidar@haidar_2850·
@xtkanon Congratulations Any tips for sql injection please.
English
1
0
1
282
Kanon
Kanon@xtkanon·
@tysonbenson Mostly manual testing with Burp Suite
English
1
0
2
276
Kanon
Kanon@xtkanon·
@Deepaksaini7740 Thanks, brother❤️ Just trying fuzzing to get hidden endpoints
English
1
0
1
292
Kanon ری ٹویٹ کیا
CVE
CVE@CVEnew·
CVE-2025-52664 SQL injection in Revive Adserver 6.0.0 causes potential disruption or information access when specifically crafted payloads are sent by logged in users cve.org/CVERecord?id=C…
English
0
1
2
885
Yunxohang Limbu
Yunxohang Limbu@yunxohang·
Got my first 4 digit!
Yunxohang Limbu tweet media
English
20
8
397
11.7K
Kanon
Kanon@xtkanon·
They say October is the month of falling in love... For me, October is the month of falling into vulnerabilities. 💻❤️
Kanon tweet media
English
1
0
6
432
Dom
Dom@dominic__sr·
@xtkanon Which platform bro
English
1
0
2
68
Kanon
Kanon@xtkanon·
IDOR my favorite bug New zero-click lead to full account takeover
Kanon tweet media
English
3
6
183
5.5K
Kanon
Kanon@xtkanon·
@Monir_Ish I was trying to change the password on the main hacker account and noticed a parameter in the JSON for the hacker's email. I added a userID parameter to the request, and it worked! The victim's account email and password were changed
English
1
0
6
274
Kanon
Kanon@xtkanon·
Today I reported a vulnerability Information Disclosure And I got it Triaged 😁
Kanon tweet media
English
0
0
5
350
Kanon
Kanon@xtkanon·
مساء الدبلكيت علي عيونك 🚶‍♂️
Kanon tweet media
العربية
0
0
5
268
Kanon
Kanon@xtkanon·
@yunxohang The challenges ended 4 months ago, but the time of reporting and submitting the report was during the challenges and the bounty awarding period, not after. However, they used a stupid excuse.
English
1
0
1
89
Kanon
Kanon@xtkanon·
الحمد لله This month, I reported more than 10 vulnerabilities, including: Reflected XSS Stored XSS IDOR broken access control misconfiguration
Kanon tweet media
Română
4
3
148
5.5K
Kanon
Kanon@xtkanon·
@GERR4Y عادي حاصله معايا في SSRF وكل ما اكلمهم يقولو لسه بنراجعها استنا شوية 😂😂
Kanon tweet media
العربية
0
0
0
242
آية أيمن 🇵🇸
يعني إي بقاله 3 شهور pending review؟! هكروان اتجننو
آية أيمن 🇵🇸 tweet media
العربية
12
0
53
4.2K
Kanon
Kanon@xtkanon·
@Abdulluuuu عادي فوق الشهر والشهرين
العربية
0
0
1
123
Kanon
Kanon@xtkanon·
@AlBoshanji No, but internal files, because the vulnerability is of medium severity.
English
0
0
0
15
Kanon
Kanon@xtkanon·
This month 5 vulnerabilities. SSRF Stored XSS Path Traversal Bypass 401 Information Disclosure #togetherwehitharder
Kanon tweet mediaKanon tweet mediaKanon tweet mediaKanon tweet media
English
3
0
62
4.4K