0x9747 Profile Banner
Umair Profile
Umair

@0x9747

Followers
1K
Following
2K
Media
142
Statuses
1K

Senior Security Analyst and Researcher | That guy who makes tools | Presented at BlackHat USA, Europe, Asia and MEA as well as GISEC DXB

India
Joined December 2018
Don't wanna be here? Send us removal request.
@0x9747
Umair
3 years
In continuation of the research done by @silascutler, last week I scanned the entire Internet and generated JARM fingerprints from all the hosts listening on port 443. Check out:
Tweet card summary image
mega.nz
6
125
358
@0x9747
Umair
27 days
Firemon helps you to concurrently scan several endpoints at once and help discover misconfigurations like Data Exposures and Firebase takeover cases! It comes with several user-based customisations, which you can learn about through the README (.
Tweet card summary image
github.com
A fast, concurrent CLI tool to scan Firebase URLs for vulnerabilities. - umair9747/Firemon
0
0
0
@0x9747
Umair
27 days
When I went through the news, I realised that there's a need for a tool which can help folks identify such misconfigurations in Firebase endpoints, something which even the Bug bounty folks could benefit from.
1
0
0
@0x9747
Umair
27 days
The recent Tea App Data breach serves as a stark reminder that orgs and individuals need to prioritise the security of Firebase endpoints!.
1
0
0
@0x9747
Umair
27 days
🚨 New Tool Release.Firemon - A fast, concurrent CLI tool to scan Firebase URLs for vulnerabilities! .Repo :
Tweet media one
2
0
1
@0x9747
Umair
1 month
I also believe these tools will be serve as a great ā€œintegrationā€ but not replacement of existing security workflows. At the same time it opens several doors for existing vendors/tools to integrate with these platforms to further solidify their analysis/scanning.
0
0
0
@0x9747
Umair
1 month
Some people especially those who do bug bounty feel that these tools could affect their careers/discoveries but honestly I just see this as a time to start learning more niche or complex attacks where these tools will likely fail.
1
0
0
@0x9747
Umair
1 month
Too much of noise around AI-powered security tools/products in the last couple of weeks. Honestly I don’t see something like @Xbow or @HacktronAI completely replacing security teams but providing an additional layer of scanning surface level as well as some exceptional cases.
1
0
2
@0x9747
Umair
1 month
About to submit a CFP that will redefine the way we see and implement digital surveillance and spatial monitoring in the modern day! Announcement coming soon šŸ¤žšŸ˜‰.
0
0
1
@0x9747
Umair
1 month
RT @Xbow: When simple attack vectors fail, XBOW doesn't give up. āš”ļøNew discovery: Arbitrary file read in WordPress Ninja Tables plugin. H….
0
16
0
@0x9747
Umair
1 month
RT @0xacb: DMARC can reveal more domains associated with a target. lt;target-domain> allows you to find domains using….
0
208
0
@0x9747
Umair
1 month
Made my @topmateHQ profile today! HMU if you're an aspiring security guy :D.
0
0
1
@0x9747
Umair
2 months
RT @Xbow: Sometimes the most illogical approach wins. XBOW discovered XSS in Salesforce Aura by testing aura.format=JSON - which counterin….
0
59
0
@0x9747
Umair
2 months
RT @Xbow: Even mature products hide critical flaws – and @XBOW just found another one. CVE-2025-49493: XXE in Akamai CloudTest discovered….
0
39
0
@0x9747
Umair
4 months
RT @entarabicom: CPX Holding, a leading provider of cutting-edge cyber and physical security solutions and services, today announced the ac….
0
1
0
@0x9747
Umair
4 months
RT @mossab_hussein: šŸ•øļø Super excited about this new chapter for spiderSilk 2.0!.
0
2
0
@0x9747
Umair
5 months
RT @colossal: SOUND ON. You’re hearing the first howl of a dire wolf in over 10,000 years. Meet Romulus and Remus—the world’s first de-exti….
0
28K
0
@0x9747
Umair
6 months
To read more about this research, check out our Medium post:
0
0
0
@0x9747
Umair
6 months
Its quite concerning to see the amount of PII voluntarily exposed by the people over such platforms but at the same time we believe Scribd and other document hosting platforms need to pay special attention to avoid PII from being publicly accessible.
0
0
0
@0x9747
Umair
6 months
The data constitutes of bank statements, salary slips, driving licenses, vaccine certificates, Adhaar/PAN cards, WhatsApp Chat exports and so much more!!.
2
0
0
@0x9747
Umair
6 months
Throughout this research we retrieved a whopping 13000+ PII docs just from the last one year targeting specific categories, which also means that this is just a tip of the iceberg! šŸ˜µā€šŸ’«.
1
0
0