Omar Hashem Profile
Omar Hashem

@OmarHashem666

Followers
2K
Following
665
Media
8
Statuses
237

PenTester | Bug Hunter | Develop automation tools | Author of 7 CVEs | Acknowledged by Google, Hubspot, Paypal, OPPO, and +25 more

Egypt
Joined May 2017
Don't wanna be here? Send us removal request.
@OmarHashem666
Omar Hashem
3 years
Hello everyone, as promised, this is a detailed write-up on how I was able to get an account takeover in HubSpot Public Bug Bounty Program. #BugBounty #bugbountytips #Pentesting #cybersecurite #infosec ATO.
Tweet card summary image
infosecwriteups.com
Hi everybody, our story today will be about how I was able to get a Full account takeover on HubSpot Public Bug Bounty Program at Bugcrowd…
78
372
1K
@OmarHashem666
Omar Hashem
2 years
One of my favorite things i love to do is browsing team leaders profiles on LinkedIn and Twitter to understand their infrastructure priorities and discover backend technologies that I may not have discovered through enumeration with a black box approach. #bugbounty #bugbountytip.
4
3
23
@OmarHashem666
Omar Hashem
3 years
Some time ago I found about 5 full ATO(0-click and 1-click) and PE while hunting on HubSpot at @Bugcrowd, some of the vulns have interesting attack chains, fortunately, I found some of them fixed, so stay tuned for some juicy write-ups soon.#bugbounty #bugbountytips #bugbountytip
Tweet media one
8
5
128
@OmarHashem666
Omar Hashem
3 years
Hello guys, I end this year by sharing with you a new article about how I found a SQL Injection Zero Day (CVE-2022-38627) via static analysis.Research:. Exploit:. #BugBounty #bugbountytips #Zeroday #0day #redteam #Pentesting.
Tweet card summary image
infosecwriteups.com
Introduction:
5
119
307
@OmarHashem666
Omar Hashem
3 years
Hello guys, I'm sharing with you a new article about how I found a Stored XSS 0-day (CVE-2022–42710) via static analysis.Research:. Exploit:. #BugBounty #bugbountytips #Zeroday #0day #redteam #Pentesting.
Tweet card summary image
infosecwriteups.com
Hi everybody, I will share with you in this article in detail how I was able to find CVE-2022–42710 through static analysis
3
61
144
@OmarHashem666
Omar Hashem
3 years
1
10
35
@OmarHashem666
Omar Hashem
3 years
1/2.Hello guys,.I'm sharing with you some new zero-days that I found recently that can allow an unauthenticated attacker to ATO of admin or other users accounts with one click you can scan bug bounty programs or your company assets right now using nuclei. #bugbounty #bugbountytip
Tweet media one
7
64
225
@OmarHashem666
Omar Hashem
3 years
2/2.including (Paypal, Hyatt Hotels) and much more, (MSRC team) fixed the vulnerability after being reported within 5 days, and right now there are no more companies still affected, but I will share it with you as the scenario will still be helpful for your future bug hunting.
2
0
10
@OmarHashem666
Omar Hashem
3 years
#BugBounty #bugbountytips .1/2.While doing bug hunting on Microsoft I found an open redirect, Microsoft was not the only affected company but it was affecting other bug bounty programs that use Microsoft services.
2
5
52
@OmarHashem666
Omar Hashem
3 years
I'm really happy to see a bunch of people who found bugs in bug bounty programs after reading my write-ups.and glad to see that we have crossed +30k views and +10k reads in the last month only on my blog ❤️. #BugBounty
Tweet media one
9
8
39
@OmarHashem666
Omar Hashem
3 years
Hello everybody, I Found an interesting vulnerability while hunting on one of the @Hacker0x01 programs, enjoy reading it😀. #BugBounty #bugbountytips #bugbountytips.
Tweet card summary image
infosecwriteups.com
Hello everybody, Most of the time you read about account takeover or Infrastructure takeover but did you heard before about Company…
10
77
256
@OmarHashem666
Omar Hashem
3 years
Winner winner, chicken dinner 😁, They were expecting path traversal vulnerability but I got RCE 😄.Take a look at my solution for the @yeswehack security source code review challenge you might learn something new. #BugBounty #bugbountytips #bugbountytip.
@yeswehack
YesWeHack ⠵
3 years
#3 Vulnerable snippets🏁 . Top solutions!🏆.@OmarHashem666,@devangsolankii,@Abdulmalik_TTG. Read their solution👇.➡ ➡ ➡
2
0
13
@OmarHashem666
Omar Hashem
3 years
Inspired by @ghostlulz1337 bug bounty playbook, I published a new write-up about a technique that helped me to get more than 10 RCE in different companies. #BugBounty #bugbountytips #bugbountytip #Pentesting #cybersecurity #bugbountywriteup #redteam.
5
47
171
@OmarHashem666
Omar Hashem
3 years
Hello hunters,.If you are interested in bug bounty hunting you can watch my PoC videos on my YouTube channel maybe help you to find your first vulnerability.Enjoy 😀. #bugbounty #bugbountytips #bugbountytip #infosec #cybersecurity.
2
0
4
@OmarHashem666
Omar Hashem
3 years
RT @Jhaddix: == Trademark and Copyright Recon ==. How to find assets no other bug hunters have found. One of my simple "secrets" for year….
0
280
0
@OmarHashem666
Omar Hashem
3 years
RT @0x_rood: nuclei templates collection. h….
0
165
0