
Omar Hashem
@OmarHashem666
Followers
2K
Following
665
Media
8
Statuses
237
PenTester | Bug Hunter | Develop automation tools | Author of 7 CVEs | Acknowledged by Google, Hubspot, Paypal, OPPO, and +25 more
Egypt
Joined May 2017
Hello everyone, as promised, this is a detailed write-up on how I was able to get an account takeover in HubSpot Public Bug Bounty Program. #BugBounty #bugbountytips #Pentesting #cybersecurite #infosec ATO.
infosecwriteups.com
Hi everybody, our story today will be about how I was able to get a Full account takeover on HubSpot Public Bug Bounty Program at Bugcrowd…
78
372
1K
One of my favorite things i love to do is browsing team leaders profiles on LinkedIn and Twitter to understand their infrastructure priorities and discover backend technologies that I may not have discovered through enumeration with a black box approach. #bugbounty #bugbountytip.
4
3
23
Some time ago I found about 5 full ATO(0-click and 1-click) and PE while hunting on HubSpot at @Bugcrowd, some of the vulns have interesting attack chains, fortunately, I found some of them fixed, so stay tuned for some juicy write-ups soon.#bugbounty #bugbountytips #bugbountytip
8
5
128
Hello guys, I end this year by sharing with you a new article about how I found a SQL Injection Zero Day (CVE-2022-38627) via static analysis.Research:. Exploit:. #BugBounty #bugbountytips #Zeroday #0day #redteam #Pentesting.
infosecwriteups.com
Introduction:
5
119
307
Hello guys, I'm sharing with you a new article about how I found a Stored XSS 0-day (CVE-2022–42710) via static analysis.Research:. Exploit:. #BugBounty #bugbountytips #Zeroday #0day #redteam #Pentesting.
infosecwriteups.com
Hi everybody, I will share with you in this article in detail how I was able to find CVE-2022–42710 through static analysis
3
61
144
1/2.Hello guys,.I'm sharing with you some new zero-days that I found recently that can allow an unauthenticated attacker to ATO of admin or other users accounts with one click you can scan bug bounty programs or your company assets right now using nuclei. #bugbounty #bugbountytip
7
64
225
#BugBounty #bugbountytips .1/2.While doing bug hunting on Microsoft I found an open redirect, Microsoft was not the only affected company but it was affecting other bug bounty programs that use Microsoft services.
2
5
52
I'm really happy to see a bunch of people who found bugs in bug bounty programs after reading my write-ups.and glad to see that we have crossed +30k views and +10k reads in the last month only on my blog ❤️. #BugBounty
9
8
39
Hello everybody, I Found an interesting vulnerability while hunting on one of the @Hacker0x01 programs, enjoy reading it😀. #BugBounty #bugbountytips #bugbountytips.
infosecwriteups.com
Hello everybody, Most of the time you read about account takeover or Infrastructure takeover but did you heard before about Company…
10
77
256
Winner winner, chicken dinner 😁, They were expecting path traversal vulnerability but I got RCE 😄.Take a look at my solution for the @yeswehack security source code review challenge you might learn something new. #BugBounty #bugbountytips #bugbountytip.
#3 Vulnerable snippets🏁 . Top solutions!🏆.@OmarHashem666,@devangsolankii,@Abdulmalik_TTG. Read their solution👇.➡ ➡ ➡
2
0
13
Inspired by @ghostlulz1337 bug bounty playbook, I published a new write-up about a technique that helped me to get more than 10 RCE in different companies. #BugBounty #bugbountytips #bugbountytip #Pentesting #cybersecurity #bugbountywriteup #redteam.
5
47
171
Hi everybody, Inspired by @_zwink @Zigoo0 file upload videos, I published a new write-up about a P2 vulnerability found while bug bounty hunting.Enjoy 😀. #bugbounty #bugbountytip #bugbountytips #informationsecurity #infosec #bugbountywriteup #Pentesting.
infosecwriteups.com
Hello everyone, one of the most interesting functions is file uploading, vulnerabilities in file uploads usually lead you to critical or…
7
90
289
Inspired by the @brutelogic @rodoassis XSS bypasses, I have published a write-up about a filter that I bypassed to get multiple XSS. #BugBounty #bugbountytip #bugbountytips #xss #cybersecurity #infosec.
infosecwriteups.com
Hi everybody, today i will show you how can simple technique lead you to find multiple series vulnerabilities across the whole subdomains
2
66
199
Inspired by @GodfatherOrwa SQLI tips | I have shared a new write-up about my way of finding some SQL Injections vulnerabilities. #BugBounty #bugbountytip #cybersecurite #infosec #Pentesting.
infosecwriteups.com
Hi everybody, SQL Injection is one of the most critical vulnerabilities that can be found in web applications I will show you today how I…
10
142
376
RT @tbbhunter: How I abused the file upload function to get a high severity vulnerability in Bug Bounty.
infosecwriteups.com
Hello everyone, one of the most interesting functions is file uploading, vulnerabilities in file uploads usually lead you to critical or…
0
92
0
Hello hunters,.If you are interested in bug bounty hunting you can watch my PoC videos on my YouTube channel maybe help you to find your first vulnerability.Enjoy 😀. #bugbounty #bugbountytips #bugbountytip #infosec #cybersecurity.
2
0
4
RT @Jhaddix: == Trademark and Copyright Recon ==. How to find assets no other bug hunters have found. One of my simple "secrets" for year….
0
280
0