YShahinzadeh Profile Banner
YS Profile
YS

@YShahinzadeh

Followers
17K
Following
2K
Media
226
Statuses
2K

Security enthusiastic, chess player

Istanbul, Turkey
Joined September 2012
Don't wanna be here? Send us removal request.
@YShahinzadeh
YS
1 year
How I reverse-engineered an Android app, bypassed custom encryption layer, achieved server-side RCE, and earned a $5000 bounty. read the full story here (TLDR; but worth reading) https://t.co/xgvffzspiB
21
192
971
@YShahinzadeh
YS
2 days
$7500 again, there is a 20k or 25k in the way...
9
1
138
@YShahinzadeh
YS
5 days
this one is brilliant! you may have seen GIS OAuth during hunting (I have, many times), XSS + ATO. I recommend reading and studying this write-up (author does not have X acc)✌🏻 https://t.co/x6BiMUpHNC
Tweet card summary image
blog.voorivex.team
Discover how a clever DOM XSS bypass led to an automated account takeover by exploiting OAuth flows in GIS SDK
9
43
285
@YShahinzadeh
YS
5 days
google fits me well, complicated flows, noisy HTTP requests, lots of JS codes, like a jungle where you should hunt down a small rabbit :]
3
1
101
@Cboe
Cboe
2 months
Choose a life with options.
13
6
83
@YShahinzadeh
YS
6 days
another one on Google
14
6
331
@YShahinzadeh
YS
11 days
impact increased to S1, im expecting $20k for this one :]
4
0
170
@YShahinzadeh
YS
12 days
my first cashout from Bugcrowd arrived, the bank deducted ~$60 for international transfer fee and I'm not sure know it's normal or not (I have never received $ from BC before)
15
3
264
@LoviseUs
Lovise
3 months
It flies, glides, and returns to your hand. Holiday deal—grab it now! ⏱️
34
72
869
@YShahinzadeh
YS
18 days
public program on BugCrowd, tip: in OAuth, check every "login with" seprately. Google, Apple, etc. each might have different implementaion and flaw, btw I'm going to write a blog post for 0-click, the scenario was interesting, happy hacking
24
44
725
@YShahinzadeh
YS
24 days
Another one on Google VRP. this one is an old-buggy-pettern storing data as an object in State parameter and processing it in OAuth callback. I couldn't manipulate final url using attacker/domain or attacker@domain, but with attacker\u002fdomain. I expect 20k or 13k for this ;]
30
24
589
@YShahinzadeh
YS
1 month
they issued $7500, I was expecting $15000 but their statement were reasonable so I'm happy with, trying to put more time on Google
4
1
90
@YShahinzadeh
YS
1 month
new to Google VRP, seems google does not define the bounty amount right after triage, the bug is on an AI product (I cannot name it here), I'm not sure how much bounty should I expect here
15
7
314
@INN_Resource
Resource Investing
1 month
North American PEA Shows After-Tax $1.25B NPV at US$3,650 Gold
0
11
92
@YShahinzadeh
YS
1 month
why are most SPA web apps vulnerable to DOM XSS? I've found MANY bugs in Oauth when custom implementation gets involved, many ATO and DOM XSS. never overlook custom OAuth setups, like what? storing DATA in state parameter, happy hunting :]
11
12
390
@YShahinzadeh
YS
2 months
This one was easy: searched JS files → revealing endpoints → JSON HTTP request → exposed PII. Tip: account for lazy-loading. many hunters miss endpoints. Method: click to trigger lazy-loaded JS, then search again for endpoints. Happy hunting :]
21
59
810
@YShahinzadeh
YS
2 months
I haven’t fully returned to BB since my H1 acc was suddenly closed, but this week I tried to start working again. I spent some time on BC and found an XSS and an IDOR, the XSS was easy with a simple payload :]
39
3
386
@AmirMSafari
AmirMohammad Safari
2 months
If a CSPT bug can't be exploited on the same origin, you can pivot it to another one. Cloudflare Image Transform can act as a cross‑origin gadget to reach more sensitive endpoints on different origins - you can read more about it here ;) https://t.co/jOQOkpdHVJ
Tweet card summary image
blog.voorivex.team
Explore Cloudflare's Image Proxy as a CSPT exploit tool, enabling impactful cross-origin path traversal attacks through redirect techniques
26
42
283
@YShahinzadeh
YS
2 months
20 days ago I found a uXSS and reported, it got triaged now, I'll publish a blog post after fix and vendor permission, it's my first bug that I'm not happy with due to recent H1 situation 🖤
39
21
787
@UH_RE_Institute
UH Research & Education Institute
1 month
From deep brain stimulation to reanimating paralyzed limbs, cutting-edge neurotechnology is transforming what’s possible for patients with movement disorders, paralysis, and psychiatric conditions. Listen to the latest Science@UH episode.
0
3
31
@samm0uda
Youssef Sammouda (sam0)
2 months
Due to the repeated screw-ups and zero transparency around bans by @Hacker0x01, I’ve chosen to leave with dignity. My account is now fully deactivated and to be removed. If you need my services, I’m still available at @Bugcrowd @intigriti @immunefi @HackenProof @StandoffBB
@YShahinzadeh
YS
3 months
I’ve been hunting on H1 for almost 3 years, ranked #18 in 2025, have always tried to contribute positively to the hacker community. I’ve earned around $500k in bounties and was on the road to $1M. Yet I don’t even have HSM, and I feel I haven’t been recognized as I should 1/4
12
32
502
@NahamSec
Ben Sadeghipour
3 months
Really disappointed to see @Hacker0x01 do this. I also had a similar interaction with h1 about a month ago where they questioned my nationality and place of residence after 10+ on the platform.
@YShahinzadeh
YS
3 months
I’ve been hunting on H1 for almost 3 years, ranked #18 in 2025, have always tried to contribute positively to the hacker community. I’ve earned around $500k in bounties and was on the road to $1M. Yet I don’t even have HSM, and I feel I haven’t been recognized as I should 1/4
21
54
640
@YShahinzadeh
YS
3 months
I also submitted another ticket, but it was closed within just one hour without any response. After everything, I believe I still deserve a chance to be reviewed. I value transparency and am ready to provide any documents or explanations required. Thanks for reading 4/4
2
6
260
@YShahinzadeh
YS
3 months
Although H1 may have their own reasons, I’m 100% sure there’s been a misunderstanding here. I don’t hack on other platforms, H1 was my main income, which is now terminated along with 230 open reports worth around $50k. But beyond money, what matters most to me is my identity 3/4
1
6
239
@MagnesiacoreMan
MagnesiacoreGuy
4 days
Magnesiacore panels can be applied to wood, metal, steel and masonry structures using a variety of mechanical fasteners, including screws, bolts, rivets, brads, staples, and nails. It can also be easily laminated over existing surfaces using adhesives and cements.
0
1
1
@YShahinzadeh
YS
3 months
I really appreciate Youssef for the Tweet, he’s been very supportive. Around 10 days ago I received a message about a permanent ban from H1 with only a vague statement and no further communication, so I couldn’t understand the reason 2/4
2
4
225