_public_void Profile Banner
Mohamed Fodil Profile
Mohamed Fodil

@_public_void

Followers
2K
Following
16K
Media
134
Statuses
2K

iOS Programming ~ Reverse Engineering | Electronic-ST | WhiteHat | Bug Bounty Hunter | Acknowledged By Apple 🍏

Algeria 🇩🇿🇵🇸
Joined April 2021
Don't wanna be here? Send us removal request.
@_public_void
Mohamed Fodil
3 years
Despite my long experience in iOS reverse engineering i prefer not targeting VDP/BBP iOS Apps that may result in getting my exploits burned for nothing 🤷‍♂️ Instead, I’m good with reporting iOS related stuff directly to Apple 🙃 #BugBounty #bugbountytips #CyberSecurity
1
5
79
@_public_void
Mohamed Fodil
1 year
Lesson Learned: To avoid Self-Dulplicate, when you discover the same vulnerability across different domains/endpoints, report just one and wait for it to be Resolved, then do the same for the others. #bugbountytips #BugBounty #CyberSecurity
3
0
47
@_public_void
Mohamed Fodil
1 year
Yay, I and my friend @uieyuyeriuzyer were awarded $1,900 bounty on @Hacker0x01 #TogetherWeHitHarder #BugBounty #CyberSecurity
12
2
115
@_public_void
Mohamed Fodil
1 year
I earned $$$ for my submission on @bugcrowd #ItTakesACrowd 😁 2FA Bypass [Duplicate > Resolved > FIX-Bypass] Neither BC Triage nor the Program Team were able to reproduce. Finally, a Team Member have figured out why the issue wasn’t reproducible ✅ #BugBounty #CyberSecurity
6
0
49
@_public_void
Mohamed Fodil
1 year
I find it really fun targeting and bypassing fixes of "Duplicated/Resolved" reports 😁 #BugBounty #CyberSecurity #bugbountytips
7
0
50
@_public_void
Mohamed Fodil
2 years
Yay, I was awarded a $150 bounty on @Hacker0x01! #TogetherWeHitHarder
6
1
66
@_public_void
Mohamed Fodil
2 years
While I was performing a retest for my report to a program on @Hacker0x01 , I’ve noticed an extra security layer was added, after testing it separately, I found it vulnerable to something 🤷‍♂️ I reported it and got it Triaged 🙃 #CyberSecurity #BugBounty
4
1
46
@_public_void
Mohamed Fodil
2 years
Yay, I was awarded a $1,000 bounty on @Hacker0x01! #TogetherWeHitHarder This was really fast ⚡️😃 Reported + Triaged on 17/04/2024 Retested on 18/04/2024 Resolved + Awarded on 19/04/2024 #BugBounty #CyberSecurity https://t.co/dmj7jPPaTF…
14
1
101
@_public_void
Mohamed Fodil
2 years
WOW 🤩 Triage, Fix and Retest were done in less than 24h I was invited to this PBBP at @Hacker0x01 since a month ago, (launched in 2020 with only 2 domains in-scope) 🤷‍♂️ Simple, no freaking tip 🙃 "api/vx/me/" => "api/vx/other_usrid/" #bugbountytips #BugBounty #CyberSecurity
7
3
114
@_public_void
Mohamed Fodil
2 years
Use FFUF for subdomains-list batch fuzzing 👇 Windows PowerShell Save the code in the pic below as "script.ps1" Linux Save this as " https://t.co/hnQ9C7yNvo" [#!/bin/bash for URL in $(<subs.txt); do ffuf…-u "$URL/FUZZ" … done] #bugbountytips #BugBounty #CyberSecurity
3
15
54
@_public_void
Mohamed Fodil
2 years
Thanks for the invitation 😃😃 I have to find an authentication flaw as this is the right way to say thanks 😁 #bugbountytips #CyberSecurity
6
3
58
@_public_void
Mohamed Fodil
2 years
Today, I received 20 private invitations to hack on private programs at @Hacker0x01 😃 Although I’m a lazy hunter 😅 I’ll try my best ! #BugBounty #CyberSecurity
17
4
161
@_public_void
Mohamed Fodil
2 years
Companies that don’t have BBP or VDP programs be like 👇 #BugBounty #CyberSecurity
1
4
46
@_public_void
Mohamed Fodil
2 years
Here’s how me and my friend @uieyuyeriuzyer demonstrated the HTML Injection impact 👇 All-in-One PoC 😅 We wrote a small report on the page itself in which we demonstrated 4 HTMLi examples in a single payload #bugbountytips #BugBounty #CyberSecurity
17
26
179
@_public_void
Mohamed Fodil
2 years
I got access to an IIS server vulnerable to SNS, managed to get into the Webroot directory and downloaded the content as PoC, triaged as P4. I reversed the DLL's and got sensitive information. Do you think Severity will increase? #bugbountytips #BugBounty #CyberSecurity
15
13
131
@_public_void
Mohamed Fodil
2 years
Bad luck 😐 I found a leaked "Authorization Bearer" that grant me access to read (internal/private repos content), I can even know what will be the upcoming updates! but it turned out to be a "read-only" token 😬 #bugbountytips #BugBounty #CyberSecurity
3
2
36
@_public_void
Mohamed Fodil
2 years
The 2nd submission was triaged in just 24 hours 😁 waiting for the other one ! Big shout out to @Bugcrowd Triage #BugBounty #CyberSecurity
5
4
74
@_public_void
Mohamed Fodil
2 years
First duplicate in 2024 ☹️ it was already triaged, then boom 💥the program found it duplicate 🥲 #BugBounty #CyberSecurity
3
1
43
@_public_void
Mohamed Fodil
2 years
Yay, I and my friend @uieyuyeriuzyer were awarded an extra $1100 bounty on @Hacker0x01 #TogetherWeHitHarder HTML Injection worth $1900 😅 Although XSS wasn’t possible, we found a way to escalate the HTMLi #bugbountytips #BugBounty #CyberSecurity https://t.co/U14d1KDlrl
@_public_void
Mohamed Fodil
2 years
Yay, I and my friend @uieyuyeriuzyer were awarded a $800 bounty on @Hacker0x01 #TogetherWeHitHarder Bug: HTML Injection XSS wasn’t possible due to CSP + WAF #bugbountytips #BugBounty #CyberSecurity
13
6
117
@_public_void
Mohamed Fodil
2 years
Yay, I and my friend @uieyuyeriuzyer were awarded a $800 bounty on @Hacker0x01 #TogetherWeHitHarder Bug: HTML Injection XSS wasn’t possible due to CSP + WAF #bugbountytips #BugBounty #CyberSecurity
14
5
135
@_public_void
Mohamed Fodil
2 years
I earned $600 for my submission on @bugcrowd #ItTakesACrowd 😁 Bug: Broken Authentication Ability to initiate and re-generate a valid session by just using one leaked value in the requests. #bugbountytips #BugBounty #CyberSecurity
15
15
165