Mohamed Fodil
@_public_void
Followers
2K
Following
16K
Media
134
Statuses
2K
iOS Programming ~ Reverse Engineering | Electronic-ST | WhiteHat | Bug Bounty Hunter | Acknowledged By Apple 🍏
Algeria 🇩🇿🇵🇸
Joined April 2021
Despite my long experience in iOS reverse engineering i prefer not targeting VDP/BBP iOS Apps that may result in getting my exploits burned for nothing 🤷♂️ Instead, I’m good with reporting iOS related stuff directly to Apple 🙃 #BugBounty
#bugbountytips
#CyberSecurity
1
5
79
Lesson Learned: To avoid Self-Dulplicate, when you discover the same vulnerability across different domains/endpoints, report just one and wait for it to be Resolved, then do the same for the others. #bugbountytips
#BugBounty
#CyberSecurity
3
0
47
Yay, I and my friend @uieyuyeriuzyer were awarded $1,900 bounty on @Hacker0x01 #TogetherWeHitHarder
#BugBounty
#CyberSecurity
12
2
115
I earned $$$ for my submission on @bugcrowd #ItTakesACrowd 😁 2FA Bypass [Duplicate > Resolved > FIX-Bypass] Neither BC Triage nor the Program Team were able to reproduce. Finally, a Team Member have figured out why the issue wasn’t reproducible ✅ #BugBounty
#CyberSecurity
6
0
49
I find it really fun targeting and bypassing fixes of "Duplicated/Resolved" reports 😁 #BugBounty
#CyberSecurity
#bugbountytips
7
0
50
While I was performing a retest for my report to a program on @Hacker0x01 , I’ve noticed an extra security layer was added, after testing it separately, I found it vulnerable to something 🤷♂️ I reported it and got it Triaged 🙃 #CyberSecurity
#BugBounty
4
1
46
Yay, I was awarded a $1,000 bounty on @Hacker0x01! #TogetherWeHitHarder This was really fast ⚡️😃 Reported + Triaged on 17/04/2024 Retested on 18/04/2024 Resolved + Awarded on 19/04/2024 #BugBounty
#CyberSecurity
https://t.co/dmj7jPPaTF…
14
1
101
WOW 🤩 Triage, Fix and Retest were done in less than 24h I was invited to this PBBP at @Hacker0x01 since a month ago, (launched in 2020 with only 2 domains in-scope) 🤷♂️ Simple, no freaking tip 🙃 "api/vx/me/" => "api/vx/other_usrid/" #bugbountytips
#BugBounty
#CyberSecurity
7
3
114
Use FFUF for subdomains-list batch fuzzing 👇 Windows PowerShell Save the code in the pic below as "script.ps1" Linux Save this as "
https://t.co/hnQ9C7yNvo" [#!/bin/bash for URL in $(<subs.txt); do ffuf…-u "$URL/FUZZ" … done] #bugbountytips
#BugBounty
#CyberSecurity
3
15
54
Thanks for the invitation 😃😃 I have to find an authentication flaw as this is the right way to say thanks 😁 #bugbountytips
#CyberSecurity
6
3
58
Today, I received 20 private invitations to hack on private programs at @Hacker0x01 😃 Although I’m a lazy hunter 😅 I’ll try my best ! #BugBounty
#CyberSecurity
17
4
161
Here’s how me and my friend @uieyuyeriuzyer demonstrated the HTML Injection impact 👇 All-in-One PoC 😅 We wrote a small report on the page itself in which we demonstrated 4 HTMLi examples in a single payload #bugbountytips
#BugBounty
#CyberSecurity
17
26
179
I got access to an IIS server vulnerable to SNS, managed to get into the Webroot directory and downloaded the content as PoC, triaged as P4. I reversed the DLL's and got sensitive information. Do you think Severity will increase? #bugbountytips
#BugBounty
#CyberSecurity
15
13
131
Bad luck 😐 I found a leaked "Authorization Bearer" that grant me access to read (internal/private repos content), I can even know what will be the upcoming updates! but it turned out to be a "read-only" token 😬 #bugbountytips
#BugBounty
#CyberSecurity
3
2
36
The 2nd submission was triaged in just 24 hours 😁 waiting for the other one ! Big shout out to @Bugcrowd Triage #BugBounty
#CyberSecurity
5
4
74
First duplicate in 2024 ☹️ it was already triaged, then boom 💥the program found it duplicate 🥲 #BugBounty
#CyberSecurity
3
1
43
Yay, I and my friend @uieyuyeriuzyer were awarded an extra $1100 bounty on @Hacker0x01 #TogetherWeHitHarder HTML Injection worth $1900 😅 Although XSS wasn’t possible, we found a way to escalate the HTMLi #bugbountytips
#BugBounty
#CyberSecurity
https://t.co/U14d1KDlrl
Yay, I and my friend @uieyuyeriuzyer were awarded a $800 bounty on @Hacker0x01 #TogetherWeHitHarder Bug: HTML Injection XSS wasn’t possible due to CSP + WAF #bugbountytips
#BugBounty
#CyberSecurity
13
6
117
Yay, I and my friend @uieyuyeriuzyer were awarded a $800 bounty on @Hacker0x01 #TogetherWeHitHarder Bug: HTML Injection XSS wasn’t possible due to CSP + WAF #bugbountytips
#BugBounty
#CyberSecurity
14
5
135
I earned $600 for my submission on @bugcrowd #ItTakesACrowd 😁 Bug: Broken Authentication Ability to initiate and re-generate a valid session by just using one leaked value in the requests. #bugbountytips
#BugBounty
#CyberSecurity
15
15
165