armaancrockroax Profile Banner
Armaan Pathan Profile
Armaan Pathan

@armaancrockroax

Followers
11K
Following
4K
Media
115
Statuses
2K

Senior Engineer - Security at Katim | OSCP | Bug Bounty Hunter | Keen Learner | Ex-AppSec @emirates ✈️

Gandhinagar,gujarat,India
Joined June 2012
Don't wanna be here? Send us removal request.
@armaancrockroax
Armaan Pathan
7 years
I just published Scary Bug in Burp Suite Upstream Proxy Allows Hackers to Hack Hackers
Tweet card summary image
medium.com
One day I was playing with a tool debookee (Network Traffic Interception) in the office, I noticed that the tool was intercepting facebook…
11
201
567
@bsidesahmedabad
Security BSides Ahmedabad
5 months
1 Click. 0 Warnings. Infinite Regret. 😵‍💫 What if your mic, cam & location got hijacked without a single alert? Yeah… Armaan Pathan isn’t here to scare you — he’s here to show you how it’s done. 🧠💻 🎯 Tech Talk: "1 Click, 0 Warnings: Hijacking mic, camera & geolocation via
2
15
27
@RekhaGuptaDelhi
Delhi
7 months
Hello Pakistaniyo
3K
2K
34K
@EpochTimes
The Epoch Times
1 month
🚨 Actress Diane Keaton’s Cause of Death Revealed Read more
0
205
3K
@armaancrockroax
Armaan Pathan
1 year
🐺 Proud to share my 2024 #HackerOne journey! 232 vulnerabilities reported, 6 critical findings, and a whole lot of learning along the way. Special focus on access control and web security. Here's to making the internet safer, one bug at a time! 🚀 Thank you @Hacker0x01 for the
0
0
30
@8kSec
8kSec
1 year
🚨🚨🚨Big Announcement! Introducing On-Demand Mobile Security Courses🚀 We’re thrilled to announce the start of pre-registration for our On-Demand Courses! At 8kSec Academy, you can advance your Mobile Security skills and earn certifications anytime, from anywhere🌍 Available
1
23
69
@httpvoid0x2f
HTTPVoid
1 year
Checkout our new blogpost! In this post we talk about SAML and the recent Ruby-SAML Auth bypass. CVE-2024-45409: Ruby-SAML Auth Bypass in GitLab https://t.co/VYZ3YG0oXD
3
153
556
@armaancrockroax
Armaan Pathan
1 year
August was a productive month. While I didn't hit my 30k USD target, I did discover some excellent puzzle-solving business logic and BAC issues.
9
3
232
@armaancrockroax
Armaan Pathan
1 year
In August, I submitted 23 vulnerabilities to 4 programs on @Hacker0x01. #TogetherWeHitHarder
1
1
52
@Hack_All_Things
Roy Davis
1 year
I was diagnosed with ALS a year ago. I am fighting this disease with everything I have, while still managing the Zoom BBP! To raise funding for ALS, I am participating in the ALS Walk in Denver on October 6, 2024. If you'd like to help, go here
7
5
44
@armaancrockroax
Armaan Pathan
1 year
I recently uncovered significant XML External Entity (XXE) and Server-Side Request Forgery (SSRF) vulnerabilities while hunting in a private bug bounty program. These flaws in Tibco WebFOCUS Reporting Server and Epson ePOS Printers allowed me to exfiltrate sensitive data,
2
15
87
@armaancrockroax
Armaan Pathan
2 years
In April, I submitted 59 vulnerabilities to 8 programs on @Hacker0x01. #TogetherWeHitHarder
2
0
33
@8kSec
8kSec
2 years
Learn inner workings of XPC communication between processes on iOS, intercept and modify XPC messages for advanced insights - https://t.co/Z6QEBUncOB Follow us on social media.#Frida #iOSsecurity #XPC #CyberSecurity #MobileSecurity
0
13
55
@hacker_
Corben Leo
2 years
I've made $500k+ from SSRF vulnerabilities. Here are my tricks:
85
1K
4K
@armaancrockroax
Armaan Pathan
2 years
It’s incredibly frustrating when you can't sign up, and the client assigns credentials and other bug bounty hunters to change your password or delete your account while executing test cases. Fellow researchers, please consider the impact on others before making such updates or
1
1
16
@armaancrockroax
Armaan Pathan
2 years
In March, I submitted 62 vulnerabilities to 6 programs on @Hacker0x01. #TogetherWeHitHarder https://t.co/iOOKjJC12S 😎😎😎
1
0
25
@armaancrockroax
Armaan Pathan
2 years
In February, I submitted 15 vulnerabilities to 3 programs on @Hacker0x01. #TogetherWeHitHarder
2
0
27
@_0x999
0x999 🇮🇱
2 years
Just published a Burp Suite extension I wrote for @TomNomNom's tool jsluice🥳 jsluice++ allows you to scan traffic from Burp Suite's Sitemap/Proxy using jsluice while providing a user-friendly UI for easier results inspection and more🔍 Check it out 👇 https://t.co/vkFif1Xyvd
12
126
432
@Dinosn
Nicolas Krassas
2 years
Setting Up an iOS Pentesting Lab on a Non-Jailbroken iDevice
Tweet card summary image
infosecwriteups.com
Introduction:
2
96
327