ayadim_ Profile Banner
Ayadim Profile
Ayadim

@ayadim_

Followers
2K
Following
6K
Media
61
Statuses
3K

🇲🇦.{Farmer, Developer background , bug bounty hunter N00b , PUBG mobile player...}

Morocco
Joined January 2020
Don't wanna be here? Send us removal request.
@ayadim_
Ayadim
1 year
#nuclei Js-analyse template is updated now! .The new update include extraction of : .-S3 buckets. -Private keys. -Github-Personal-Access-Token. -Github-OAuth-Access-Token. -Ajax request in JavaScript could led to find more backend requests . Best regards.
Tweet card summary image
github.com
i will upload more templates here to share with the comunity. - ayadim/Nuclei-bug-hunter
@ayadim_
Ayadim
1 year
Big updates are coming to nuclei template "js-analyse" to extract more creds,api keys,private keys (SSH) also it will extract S3 bucket from javascript files.
Tweet media one
6
49
168
@ayadim_
Ayadim
23 days
RT @infosec_au: Today, we're releasing the new Searchlight Cyber (@SLCyberSec) tools website, which allows you to use several of our open-s….
0
78
0
@ayadim_
Ayadim
1 month
I earned $1,500 for my submission on @bugcrowd #ItTakesACrowd. My first prompt injection report.
6
0
89
@ayadim_
Ayadim
2 months
RT @cyb_detective: Go for Dorks. Online generator of advanced search queries for Google, Bing, DuckDuckGo, LeaklX, Shodan, Refseek, Fofa, Y….
0
58
0
@ayadim_
Ayadim
2 months
I earned $620 for my submission on @bugcrowd #ItTakesACrowd.
2
1
55
@ayadim_
Ayadim
4 months
Tip#: Don’t rely only on Wayback Machine or crawlers to find hidden endpoints. Always try submitting forms manually — you might trigger requests and discover endpoints that automated tools completely miss. Also use browser console ( inspection) to see requests in real time.
0
0
16
@ayadim_
Ayadim
4 months
Just earned $6,200 in bug bounties through @Bugcrowd for my latest submissions!. #BugBounty #EthicalHacking #Infosec.
5
1
109
@ayadim_
Ayadim
4 months
RT @rez0__: I'm a hacker and AI researcher who has reported vulnerabilities to OpenAI, Google, and others. I wrote this guide as a referenc….
0
750
0
@ayadim_
Ayadim
7 months
4x SQLi to RCE findings today! 💀 Exploiting the unexpected is always fun.
Tweet media one
2
4
121
@ayadim_
Ayadim
7 months
Successfully got my first Blind XSS validated on HackerOne! 🚀 This one enables admin account takeover via the registration form by injecting payload in user name.#BugBounty #XSS
Tweet media one
8
2
133
@ayadim_
Ayadim
7 months
Imagine signing up for a site, setting roleid=0, and suddenly you're an admin! 🚀💀 Found a critical Broken Access Control issue where improper role assignment let me escalate privileges at registration. Always enforce server-side role checks! #BugBounty.
0
0
5
@ayadim_
Ayadim
7 months
RT @ArchAngelDDay: 100 (very) short bug bounty rules:.
0
718
0
@ayadim_
Ayadim
7 months
RT @protosphinx: deepseek is a side project.
Tweet media one
0
2K
0
@ayadim_
Ayadim
8 months
RT @mrdoornbos: @nixcraft If you're gonna run code from the internet you don't understand, maybe start with:. docker run -it --rm alpine:la….
0
134
0
@ayadim_
Ayadim
8 months
RT @ryousifacu: سؤال للذكاء الاصطناعي والقرار لكم
0
2K
0
@ayadim_
Ayadim
11 months
you can create a Launcher to run it.
0
0
1
@ayadim_
Ayadim
11 months
I found a method to use dom-invader without opening burpsuite and without problems. Using the integrated chromium in burp directory. exec:~/.BurpSuite/burpbrowser/XXX/chrome.it will load chromium with the extension without any problem. change (XXX) with your version.
1
0
6
@ayadim_
Ayadim
1 year
RT @BugBountyDEFCON: We're excited to announce one of our giveaways thanks to "@CaidoIO" 🎉 We will pick 5 winners to win a 1-year Caido Pro….
0
379
0
@ayadim_
Ayadim
1 year
RT @h4x0r_fr34k: Fuzzing lists - Part 1 .Wordlists for few specific Funtions you can use for Specific Purpuses. 1. Email Providers .https:….
Tweet card summary image
github.com
Contribute to orwagodfather/WordList development by creating an account on GitHub.
0
86
0
@ayadim_
Ayadim
1 year
RT @nav1n0x: I just Published - A Comprehensive Guide to Manually Hunting SQL Injection in MSSQL, MySQL, Oracle, and NoSQL (MongoDB) - htt….
0
258
0
@ayadim_
Ayadim
1 year
RT @ayadim_: @Bugcrowd @Yassineaboukir I download dataset from ipinfo it has all ASN records contain ( geography+ ip range + company).
0
2
0