nazmul_ethi Profile Banner
Md Nazmul Islam🇧🇩🇵🇸 Profile
Md Nazmul Islam🇧🇩🇵🇸

@nazmul_ethi

Followers
213
Following
2K
Media
37
Statuses
434

Bugbounty Hunter

Bangladesh
Joined January 2023
Don't wanna be here? Send us removal request.
@nazmul_ethi
Md Nazmul Islam🇧🇩🇵🇸
2 years
Alhamdulillah, I was awarded a $400 bounty on @Hacker0x01 ! #bugbounty #hackerone #bugbountytips #bugbountytip
3
2
96
@nav1n0x
N$
6 months
Cloudflare 403 bypass to time-based blind SQLi: PL: (select(0)from(select(sleep(10)))v) → 403 but PL: (select(0)from(select(sleep(6)))v)/*'%2B(select(0)from(select(sleep(6)))v)%2B'%5C"%2B(select(0)from(select(sleep(6)))v) → Time-based Blind SQLi #BugBounty #SQLi
7
122
719
@nav1n0x
N$
5 months
Discovered a very interesting path based SQLi yesterday. Injected: /‘XOR(if(now()=sysdate(),sleep(8),0))XOR’111/ → No delay /page/‘XOR(if(now()=sysdate(),sleep(8),0))XOR’111/test.test triggered delay. Same payload, different results. Here's why👇 1/4 #BugBounty #SQLi #WebSec
6
115
630
@bountywriteups
𝕏 Bug Bounty Writeups 𝕏
23 days
0
9
29
@silentgh00st
Mehdi
2 months
#bugbountytips ❌ Stop Doing These 10 Bug Hunting Mistakes ... And revise your methodology if : 1. You spend 2 days or less per program 2. You run automated tools on each URL and wait for unique results 3. You don't scan servers' open ports 4. You don't register an account in
8
63
417
@bountywriteups
𝕏 Bug Bounty Writeups 𝕏
9 months
Understanding Race Conditions in Web Applications https://t.co/CviiufotCZ #bugbounty #bugbountytips #bugbountytip
0
2
29
@bountywriteups
𝕏 Bug Bounty Writeups 𝕏
1 year
9.6 Lab: Partial construction race conditions https://t.co/YnQHhD9If0 #bugbounty #bugbountytips #bugbountytip
0
1
2
@bountywriteups
𝕏 Bug Bounty Writeups 𝕏
2 years
Race Conditions + IDOR Leads to Bypass Email Verification & Phone Verification https://t.co/Vw90ZGX8ao #bugbounty #bugbountytips #bugbountytip
2
11
50
@TechBlazesHQ
TechBlazes
6 months
Race Conditions in Real-World Apps | Bug Bounty Guide to Finding & Exploiting Web Hacking for Beginners | Learn to Exploit & Secure Websites Step-by-Step The course will introduce the various methods, tools and techniques used by attackers. You will study web application flaw…
0
2
0
@bountywriteups
𝕏 Bug Bounty Writeups 𝕏
3 months
Hidden Power of Race Conditions in Web Apps https://t.co/86cVbdRYp1 #bugbounty #bugbountytips #bugbountytip
0
4
35
@dawidczagan
Dawid Czagan
2 years
“Black Belt Pentesting / Bug Hunting Millionaire” 4-day training in Seoul #POC2023 https://t.co/P16f6P3tRy 3 videos: - Exploiting Race Conditions: https://t.co/SSUL63F8Jr - Token Hijacking via PDF: https://t.co/AJ59HH7BxA - Bypassing CSP: https://t.co/NjoQJSPmuH @POC_Crew
0
10
29
@algoboost
10K.world
7 months
PLEASE UPDATE YOUR APP We just pushed a critical update with a ton of important fixes: ✦ Claim button issues ✦ Sign-in race conditions ✦ General bug + performance improvements Download the latest iPhone update now: https://t.co/o81SMaUJXf & Android:
27
7
57
@bountywriteups
𝕏 Bug Bounty Writeups 𝕏
3 months
Auth Bypasses: Logic Flaws, Race Conditions, and Deserialization. What you need to know https://t.co/puNnfjOcKN #bugbounty #bugbountytips #bugbountytip
0
6
23
@kjasuquo
JA Asuquo | The Tech Bro
3 months
Go is blazing fast ⚡ but race conditions can wreck your code. 🐐 Here’s a quick demo on fixing race bugs with sync.Mutex: 🎥👇 https://t.co/DGBp1rqTRt Q: What’s the nastiest race bug you’ve faced in prod? 👀 #golang #concurrency #mutex #SoftwareEngineering #go
0
2
3
@OreoB1scuit
Biscuit
4 months
I published a new writeup on Medium where I explain how I found and exploited 3 unique race condition bugs that allowed bypassing free user limit, gaining unlimited followers, and manipulating leaderboard ranking. Read here: https://t.co/YdittYgtFo #bugbounty #bugbountytips
1
34
255
@Rwafrankie
Frankie@kali🧧
3 months
How do you find a Race Condition? You stress test the logic first! I started by testing a live transfer function on the lab; sending amounts within and beyond the current balance. The second transfer failed, but further testing is required. Burp Suite Repeater comes in here.
1
1
1
@Karl_J3
Joel
3 months
[ This is a Design pattern playground ] In Kotlin, a Singleton ensures only one instance exists, perfect for a TicketBookingSystem. ⚠️ Without synchronization → race conditions = double booking bug. ✅ Fix: use @Synchronized so only one thread books at a time. #Kotlin
0
1
1
@albinowax
James Kettle
8 months
I just built a custom action to let you test for race conditions with a single click! No tab groups required, and it uses the cutting edge single-packet attack under the hood.
9
63
359
@vickieli7
Vickie Li
5 years
Race conditions stem from simple programming mistakes and have been used by hackers to steal money from online banks and manipulate online voting systems. https://t.co/Lvfqt8pcuF
2
60
267