Osama Avvan
@osamaavvan
Followers
2K
Following
225
Media
13
Statuses
115
_Bug bounty hunter. ❤️ To Code.
Karachi, Pakistan
Joined January 2019
Ever wondered how NTLM hashes can be stolen through PDF files? Check out my latest write-up to learn more about this cybersecurity threat. https://t.co/VU1b5idFGW
#CyberSecurity #NTLM #Hacking #PDF #DataSecurity
medium.com
In this write-up, we will discuss how to steal NTLM hashes using a PDF file.
1
1
4
Exploring Stored XSS Vulnerabilities in PDF Viewers: Unlocking Access to the DOM. Check out my new write-up for insights. https://t.co/rErHiqeE3Z
#BugBounty #XSS #cybersecurity #bugbountytips
medium.com
Hi Everyone, I hope you all are doing well.
0
13
49
Unveiling the Risks: AWS Cross Account Enumeration Demystified. Dive deep into securing your AWS infrastructure. Check out my latest write-up for insights. https://t.co/PLYhLqSo8M
#cybersecurity #aws #cloudsecurity #bugbounty
0
2
5
Excited to share my latest writeup: "Guide to AWS Penetration Testing"! Delve into the nuances of securing cloud environments, and identifying vulnerabilities. https://t.co/lMeMXPsZ0K
#cybersecurity #cloudsecurity #bugbounty #devsecops #aws
0
12
34
Just released Part 1 of my series on 'Android SSL Pinning Bypass'! Dive into the essentials without the need for a rooted device. Stay tuned for more advanced techniques in the upcoming writeups! https://t.co/TcrD3OYbuu
#bugbounty #android #mobilesecurity
medium.com
Hi Folks, I hope you are all doing well. I will be doing a series of writeups for the SSL Pinning Bypass for Android, we will be starting…
1
16
68
Excited to share my latest write-up on uncovering DOM XSS vulnerabilities through client-side JavaScript analysis and bypassing WAF. https://t.co/r5v9UkqXUp
#CyberSecurity #XSS #BugBounty #bugbountytips
medium.com
Hi Folks, I hope you are all doing well. This write-up is about DOM XSS and how you can hunt for DOM XSS by simply doing Source Code…
4
27
112
🔴 Challenge During hunting, I encountered a situation where injected code was converted to uppercase.
8
28
156
Alhamdulillah, I am now an Offensive Security Certified Professional (OSCP) I look forward to leveraging my OSCP certification to contribute to challenging projects and collaborate with like-minded professionals. #oscp #cybersecurity #infosec
6
0
66
Calling all security researchers and bug bounty hunters! Don't miss out on this commonly overlooked vulnerability that could potentially earn you a big bounty. https://t.co/2Sdhb3ANeF
#bugbounty #hacking #cybersecurity #vulnerability
medium.com
Hi, Today's write-up is about a common security vulnerability that is mostly overlooked by security researchers and the companies…
2
2
19
Hello @yeswehack It's been more than a month and I still can't withdraw my bounty due to the verification issue, I have provided all of my documents. The ticket is still open but no one is willing to respond. Please resolve this issue.
1
0
4
Hello, Another Interesting XSS challenge, DOM Clobbering to XSS. In collaboration with @hamzaavvan
https://t.co/cbUXZfOKke
#xss #BugBounty #challenge
0
0
6
Hi folks, Back with another XSS challenge. Just a regular XSS, try to get a pop-up. https://xss-heaven(.)000webhostapp(.)com/xss.php Note: Remove the Brackets from URL Dm your solutions. #cyberseurity #xss #BugBounty
0
1
11
I just published Exploiting Unauthenticated GraphQL Introspection and API calls https://t.co/ALZPVyfAG1
#WebApplicationSecurity
#APIsecurity
#bugbountytips
link.medium.com
Assalam u Alikum Everyone, it’s been a while since my last writeup. So here I am with another interesting finding.
4
23
91
I have created a simple Prototype Pollution XSS challenge. Try to get a pop-up. DM me your solution. https://t.co/l8BxnBDWKK
#BugBounty #XSS
0
0
4
Done with Bug Bounties, now I'm looking for a job in security preferably remote. Web/Android and Network are my forte. Anyone hiring? #cybersecurity
1
3
36
Is anyone facing issue with Bugcrowd Payment, it's been more than 5 days still haven't received the bounty in bank account. Payment page is also not working giving 500 internal error. Also no response for the support. @Bugcrowd
1
0
5
Thank You ...Thank you all to make dream come true but remember We are join to make new records and create history.1 year and counting..! #SecurityFoster #CyberSecurity #paas #SaaS #Celebrations
2
7
13