Osama Avvan Profile
Osama Avvan

@osamaavvan

Followers
2K
Following
225
Media
13
Statuses
115

_Bug bounty hunter. ❤️ To Code.

Karachi, Pakistan
Joined January 2019
Don't wanna be here? Send us removal request.
@osamaavvan
Osama Avvan
1 year
Ever wondered how NTLM hashes can be stolen through PDF files? Check out my latest write-up to learn more about this cybersecurity threat. https://t.co/VU1b5idFGW #CyberSecurity #NTLM #Hacking #PDF #DataSecurity
Tweet card summary image
medium.com
In this write-up, we will discuss how to steal NTLM hashes using a PDF file.
1
1
4
@osamaavvan
Osama Avvan
1 year
Exploring Stored XSS Vulnerabilities in PDF Viewers: Unlocking Access to the DOM. Check out my new write-up for insights. https://t.co/rErHiqeE3Z #BugBounty #XSS #cybersecurity #bugbountytips
medium.com
Hi Everyone, I hope you all are doing well.
0
13
49
@osamaavvan
Osama Avvan
2 years
Unveiling the Risks: AWS Cross Account Enumeration Demystified. Dive deep into securing your AWS infrastructure. Check out my latest write-up for insights. https://t.co/PLYhLqSo8M #cybersecurity #aws #cloudsecurity #bugbounty
0
2
5
@osamaavvan
Osama Avvan
2 years
Excited to share my latest writeup: "Guide to AWS Penetration Testing"! Delve into the nuances of securing cloud environments, and identifying vulnerabilities. https://t.co/lMeMXPsZ0K #cybersecurity #cloudsecurity #bugbounty #devsecops #aws
0
12
34
@osamaavvan
Osama Avvan
2 years
Just released Part 1 of my series on 'Android SSL Pinning Bypass'! Dive into the essentials without the need for a rooted device. Stay tuned for more advanced techniques in the upcoming writeups! https://t.co/TcrD3OYbuu #bugbounty #android #mobilesecurity
Tweet card summary image
medium.com
Hi Folks, I hope you are all doing well. I will be doing a series of writeups for the SSL Pinning Bypass for Android, we will be starting…
1
16
68
@osamaavvan
Osama Avvan
2 years
Excited to share my latest write-up on uncovering DOM XSS vulnerabilities through client-side JavaScript analysis and bypassing WAF. https://t.co/r5v9UkqXUp #CyberSecurity #XSS #BugBounty #bugbountytips
Tweet card summary image
medium.com
Hi Folks, I hope you are all doing well. This write-up is about DOM XSS and how you can hunt for DOM XSS by simply doing Source Code…
4
27
112
@hamzaavvan
Hamza Avvan
3 years
🔴 Challenge During hunting, I encountered a situation where injected code was converted to uppercase.
8
28
156
@osamaavvan
Osama Avvan
3 years
Alhamdulillah, I am now an Offensive Security Certified Professional (OSCP) I look forward to leveraging my OSCP certification to contribute to challenging projects and collaborate with like-minded professionals. #oscp #cybersecurity #infosec
6
0
66
@osamaavvan
Osama Avvan
3 years
Calling all security researchers and bug bounty hunters! Don't miss out on this commonly overlooked vulnerability that could potentially earn you a big bounty. https://t.co/2Sdhb3ANeF #bugbounty #hacking #cybersecurity #vulnerability
medium.com
Hi, Today's write-up is about a common security vulnerability that is mostly overlooked by security researchers and the companies…
2
2
19
@osamaavvan
Osama Avvan
3 years
Hello @yeswehack It's been more than a month and I still can't withdraw my bounty due to the verification issue, I have provided all of my documents. The ticket is still open but no one is willing to respond. Please resolve this issue.
1
0
4
@osamaavvan
Osama Avvan
3 years
Hello, Another Interesting XSS challenge, DOM Clobbering to XSS. In collaboration with @hamzaavvan https://t.co/cbUXZfOKke #xss #BugBounty #challenge
0
0
6
@osamaavvan
Osama Avvan
3 years
Hi folks, Back with another XSS challenge. Just a regular XSS, try to get a pop-up. https://xss-heaven(.)000webhostapp(.)com/xss.php Note: Remove the Brackets from URL Dm your solutions. #cyberseurity #xss #BugBounty
0
1
11
@osamaavvan
Osama Avvan
3 years
I have created a simple Prototype Pollution XSS challenge. Try to get a pop-up. DM me your solution. https://t.co/l8BxnBDWKK #BugBounty #XSS
0
0
4
@osamaavvan
Osama Avvan
3 years
Done with Bug Bounties, now I'm looking for a job in security preferably remote. Web/Android and Network are my forte. Anyone hiring? #cybersecurity
1
3
36
@SecurityFoster
Security Foster
3 years
0
3
5
@osamaavvan
Osama Avvan
4 years
Is anyone facing issue with Bugcrowd Payment, it's been more than 5 days still haven't received the bounty in bank account. Payment page is also not working giving 500 internal error. Also no response for the support. @Bugcrowd
1
0
5
@osamaavvan
Osama Avvan
4 years
In Love with this new Private Program on Bugcrowd. #bugbounty #bugcrowd
7
2
77
@osamaavvan
Osama Avvan
4 years
DM for Akamai Waf XSS Bypass. #BugBounty #bugbountytips
2
1
12
@SecurityFoster
Security Foster
4 years
Thank You ...Thank you all to make dream come true but remember We are join to make new records and create history.1 year and counting..! #SecurityFoster #CyberSecurity #paas #SaaS #Celebrations
2
7
13