Shebiiiii Profile
Shebiiiii

@xshebix

Followers
670
Following
16K
Media
49
Statuses
4K

Cyber Security Researcher - Red Team Member at Synack

Joined November 2016
Don't wanna be here? Send us removal request.
@xshebix
Shebiiiii
3 years
Hello all security enthusiasts! During a recent security assessment for a private client, I came across a potential cross-site scripting (XSS) vulnerability that I wanted to share with you. 1/n #security #cybersecurity #penetrationtesting #informationsecurity #bughunting #xss
5
12
95
@pentest_swissky
Swissky
10 months
Configuring Android Emulator with Burp Suite https://t.co/fpDDlQ7Ek6
1
75
297
@nullenc0de
Paul Seekamp
2 years
@TanmayLP7 If you are running automated scanners. This is about 95-98% of the things that are missed. Also, if you want to make a name for yourself in BB or web app pentest world. Get really good at these.
1
3
15
@hamzaavvan
Hamza Avvan
2 years
Check out my playlist: Road To Ethical Hacking https://t.co/OlKzqowoEz via @YouTube
Tweet card summary image
youtube.com
0
1
3
@shaybt12
shay
2 years
you found Jfrog URL and you get 403 / 401 ? try to add /ui/repos/tree/General mabye you get lucky and found nuget / other compile customer source code :)
1
31
147
@0xblackbird
0xblackbird
2 years
Still haven't found your first SSRF vulnerability? Or only found a useless blind SSRF somewhere but couldn't get to escalate it? You're probably looking at the wrong place... Here, a mega-thread on Server-Side Request Forgeries (SSRF) vulnerabilities👇️
6
159
537
@ransomsec
xlr8 •
2 years
Unexpected! 😂 But worth it! Add this 'database.create.json' in your wordlist. #BugBounty #bugbountytips
12
114
486
@busf4ctor
Vitor Falcão "busfactor"
2 years
Most people believe SQL injections are in the past. They say it's hard to find them. The main issue is the use of automated tools like SQLMap. I'll go through the reasons in this thread so you can give your opinions.
5
56
293
@ShaykhSulaiman
Sulaiman Ahmed
2 years
ISRAEL BREAKS INTERNATIONAL LAW
929
21K
36K
@ThisIsDK999
Debangshu 🇮🇳🥷
2 years
https://t.co/A3OdrTFnq2: the intentionally open redirect #bugbountytip
1
44
169
@GodfatherOrwa
Godfather Orwa 🇯🇴
2 years
مات الطبيب و المسعف و الجريح كل ذنبك يا فلسطين انك جميله كسيدنا يوسف و العالم خانك مثل اخوته
11
65
347
@_ayoubfathi_
Ayoub FATHI 阿尤布
2 years
I’ve published the slides for my @bsidesahmedabad closing keynote: https://t.co/9rh4x3ymq3 In this talk, I shared: “Lateral movement brute forcing” — a new technique that I covered and used against different targets to go, eg. From a limited GitHub token to achieve multi-lateral
Tweet card summary image
docs.google.com
Laws, Compliance and Data Privacy Regulations A CISO Perspective: How to ensure Business Continuity by staying compliant with cybersecurity laws and regulations Ayoub Fathi @_ayoubfathi_
1
82
255
@rana__khalil
Rana Khalil 🇵🇸
2 years
It’s been tough being on social media the past couple of days. My own family, like thousands of Palestinians, was ethnically cleansed by Israel 75 years ago, and was denied the right of return to Palestine. For 75 years, Israel has forcibly displaced entire Palestinian
0
186
1K
@0x_rood
🇸🇦 Murtada Bin Abdullah (Rood)
2 years
If you found /actuator/jolokia/ endpoint in your target you can escalate it to LFI POC: https://target[.]com/actuator/jolokia/exec/com.sun.management:type=DiagnosticCommand/compilerDirectivesAdd/!/etc!/passwd
5
71
217
@0xM5awy
Mohamed Anani
2 years
Good morning! I've been using this payload for over a year to discover XSS via open redirect vulnerabilities that bypass WAF. It works great: :DD Payload: javascript%3avar{a%3aonerror}%3d{a%3aalert}%3bthrow%2520document.cookie #BugBounty #bugbountytips #bugbountytip
8
140
438
@0xLupin
Lupin
2 years
XSS with no parenthesis 🔥 Thanks to @Rhynorater for sending me this target with a really weird filter. It was a fun challenge 🤟 Btw I'm not the one that discovered the use of instanceof for XSS ;) #bugbountytips
5
44
219
@_hg8_
𝚑𝚐𝟾
2 years
"Web Application Black-Box Testing" by @yeswehack Outline various black-box testing techniques and payload generation for performing offensive tests against web applications. https://t.co/C526w1xPZl #bugbounty #pentest
2
92
301
@soldierspeaks
Adil Raja
2 years
Sources claim that the military junta wants to murder Imran Khan in jail through poisoning him. He is being kept in inhumane conditions.
417
4K
9K