Shebiiiii
@xshebix
Followers
670
Following
16K
Media
49
Statuses
4K
Cyber Security Researcher - Red Team Member at Synack
Joined November 2016
Hello all security enthusiasts! During a recent security assessment for a private client, I came across a potential cross-site scripting (XSS) vulnerability that I wanted to share with you. 1/n #security #cybersecurity #penetrationtesting #informationsecurity #bughunting #xss
5
12
95
This Writeup exaplains how we got ATO from Android Application https://t.co/fGNdTIM8HA
#BugBounty #bugbountytip #cybersecuritytips #hackerone
medium.com
Hello friend, Me and my friend oXnoOneXo were recently looking for an android application at Bugcrowd to hack on and luckily we found an…
2
29
125
Bypass Reset Password Code Lead to Account Takeover https://t.co/aHGsODSaJF GitHub python script https://t.co/4kIA4YFlsS
#bugbountytips #bugbounty
github.com
Bypass Reset Password Code Lead to Account Takeover - Lu3ky13/Bypass-Reset-Password-Code-Lead-to-Account-Takeover
3
54
222
@TanmayLP7 If you are running automated scanners. This is about 95-98% of the things that are missed. Also, if you want to make a name for yourself in BB or web app pentest world. Get really good at these.
1
3
15
Check out my playlist: Road To Ethical Hacking https://t.co/OlKzqowoEz via @YouTube
youtube.com
0
1
3
you found Jfrog URL and you get 403 / 401 ? try to add /ui/repos/tree/General mabye you get lucky and found nuget / other compile customer source code :)
1
31
147
Still haven't found your first SSRF vulnerability? Or only found a useless blind SSRF somewhere but couldn't get to escalate it? You're probably looking at the wrong place... Here, a mega-thread on Server-Side Request Forgeries (SSRF) vulnerabilities👇️
6
159
537
Unexpected! 😂 But worth it! Add this 'database.create.json' in your wordlist. #BugBounty #bugbountytips
12
114
486
Most people believe SQL injections are in the past. They say it's hard to find them. The main issue is the use of automated tools like SQLMap. I'll go through the reasons in this thread so you can give your opinions.
5
56
293
مات الطبيب و المسعف و الجريح كل ذنبك يا فلسطين انك جميله كسيدنا يوسف و العالم خانك مثل اخوته
11
65
347
I’ve published the slides for my @bsidesahmedabad closing keynote: https://t.co/9rh4x3ymq3 In this talk, I shared: “Lateral movement brute forcing” — a new technique that I covered and used against different targets to go, eg. From a limited GitHub token to achieve multi-lateral
docs.google.com
Laws, Compliance and Data Privacy Regulations A CISO Perspective: How to ensure Business Continuity by staying compliant with cybersecurity laws and regulations Ayoub Fathi @_ayoubfathi_
1
82
255
It’s been tough being on social media the past couple of days. My own family, like thousands of Palestinians, was ethnically cleansed by Israel 75 years ago, and was denied the right of return to Palestine. For 75 years, Israel has forcibly displaced entire Palestinian
0
186
1K
we earned $20,000 for Our submission on @bugcrowd
@haxor31337
@GodfatherOrwa It's nice to work with you guys :) #Tip: Always check `viewstate` In Asp. Net More Info : https://t.co/xmwkZGFkOu
https://t.co/04NTyt2B0S
#ItTakesACrowd
notsosecure.com
In this blog post, Sanjay talks of various test cases to exploit ASP.NET ViewState deserialization using Blacklist3r and YSoSerial.Net. Blacklist3r is used to identify the use of pre-shared
5
50
318
If you found /actuator/jolokia/ endpoint in your target you can escalate it to LFI POC: https://target[.]com/actuator/jolokia/exec/com.sun.management:type=DiagnosticCommand/compilerDirectivesAdd/!/etc!/passwd
5
71
217
Good morning! I've been using this payload for over a year to discover XSS via open redirect vulnerabilities that bypass WAF. It works great: :DD Payload: javascript%3avar{a%3aonerror}%3d{a%3aalert}%3bthrow%2520document.cookie #BugBounty #bugbountytips #bugbountytip
8
140
438
XSS with no parenthesis 🔥 Thanks to @Rhynorater for sending me this target with a really weird filter. It was a fun challenge 🤟 Btw I'm not the one that discovered the use of instanceof for XSS ;) #bugbountytips
5
44
219
"Web Application Black-Box Testing" by @yeswehack Outline various black-box testing techniques and payload generation for performing offensive tests against web applications. https://t.co/C526w1xPZl
#bugbounty #pentest
2
92
301
Sources claim that the military junta wants to murder Imran Khan in jail through poisoning him. He is being kept in inhumane conditions.
417
4K
9K