HackFinal's profile picture. Bug Bounty Hunter | Full Stack Web Developer 🇲🇦

amfinal

@HackFinal

Bug Bounty Hunter | Full Stack Web Developer 🇲🇦

amfinal さんがリポスト

🕵️‍♂️ Calling fellow Bug Bounty hunters who consume daily blogs, articles, talks, and research There’s too much surface-level content out there -finding the meaningful gems is hard. I’m starting a closed group (currently me & @4osp3l) Retweet + comment “Interested” if you want in


amfinal さんがリポスト

Don't waste your money on cheap and unstructured DevOps courses. ❌ Learn from Harvard, Stanford, Microsoft, IBM, Amazon and Google for zero cost. 🤯 Thread 🧵👇


In July i reported 22 bugs to one program most of them were stored xss 1 blind xss => ATO 2 authorization bypass


amfinal さんがリポスト

Free Black Hat GraphQL Book Giveaway! Retweet for your chance to win! #graphql #api #hacking #book #giveaway (10 signed books)

Nick_Aleks's tweet image. Free Black Hat GraphQL Book Giveaway! Retweet for your chance to win! #graphql #api #hacking #book #giveaway (10 signed books)

🔥🔥🔥

HackFinal's tweet image. 🔥🔥🔥

amfinal さんがリポスト

On Twitter, if you read more than 600 tweets you die

pikacodes's tweet image. On Twitter, if you read more than 600 tweets you die

amfinal さんがリポスト

Mind-Maps for Bug Hunters, Penetration Testers, Offensive/Defensive Security Professionals github.com/imran-parray/M… #cybersecurity #bughunting

0xAsm0d3us's tweet image. Mind-Maps for Bug Hunters, Penetration Testers, Offensive/Defensive Security Professionals

github.com/imran-parray/M…

#cybersecurity #bughunting

I don't know how i forgot about this report but it's been a year since i reported it . Today they triaged it 😂

HackFinal's tweet image. I don't know how i forgot about this report but it's been a year since i reported it . Today they triaged it 😂

Good morning 🌞

HackFinal's tweet image. Good morning 🌞

just found a cool bug which I was able to take over account of any user including admin console


amfinal さんがリポスト

Come join me this Sunday with @OwaspNagpur as I go through my thoughts when testing. I'll be going through a web app live and giving my raw thoughts as I navigate through the various features available

zseano's tweet image. Come join me this Sunday with @OwaspNagpur as I go through my thoughts when testing. I'll be going through a web app live and giving my raw thoughts as I navigate through the various features available

OWASP NAGPUR 🍊 MEET #11 Sessions: 1) A look into Zseanos thoughts when testing a target - @zseano 2)Traversing my way in the Internal Network - @JR0ch17 Join us this Sunday for OWASP Nagpur Meet #11 meetup.com/OWASP-Nagpur-C… #appsec #security #nagpur #owasp #bugbounty

OwaspNagpur's tweet image. OWASP NAGPUR 🍊 MEET #11

Sessions: 
1) A look into Zseanos thoughts when testing a target - @zseano 

2)Traversing my way in the Internal Network - @JR0ch17

Join us this Sunday for OWASP Nagpur Meet #11
meetup.com/OWASP-Nagpur-C…

#appsec #security #nagpur #owasp #bugbounty
OwaspNagpur's tweet image. OWASP NAGPUR 🍊 MEET #11

Sessions: 
1) A look into Zseanos thoughts when testing a target - @zseano 

2)Traversing my way in the Internal Network - @JR0ch17

Join us this Sunday for OWASP Nagpur Meet #11
meetup.com/OWASP-Nagpur-C…

#appsec #security #nagpur #owasp #bugbounty


amfinal さんがリポスト

Accounts takeover via web cache poisoning. Site was using Cloudfront > run Param Miner > found a secret header: X-Forwarded-For reflecting in response > tried xss payload > executed successfully > poisoned site.tld/?cache=xss endpoint


today I got my first bounty thanks to @InsiderPhD


United States トレンド

Loading...

Something went wrong.


Something went wrong.