RashedulCSS's profile picture. Cybersecurity Enthusiast | Python Lover | PowerPoint Hero | Fiery Typist | Student at University of Dhaka

Rashedul Islam

@RashedulCSS

Cybersecurity Enthusiast | Python Lover | PowerPoint Hero | Fiery Typist | Student at University of Dhaka

Pinned

Alhamdulillah...! #Top_2 once again on Tecno Mobile Security Response Center @TecnoSRC! Rewarded with $7,300 including the special recognition #Diligent_Star. "...And Allah provides for whoever He wills without limit." [Al Quran - Sura 24:38] #bugbounty #cyber #security

RashedulCSS's tweet image. Alhamdulillah...!

#Top_2 once again on Tecno Mobile Security Response Center @TecnoSRC!

Rewarded with $7,300 including the special recognition #Diligent_Star.

"...And Allah provides for whoever He wills without limit." [Al Quran - Sura 24:38]

#bugbounty #cyber #security

I just completed module #API #Attacks in @hackthebox_eu...! Price: $10 The last challenge will teach you once again to 'Try Harder'... You'll learn here the OWASP Top 10 API Security Risks... My Rating: 4.7 academy.hackthebox.com/achievement/20… #hackthebox #htbacademy #cybersecurity

RashedulCSS's tweet image. I just completed module #API #Attacks in @hackthebox_eu...!

Price: $10

The last challenge will teach you once again to 'Try Harder'...

You'll learn here the OWASP Top 10 API Security Risks...

My Rating: 4.7

academy.hackthebox.com/achievement/20…

#hackthebox #htbacademy #cybersecurity

What an insight! @NahamSec "When I can't find bugs, I change perspective not targets. Client-side -> API Issues Main App -> Developer Platform" "Give Me 13 Minutes and 2025 Will Be Your Best Bug Bounty Year" YouTube Link: youtube.com/watch?v=PER6Nv…

RashedulCSS's tweet image. What an insight! @NahamSec

"When I can't find bugs, I change perspective not targets.

Client-side -> API Issues
Main App -> Developer Platform"

"Give Me 13 Minutes and 2025 Will Be Your Best Bug Bounty Year"

YouTube Link: youtube.com/watch?v=PER6Nv…

Alhamdulillah! Awarded with $600 for finding an IDOR vulnerability! Context: - The Web App was letting users to upload payment screenshots if they chose 'Bank Transfer' method for boosting their posts. - But abusing the IDOR vulnerability, I could upload/replace victims' images.

RashedulCSS's tweet image. Alhamdulillah!
Awarded with $600 for finding an IDOR vulnerability!

Context:
- The Web App was letting users to upload payment screenshots if they chose 'Bank Transfer' method for boosting their posts.
- But abusing the IDOR vulnerability, I could upload/replace victims' images.

Alhamdulillah...! Rewarded with $480 for a Race Condition attack...! Double Tips for Hunters: 1. Always test #race_condition if a function offers rewards e.g., coin, money, etc. 2. Don't hesitate to negotiate logically with programs. #bugbounty #whitehat #race #condition #tips

RashedulCSS's tweet image. Alhamdulillah...!
Rewarded with $480 for a Race Condition attack...!

Double Tips for Hunters:
1. Always test #race_condition if a function offers rewards e.g., coin, money, etc.

2. Don't hesitate to negotiate logically with programs.

#bugbounty #whitehat #race #condition #tips

Alhamdulillah...! Rewarded with $500 for a Stored XSS for Bypassing the Validation... Tips for You: Never trust the first page security! My malicious name was validated when I commented for the first time. But when I REPLIED to MY comment then it fired. #bugbounty #xss #tips

RashedulCSS's tweet image. Alhamdulillah...!
Rewarded with $500 for a Stored XSS for Bypassing the Validation...

Tips for You:
Never trust the first page security!
My malicious name was validated when I commented for the first time.

But when I REPLIED to MY comment then it fired.

#bugbounty #xss #tips

Alhamdulillah...! Awarded with $750 for an IDOR issue...! Tip: Change the target website's country/language to a different one. Because sometimes it may offer an additional feature for another region. Example: rashedulcss.com/?lan=en ➡️ rashedulcss.com/?lan=ar #bugbounty #tips

RashedulCSS's tweet image. Alhamdulillah...!
Awarded with $750 for an IDOR issue...!

Tip: Change the target website's country/language to a different one. Because sometimes it may offer an additional feature for another region.

Example: rashedulcss.com/?lan=en ➡️ rashedulcss.com/?lan=ar

#bugbounty #tips

Huge shout-out to @TecnoSRC ! Glad to have you @L3onid1s, @MdInjamulHaqu, @msnrasel, @araselmir, @Ontu404, @Hasan_Khan0X, @itsz4x, @akbar_ohi who made the meetup more enjoyable...! Ready for the next journey...?

👍Thanks to @RashedulCSS's organization, we have seen the style of Bangladesh security researchers! 🥰We also look forward to more fresh blood joining us in 2025! Contribute your strength to the 2025 TECNO security journey! #infosec #bugbounty #AppSec #cybersecurity #hack #MEETUP

TecnoSRC's tweet image. 👍Thanks to @RashedulCSS's organization, we have seen the style of Bangladesh security researchers! 🥰We also look forward to more fresh blood joining us in 2025! Contribute your strength to the 2025 TECNO security journey! #infosec #bugbounty #AppSec #cybersecurity #hack #MEETUP
TecnoSRC's tweet image. 👍Thanks to @RashedulCSS's organization, we have seen the style of Bangladesh security researchers! 🥰We also look forward to more fresh blood joining us in 2025! Contribute your strength to the 2025 TECNO security journey! #infosec #bugbounty #AppSec #cybersecurity #hack #MEETUP
TecnoSRC's tweet image. 👍Thanks to @RashedulCSS's organization, we have seen the style of Bangladesh security researchers! 🥰We also look forward to more fresh blood joining us in 2025! Contribute your strength to the 2025 TECNO security journey! #infosec #bugbounty #AppSec #cybersecurity #hack #MEETUP


Thanks for the huge bounty, @TecnoSRC !

💎Congratulations to every one of the top 10 security researchers in 2024! And thank you to all the researchers who supported us in 2024. 💡More activities are coming soon, so stay tuned! #infosec #bugbounty #AppSec #cybersecurity #hack

TecnoSRC's tweet image. 💎Congratulations to every one of the top 10 security researchers in 2024! And thank you to all the researchers who supported us in 2024. 
💡More activities are coming soon, so stay tuned! #infosec #bugbounty #AppSec #cybersecurity #hack


Creative attack, @AkashHamal0x01 brother...! He bypassed HackerOne 2FA abusing race condition... Link: hackerone.com/reports/2598548


Alhamdulillah...! @TecnoSRC (TECNO Mobile) featured me in their anniversary as a "#Security_Researcher with the Most Badges" for my contributions to their overall Android Applications and Websites security.

RashedulCSS's tweet image. Alhamdulillah...!
@TecnoSRC (TECNO Mobile) featured me in their anniversary as a "#Security_Researcher with the Most Badges" for my contributions to their overall Android Applications and Websites security.

Alhamdulillah... Rewarded with $7K (6K+1K) for being #TOP_2 in the yearly leaderboard (globally) of TECNO Security Response Center with the special recognition #Precious_Gem. "...And Allah provides for whoever He wills without limit." [Al Quran - Sura 24:38] #bugbounty #security

RashedulCSS's tweet image. Alhamdulillah...
Rewarded with $7K (6K+1K) for being #TOP_2 in the yearly leaderboard (globally) of TECNO Security Response Center with the special recognition #Precious_Gem.

"...And Allah provides for whoever He wills without limit." [Al Quran - Sura 24:38]
#bugbounty #security

Now #VIP Hacker of @TecnoSRC (TECNO Mobile Brand)...! Just received the badge today... It requires 4 high/6 medium valid vulnerability reports... Dive deep matters...! #bug #bounty #ethical #hacking


Loading...

Something went wrong.


Something went wrong.