hackipy's profile picture. Breaking Security Legally

Muhammad Sarim Raza

@hackipy

Breaking Security Legally

Pinned

Thanks for the swag❤️ @Sony

hackipy's tweet image. Thanks for the swag❤️ @Sony

Muhammad Sarim Raza reposted

Interesting technique by @j_zere: When a cache deception requires a specific header/token that you can't directly provide, try chaining it with CSPT to make it exploitable.

ctbbpodcast's tweet image. Interesting technique by @j_zere: 
When a cache deception requires a specific header/token that you can't directly provide, try chaining it with CSPT to make it exploitable.

Muhammad Sarim Raza reposted

I Researched Ruby class pollutions and discovered a new exploitation method, Rotate Chains, achieving 100% exploit success rate; also created a bi0s CTF 2025 challenge based on the technique which had 0 solves. Read the research/writeup: winters0x64.xyz/posts/post-2


I don’t get why bug hunters tweet stuff like ‘Had a great month’ and post a screenshot with everything censored… and the reports aren’t even triaged yet. Thanks to HackerOne for that trailing dot showing the status of every report. What exactly are you trying to show?


Muhammad Sarim Raza reposted

If your target uses Rails, look for Action View CVE-2019-5418 - File Content Disclosure vuln. Although this is an old bug, it can still be found. Intercept the request in Burp and replace the Accept header with: `Accept: ../../../../../../../../../../etc/passwd{{` #bugbountytips

nav1n0x's tweet image. If your target uses Rails, look for Action View CVE-2019-5418 - File Content Disclosure vuln. Although this is an old bug, it can still be found.

Intercept the request in Burp and replace the Accept header with: `Accept: ../../../../../../../../../../etc/passwd{{` #bugbountytips

Muhammad Sarim Raza reposted

Bug Hunters 🔥 Ever stumbled upon this weird message? "WebSockets request was expected" If you did, congratz! You just found a NodeJS server in debug mode, ready to quickly move on to RCE via simple DevTools 💥💥💥 Search for this message in Censys/FOFA and your automation 🤑

chux13786509's tweet image. Bug Hunters 🔥
Ever stumbled upon this weird message?
"WebSockets request was expected"

If you did, congratz!
You just found a NodeJS server in debug mode, ready to quickly move on to RCE via simple DevTools 💥💥💥
Search for this message in Censys/FOFA and your automation 🤑
chux13786509's tweet image. Bug Hunters 🔥
Ever stumbled upon this weird message?
"WebSockets request was expected"

If you did, congratz!
You just found a NodeJS server in debug mode, ready to quickly move on to RCE via simple DevTools 💥💥💥
Search for this message in Censys/FOFA and your automation 🤑

Muhammad Sarim Raza reposted

Just dropped a new video on Web Cache Deception to Account Takeover packed with powerful bypass techniques. Don’t miss it! youtu.be/Epzi1fWwdKk?si…

coffinxp7's tweet card. Mastering Web Cache Deception: From Exploit to Account Takeover, a...

youtube.com

YouTube

Mastering Web Cache Deception: From Exploit to Account Takeover, a...


United States Trends

Loading...

Something went wrong.


Something went wrong.