leetIbrahim's profile picture. Hacker

Ibrahim

@leetIbrahim

Hacker

سعدت بالحصول على مكافأة مالية بقيمة 21 الف ريال من منصة اكتشاف الثغرات @BugBountySA #BugBounty

leetIbrahim's tweet image. سعدت بالحصول على مكافأة مالية بقيمة 21 الف ريال من منصة اكتشاف الثغرات @BugBountySA 

#BugBounty

One of the biggest mistakes you probably make when trying to find an API token or sensitive information in JS files is relying only on automated tools like JSRecon without checking the files manually. I found an access token that let me into a company's internal website where i…


Ibrahim 已转帖

Saudi Arabia TEAM is on FIRE!! 🔥🔥 4 days remaining Leaderboard: leaderboards.hackerone.live/awc2024 #AmbassadorWorldCup @Hacker0x01


I was awarded a $3,000 bounty on @Hacker0x01! hackerone.com/nightm4re #TogetherWeHitHarder ATO i guess?


See you in the next round!

leetIbrahim's tweet image. See you in the next round!

الحمدلله ممثلين لفريق السعودية 🇸🇦 تأهلنا الى دور الـ16 في كأس العالم هكر ون، شكراً @hacker0x01 على التنظيم الرهيب. فخورين بفريقنا ونكمل مشوارنا للقب بتوفيق الله! 🏆🚀 We made it! Team Saudi to the Sweet Sixteen in #AWC2024 🎉, Huge thanks to @Hacker0x01 for the amazing event

r00t_nasser's tweet image. الحمدلله ممثلين لفريق السعودية 🇸🇦
تأهلنا الى دور الـ16 في كأس العالم هكر ون، شكراً @hacker0x01 على التنظيم الرهيب. فخورين بفريقنا ونكمل مشوارنا للقب بتوفيق الله! 🏆🚀

We made it! Team Saudi to the Sweet Sixteen in #AWC2024 🎉, Huge thanks to @Hacker0x01 for the amazing event


Ibrahim 已转帖

LY Corporation disclosed a bug submitted by @leetibrahim: hackerone.com/reports/2403554 #hackerone #bugbounty

disclosedh1's tweet image. LY Corporation disclosed a bug submitted by @leetibrahim: hackerone.com/reports/2403554 #hackerone #bugbounty

Ibrahim 已转帖

الحمدلله تأهلنا مع ال32 فريق الى دور المجموعات وضمن الفرق الاساسية (افضل 8 فرق) في مسابقة كأس العالم هكر ون 2024 🇸🇦💪 Saudi Arabia qualified to group stage with 32 teams and as one of the main teams for the next round (Top 8) 🇸🇦💪 #AWC2024

AMakki1337's tweet image. الحمدلله تأهلنا مع ال32 فريق الى دور المجموعات وضمن الفرق الاساسية (افضل 8 فرق) في مسابقة كأس العالم هكر ون  2024 🇸🇦💪

Saudi Arabia qualified to group stage with 32 teams and as one of the main teams for the next round (Top 8)  🇸🇦💪

#AWC2024

I was awarded a $2,400 bounty on @Hacker0x01! hackerone.com/nightm4re #TogetherWeHitHarder Broken Access Control


I should be faster next time

leetIbrahim's tweet image. I should be faster next time

Ibrahim 已转帖

تم قبول ممثلي المملكة العربية السعودية 🇸🇦 لمسابقة AWC 2024 هكر ون @Hacker0x01 🏆 المشاركين: @AMakki1337 @0x_rood @eman_yazji @r00t_nasser @0xRaw @0xRAYAN7 @Ahmed0Makki @Ibrah1m_0x @leetibrahim @AlHomaidNoor @abdlah_md @stuipds @Liliexx2 @omarzzu @9yk @Dr_Ro0T

AMakki1337's tweet image. تم قبول ممثلي المملكة العربية السعودية  🇸🇦
لمسابقة AWC 2024 هكر ون @Hacker0x01 🏆

المشاركين:
@AMakki1337 
@0x_rood
@eman_yazji
@r00t_nasser
@0xRaw 
@0xRAYAN7 
@Ahmed0Makki
@Ibrah1m_0x
@leetibrahim
@AlHomaidNoor
@abdlah_md
@stuipds 
@Liliexx2
@omarzzu
@9yk
@Dr_Ro0T

My tip on how I found a subdomain takeover: 1. Got a notification that a new domain had been added to the scope 2. Subdomain enum using ffuf, resolved them using dnsx 3. Checked the CNAME of valid subdomains 4. One of the subdomains was pointing to non-registered Azure service.

Let’s take a break #BugBounty

leetIbrahim's tweet image. Let’s take a break

#BugBounty


The best extension in burpsuite!

leetIbrahim's tweet image. The best extension in burpsuite!
leetIbrahim's tweet image. The best extension in burpsuite!

Let’s take a break #BugBounty

leetIbrahim's tweet image. Let’s take a break

#BugBounty

The most enjoyable XSS I have found. Let's get back to the game #BugBounty

leetIbrahim's tweet image. The most enjoyable XSS I have found. 
Let's get back to the game
#BugBounty

Ibrahim 已转帖

Don't discount dead subdomains in bug bounty! Try enumerating them against valid target IP addresses, who knows what you might find 😏 @leetibrahim has had some success with this tip, hopefully you will too! #bugbounty #bugbountytips 👇

intigriti's tweet image. Don't discount dead subdomains in bug bounty! Try enumerating them against valid target IP addresses, who knows what you might find 😏

@leetibrahim has had some success with this tip, hopefully you will too!

#bugbounty #bugbountytips 👇

I just received the lousy t-shirt from @DutchMFA gov #bugbounty

leetIbrahim's tweet image. I just received the lousy t-shirt from @DutchMFA gov

#bugbounty

Loading...

Something went wrong.


Something went wrong.