programmer__boy's profile picture. Bug Bounty Hunter, OSCP ,OSEP,ECPPTv2 Certified ,Software Engineer,Penetration Tetser

Ali Zain Zahid

@programmer__boy

Bug Bounty Hunter, OSCP ,OSEP,ECPPTv2 Certified ,Software Engineer,Penetration Tetser

置頂

By the grace of Allah Almighty i Got #OSEP certified Thank you @offsectraining for providing such an Intense Training. Learnt alot and will definitely recommend this Certification

programmer__boy's tweet image. By the grace of Allah Almighty i Got #OSEP certified 
Thank you @offsectraining for providing such an Intense Training. Learnt alot and will definitely recommend this Certification

Ali Zain Zahid 已轉發

🛡️ 𝐀 𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐄𝐧𝐠𝐢𝐧𝐞𝐞𝐫'𝐬 𝐆𝐮𝐢𝐝𝐞 𝐭𝐨 𝐌𝐂𝐏 If you need to learn how to test & secure MCPs in your org in a hurry... Get up to speed in 10min + a free MCP security cheatsheet of exactly what to look for.

clintgibler's tweet image. 🛡️ 𝐀 𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐄𝐧𝐠𝐢𝐧𝐞𝐞𝐫'𝐬 𝐆𝐮𝐢𝐝𝐞 𝐭𝐨 𝐌𝐂𝐏
If you need to learn how to test & secure MCPs in your org in a hurry...
Get up to speed in 10min + a free MCP security cheatsheet of exactly what to look for.

Ali Zain Zahid 已轉發
akaclandestine's tweet image. DarkGPT

Link :
…w2rxtdwz7y6b5u4jhlck3xdhmepvhid.onion

Ali Zain Zahid 已轉發

☄️Photon - Fast web crawler for osint and recon 🚀github.com/s0md3v/Photon

HackingTeam777's tweet image. ☄️Photon - Fast web crawler for osint and recon

🚀github.com/s0md3v/Photon

Ali Zain Zahid 已轉發

𝗖𝗶𝗽𝗵𝗲𝘆 🕵🏽‍♂️ ⚡ Descifra automáticamente cifrados sin conocer la clave o el algoritmo, decodifica codificaciones y rompe hashes. Ideal para #CTFs ⚡ 🔗 github.com/bee-san/Ciphey

HackingTeam777's tweet image. 𝗖𝗶𝗽𝗵𝗲𝘆 🕵🏽‍♂️

⚡ Descifra automáticamente cifrados sin conocer la clave o el algoritmo, decodifica codificaciones y rompe hashes. Ideal para #CTFs ⚡

🔗 github.com/bee-san/Ciphey

Ali Zain Zahid 已轉發

Stop using basic XSS payloads. @RenwaX23 compiled the nastiest collection of parentheses-free XSS eval.apply${[alert\\x2823\\x29]} `Reflect.apply.call`${alert}${undefined}${}`[11] `throw onerror=eval,SyntaxError`alert\\x2823\\x29 Check it out: github.com/RenwaX23/XSS-P…


Ali Zain Zahid 已轉發

Automates SQL injection testing using SQLMap with AI-powered decision making.⚙️ - github.com/0xSojalSec/sql… #infosec #cybersec #bugbountytips

0x0SojalSec's tweet image. Automates SQL injection testing using SQLMap with AI-powered decision making.⚙️

- github.com/0xSojalSec/sql…

#infosec #cybersec #bugbountytips

Ali Zain Zahid 已轉發

HexStrike AI: The World's Most Advanced AI-Powered Penetration Testing Framework with Autonomous Agents, Intelligent Decision Engine, and 150+ Security Tools. GitHub: github.com/0x4m4/hexstrik…

DarkWebInformer's tweet image. HexStrike AI: The World's Most Advanced AI-Powered Penetration Testing Framework with Autonomous Agents, Intelligent Decision Engine, and 150+ Security Tools.

GitHub: github.com/0x4m4/hexstrik…
DarkWebInformer's tweet image. HexStrike AI: The World's Most Advanced AI-Powered Penetration Testing Framework with Autonomous Agents, Intelligent Decision Engine, and 150+ Security Tools.

GitHub: github.com/0x4m4/hexstrik…

Ali Zain Zahid 已轉發

scan4all: Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port scanning; Fuzz, HW, awesome BugBounty GitHub: github.com/GhostTroops/sc…

DarkWebInformer's tweet image. scan4all: Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port scanning; Fuzz, HW, awesome BugBounty

GitHub: github.com/GhostTroops/sc…

Ali Zain Zahid 已轉發

GitHub - pr0v3rbs/CVE-2025-32463_chwoot: sudo Local Privilege Escalation CVE-2025-32463 - github.com/pr0v3rbs/CVE-2…


Ali Zain Zahid 已轉發

Here are the slides from my @TumpiConIT talk: Teaching LLMs how to XSS - An introduction to fine-tuning and reinforcement learning (using your own GPU) docs.google.com/presentation/d…


Ali Zain Zahid 已轉發

You keep asking about realistic usage of Burp Suite, and I like it. Let's dig through old, but still relevant, blog posts... ⤵️


Ali Zain Zahid 已轉發

Congrats! PoC usually: 1️⃣ Find target email, create email with punycode version 2️⃣ Reset password with unicoded version 3️⃣ Find reset password link in attacker's creates email adress

Account takeover due to unicode normalization issue. - Victim account: [email protected] - Attacker account: ynoⓞ[email protected] Due to no validation send to the email and some unicode issues , this leads to account takeover. Thanks @HusseiN98D for the idea. #bugbountytips

YnoofAssiri's tweet image. Account takeover due to unicode normalization issue.

- Victim account: ynoof@hotmail.com
- Attacker account: ynoⓞf@hotmail.com

Due to no validation send to the email and some unicode issues , this leads to account takeover.
Thanks @HusseiN98D for the idea.
#bugbountytips


Ali Zain Zahid 已轉發

If you never used the Piper extension, I recommend to watch the 4-minute demo I gave last year during my talk at @NorthSec_io 🛠️ youtube.com/watch?v=N7BN--…

MasteringBurp's tweet card. NSEC2023 - Burp Suite Pro tips and tricks, the sequel

youtube.com

YouTube

NSEC2023 - Burp Suite Pro tips and tricks, the sequel

Basically allows you to execute **any** tool/command on **any** part of an HTTP request/réponse. It can pipe tools together as well as automatically execute pipelines. You can even launch GUI tools such as meld for easy diffing @Agarri_FR mentioned it a while ago and it's awesome



Ali Zain Zahid 已轉發

AdaptixC2 v0.5 is out github.com/Adaptix-Framew… * Windows "gopher" agent * Fast socks5 tunnels via "gopher" agent * Remote Terminal * Client side tunnels More details in the changelog: adaptix-framework.gitbook.io/adaptix-framew…

hacker_ralf's tweet image. AdaptixC2 v0.5 is out

github.com/Adaptix-Framew…

* Windows "gopher" agent
* Fast socks5 tunnels via "gopher" agent
* Remote Terminal
* Client side tunnels

More details in the changelog: adaptix-framework.gitbook.io/adaptix-framew…

Ali Zain Zahid 已轉發

Just released WPProbe v0.6.0! It now includes a bruteforce mode and a hybrid scan (REST endpoints + bruteforce). Check it out: github.com/Chocapikk/wppr… (Thanks @ibrahimsql for the PR)

Chocapikk_'s tweet image. Just released WPProbe v0.6.0! It now includes a bruteforce mode and a hybrid scan (REST endpoints + bruteforce). Check it out: github.com/Chocapikk/wppr… (Thanks @ibrahimsql  for the PR)

Ali Zain Zahid 已轉發

Built a Burp Suite extension to run SQLmap directly from the GUI. No more saving HTTP requests + jumping to terminal. Just: – Mark param with * – Right-click → Send to SQLmap – Pick options → Run Linux-only for now. Windows support coming soon. Full write-up:…

iYousefAlotaibi's tweet image. Built a Burp Suite extension to run SQLmap directly from the GUI.

No more saving HTTP requests + jumping to terminal.

Just:
– Mark param with *
– Right-click → Send to SQLmap
– Pick options → Run

Linux-only for now. Windows support coming soon.
Full write-up:…

Ali Zain Zahid 已轉發

IngressNightmare: 9.8 Critical Unauthenticated Remote Code Execution Vulnerabilities in Ingress NGINX - @wiz_io wiz.io/blog/ingress-n…


Ali Zain Zahid 已轉發

GoExec 是用于在 Windows 设备上实现远程执行方法的新尝试。GoExec 实现了许多尚未广泛应用的执行方法,并整体上提供了显著的操作安全性(OPSEC)改进。 github.com/FalconOpsLLC/g…


Ali Zain Zahid 已轉發

collect emails, usernames from commit history of repos of an org from GitHub for more personalized targeting of employees ghintel.secrets.ninja

SecretsN1nja's tweet image. collect emails, usernames from commit history of repos of an org from GitHub for more personalized targeting of employees

ghintel.secrets.ninja

Loading...

Something went wrong.


Something went wrong.