yoyomiski's profile picture. sometimes eat and sleep

yoyomiski

@yoyomiski

sometimes eat and sleep

I no longer test VDP programs. However, since this is an open-source project and vulnerabilities found can be assigned CVEs, I spent some time last week reviewing it. I'm also glad that these are my first 4 CVEs #bugbounty #CVE

yoyomiski's tweet image. I no longer test VDP programs. However, since this is an open-source project and vulnerabilities found can be assigned CVEs, I spent some time last week reviewing it. I'm also glad that these are my first 4 CVEs
#bugbounty #CVE

yoyomiski reposted

Just released the Ultimate IDOR Testing Checklist 🧩 I combined techniques from many sources to cover IDOR scenarios. Know a technique I missed? Drop it in the comments. Notion: mrdesoky0.notion.site/Ultimate-IDOR-… GitHub: github.com/mrdesoky0/vuln… #bugbountytips #IDOR #AppSec #InfoSec

mrdesoky0's tweet image. Just released the Ultimate IDOR Testing Checklist 🧩

I combined techniques from many sources to cover IDOR scenarios.

Know a technique I missed? Drop it in the comments.

Notion:
mrdesoky0.notion.site/Ultimate-IDOR-…
 
GitHub:
github.com/mrdesoky0/vuln…

#bugbountytips #IDOR #AppSec #InfoSec
mrdesoky0's tweet image. Just released the Ultimate IDOR Testing Checklist 🧩

I combined techniques from many sources to cover IDOR scenarios.

Know a technique I missed? Drop it in the comments.

Notion:
mrdesoky0.notion.site/Ultimate-IDOR-…
 
GitHub:
github.com/mrdesoky0/vuln…

#bugbountytips #IDOR #AppSec #InfoSec
mrdesoky0's tweet image. Just released the Ultimate IDOR Testing Checklist 🧩

I combined techniques from many sources to cover IDOR scenarios.

Know a technique I missed? Drop it in the comments.

Notion:
mrdesoky0.notion.site/Ultimate-IDOR-…
 
GitHub:
github.com/mrdesoky0/vuln…

#bugbountytips #IDOR #AppSec #InfoSec
mrdesoky0's tweet image. Just released the Ultimate IDOR Testing Checklist 🧩

I combined techniques from many sources to cover IDOR scenarios.

Know a technique I missed? Drop it in the comments.

Notion:
mrdesoky0.notion.site/Ultimate-IDOR-…
 
GitHub:
github.com/mrdesoky0/vuln…

#bugbountytips #IDOR #AppSec #InfoSec

then, BAC > low impact now, account take over > CIA = high

never thought one day i will have a CVE :>>> #bugbounty

yoyomiski's tweet image. never thought one day i will have a CVE :>>>

#bugbounty


never thought one day i will have a CVE :>>> #bugbounty

yoyomiski's tweet image. never thought one day i will have a CVE :>>>

#bugbounty

yoyomiski reposted

DUHHHH of course i look for BAC! Top 100 web app exploits listed by how common they are IDOR (object-level auth) Function-level auth bypass Role/privilege escalation Missing admin-endpoint access control Insecure direct file reference Mass assignment HTTP parameter pollution…


yoyomiski reposted

10 bsqli in 15 mins ⏳ and nearly 2 hour to dumb data and confirm 1- i set upped my bsqli payload using nuclei 2- used custom google dorks for params found success with it on the same program 3- gathered all links and run my tempelate on them 4- dumbed the data using ghauri

Rzizah_'s tweet image. 10 bsqli in 15 mins ⏳
and nearly 2 hour to dumb data and confirm
1- i set upped my bsqli payload using nuclei
2- used custom google dorks for params found success with it on the same program
3- gathered all links and run my tempelate on them
4- dumbed the data using ghauri

yoyomiski reposted

Hey bug bounty hunters ! I've reported info disclosure / sensitive data exposure vulns that all got accepted.. Here's what I've learned from digging into these; it's super useful when you're stuck on the main app and need to pivot to recon; when I'm out of ideas on the core app,…


🤦‍♂️

Behind a $XX,XXX bounty, are dozens of N/A, duplicates / informative; let's keep that in mind.



yoyomiski reposted

Bug bounty life tips: - Triage downgrades your report? Ignore it, comments won’t save you. - Company says “aware of this issue”? Skip, no one helps. - CSRF and IDOR = same (in their eyes)? Skip, you’re “wrong.” - They fix your sqli while program suspended? Skip, you lose. Skip..


thanks @Qata for the helpful advice After several rounds of "Need more info", it finally got Triaged The big targets still have room for me :> #BugBounty

yoyomiski's tweet image. thanks @Qata for the helpful advice 
After several rounds of "Need more info", it finally got Triaged 
The big targets still have room for me :>
#BugBounty

yoyomiski reposted

Happy for securing a new program at @Bugcrowd !! ALHAMDULLAH ❤ Writeup: medium.com/@MoSalah11/a-c… #BugBounty #bugbountytips #bugbountytip

0x_MoSalah's tweet image. Happy for securing a new program at @Bugcrowd !!

  ALHAMDULLAH ❤

Writeup: medium.com/@MoSalah11/a-c…

#BugBounty #bugbountytips #bugbountytip

yoyomiski reposted

Anyone can learn Web3 Security for $0! Resources: @CyfrinUpdraft is free @immunefi (Bug Bounty Writeups/Blogs) is free @TheSecureum is free @trailofbits (Blogs/Publications) is free @RektHQ is free @CryptoZombiesHQ is free @OpenZeppelin resources are free @ProgrammerSmart is…


After a long time, hope to be accepted!!!! @Hacker0x01 #BugBounty

yoyomiski's tweet image. After a long time, hope to be accepted!!!! @Hacker0x01 

#BugBounty

yoyomiski reposted

↳ Bug Bounty Resource Guide Topics • SQL Injection …cking-resources-guide-2025.vercel.app/sql-injection • XSS (Cross-Site Scripting) …cking-resources-guide-2025.vercel.app/xss • CSRF (Cross-Site Request Forgery) …cking-resources-guide-2025.vercel.app/csrf • RCE (Remote Code Execution) …cking-resources-guide-2025.vercel.app/rce • LFI (Local File…

HackingTeam777's tweet image. ↳ Bug Bounty Resource Guide

Topics
• SQL Injection
…cking-resources-guide-2025.vercel.app/sql-injection

• XSS (Cross-Site Scripting)
…cking-resources-guide-2025.vercel.app/xss

• CSRF (Cross-Site Request Forgery)
…cking-resources-guide-2025.vercel.app/csrf

• RCE (Remote Code Execution)
…cking-resources-guide-2025.vercel.app/rce

• LFI (Local File…

I was awarded $500 for a report that was closed as 'infomative' @Hacker0x01 > report an IDOR vuln > Couldn't prove 24 character ID enumeration > Report was closed as info > Still received the award #BugBounty

yoyomiski's tweet image. I was awarded $500 for a report that was  closed as 'infomative' @Hacker0x01 
> report an IDOR vuln
> Couldn't prove 24 character ID enumeration
> Report was closed as info
> Still received the award

#BugBounty

yoyomiski reposted

Live Bug Bounty Hunting - My Recon Methodology !!!🐞


yoyomiski reposted

Took a short break, but still managed to bag a few high-severity finds while resting 🤝 #BugBounty #InfoSec #HackerLife #intigriti @intigriti

5hady_'s tweet image. Took a short break, but still managed to bag a few high-severity finds while resting 🤝

#BugBounty #InfoSec #HackerLife #intigriti @intigriti

United States Trends

Loading...

Something went wrong.


Something went wrong.