zomasec's profile picture. Bug Hunter | Offensive Security Engineer @DeepStrike_io

Hazem El-Sayed ๐Ÿ‡ต๐Ÿ‡ธ

@zomasec

Bug Hunter | Offensive Security Engineer @DeepStrike_io

Fissato

Here is a write-up for how I got a Full Account takeover with a new hidden AWS Cognito Misconfiguration. Here is the link: shorturl.at/b5VbS #BugBounty #bugbountytips #bugbountytips

zomasec's tweet image. Here is a write-up for how I got a Full Account takeover with a new hidden AWS Cognito Misconfiguration.
Here is the link: shorturl.at/b5VbS

#BugBounty #bugbountytips #bugbountytips

Repost di Hazem El-Sayed ๐Ÿ‡ต๐Ÿ‡ธ

Sometimes when I work with teammates across multiple programs, Android app bug hunting becomes tedious and wastes time that could be spent finding web bugs. I built **apkX** to automate the repetitive startup steps, give a quick preview of an appโ€™s internals, and let you testโ€ฆ


Repost di Hazem El-Sayed ๐Ÿ‡ต๐Ÿ‡ธ

๐ŸŽ™๏ธ Hunter Cust #3 โ€“ Hazem El-Sayed (zomasec) ุฑุญู„ุชู‡ ููŠ ุงู„ุณูŠูƒูŠูˆุฑุชูŠุŒ ูˆู†ุตุงูŠุญ ู…ู‡ู…ุฉ ู„ุฃูˆู„ ุดุบู„ ููŠ ู…ุฌุงู„ ุงู„ู€ Pentesting ๐Ÿ‘จโ€๐Ÿ’ป ูƒู„ุงู… ูˆุงู‚ุนูŠุŒ ู…ุตุงุฏุฑ ู‚ูˆูŠุฉุŒ ูˆุชุณูˆูŠู‚ ู„ู†ูุณูƒ ููŠ ุงู„ุณูˆู‚ ุงู„ู…ุตุฑูŠ ๐Ÿ‡ช๐Ÿ‡ฌ ๐Ÿ“บ ุดุงู‡ุฏ ุงู„ุญู„ู‚ุฉ: ๐Ÿ”— youtu.be/Zyrez7QfxBQ ๐Ÿ“Œ ุดูƒุฑุงู‹ โจ@zomasecโฉ ุนู„ู‰ ุงู„ุญูˆุงุฑ ุงู„ุฑุงูŠู‚ ูˆุงู„ู…ููŠุฏ โค๏ธ #BugBounty

SalhiMahdi72759's tweet card. Hunter Cust #3 โ€“ Hazem El-Sayed: Tips to Get Your First Job in...

youtube.com

YouTube

Hunter Cust #3 โ€“ Hazem El-Sayed: Tips to Get Your First Job in...


I hope some one find this usefull ๐Ÿ˜

Want to master client-side bugs? ๐Ÿ˜Ž Check out this extensive GitHub repository with tens of different resources curated by @zomasec! ๐Ÿ”— github.com/zomasec/clientโ€ฆ

intigriti's tweet image. Want to master client-side bugs? ๐Ÿ˜Ž

Check out this extensive GitHub repository with tens of different resources curated by @zomasec!

๐Ÿ”— github.com/zomasec/clientโ€ฆ


Repost di Hazem El-Sayed ๐Ÿ‡ต๐Ÿ‡ธ

Use NextJS? Recon Tip by renniepak A quick way to find "all" paths for Next.js websites: DevTools->Console console.log(__BUILD_MANIFEST.sortedPages) javascriptโ€‹:console.log(__BUILD_MANIFEST.sortedPages.join('\n')); #infosec #cybersec #bugbountytips

0x0SojalSec's tweet image. Use NextJS? Recon Tip by renniepak

A quick way to find "all" paths for Next.js websites:
DevTools->Console

console.log(__BUILD_MANIFEST.sortedPages)

javascriptโ€‹:console.log(__BUILD_MANIFEST.sortedPages.join('\n'));

#infosec #cybersec #bugbountytips

With @Amr_MustafaAA we got this awesome bug 3> GET /api/nonsensitive/123%23non.svg The endpoint initially didnโ€™t return sensitive data, but after being cached, it started exposing user PII. found on @yeswehack #BugBounty #bugbountytip #bugbountytips #Pentesting #websecurity

zomasec's tweet image. With @Amr_MustafaAA  we got this awesome bug 3>

GET /api/nonsensitive/123%23non.svg

The endpoint initially didnโ€™t return sensitive data, but after being cached, it started exposing user PII.

found on @yeswehack 

#BugBounty #bugbountytip #bugbountytips #Pentesting #websecurity

ู†ูุงู‚ ูˆุงุถุญ

ุงู„ุฏูˆู„ "ุงู„ุนู„ู…ุงู†ูŠุฉ" ุงู„ุฃูˆุฑูˆุจูŠุฉ ุนุงุฏูŠ ุชุญุท ุงู„ุตู„ูŠุจ ุนู„ู‰ ุนู„ู… ุฏูˆู„ู‡ุง ุฃู…ุง ููŠ ุจู„ุฏ ู†ุณุจุฉ ุงู„ู…ุณู„ู…ูŠู† ููŠู‡ 90 ุจุงู„ู…ุฆุฉ ูˆูƒุงู† ุงู„ุฏูŠู† ุณุจุจ ููŠ ุชุญุฑูŠุฑู‡ู… ูˆูŠุถุนูˆุง ูƒู„ู…ุฉ ุงู„ุชูˆุญูŠุฏ ุจุฌู†ุจ ุนู„ู…ู‡ู…ุŒ ูู‡ุฐุง ุทุงุฆููŠุฉ ูˆุงู„ุนูŠุงุฐ ุจุงู„ู„ู‡ ุบุฑุฏ ูƒุฃู†ูƒ ุนู„ู…ู†ุฌูŠ

MoMegdadi's tweet image. ุงู„ุฏูˆู„ "ุงู„ุนู„ู…ุงู†ูŠุฉ" ุงู„ุฃูˆุฑูˆุจูŠุฉ ุนุงุฏูŠ ุชุญุท ุงู„ุตู„ูŠุจ ุนู„ู‰ ุนู„ู… ุฏูˆู„ู‡ุง 
ุฃู…ุง ููŠ ุจู„ุฏ ู†ุณุจุฉ ุงู„ู…ุณู„ู…ูŠู† ููŠู‡ 90 ุจุงู„ู…ุฆุฉ ูˆูƒุงู† ุงู„ุฏูŠู† ุณุจุจ ููŠ ุชุญุฑูŠุฑู‡ู… ูˆูŠุถุนูˆุง ูƒู„ู…ุฉ ุงู„ุชูˆุญูŠุฏ ุจุฌู†ุจ ุนู„ู…ู‡ู…ุŒ ูู‡ุฐุง ุทุงุฆููŠุฉ ูˆุงู„ุนูŠุงุฐ ุจุงู„ู„ู‡ 
ุบุฑุฏ ูƒุฃู†ูƒ ุนู„ู…ู†ุฌูŠ


see our changes here

Tools Updates: - ffuf: -unique filters unique responses by size.- - Subfalcon: Single-domain input, -sdt for Azure takeover. - Paramx: -at for all tags, -ap for all params(no need for gf any more). Tools Here: github.com/cyinnove Happy Automation! #CyberSecurity #Automation



Repost di Hazem El-Sayed ๐Ÿ‡ต๐Ÿ‡ธ

If you're scratching your head after the @matanber episodes, here's a demo to show you how to: - Enable developer mode - Download extension's crx file Debugging: - Enable "Search in anonymous and content scripts" - Disable Ignore List "Content scripts injected by extensions"


Repost di Hazem El-Sayed ๐Ÿ‡ต๐Ÿ‡ธ

To succeed in bug bounty, be a specialist feat. @snyff #bugbounty #bugbountytips #bugbountyhunter


Repost di Hazem El-Sayed ๐Ÿ‡ต๐Ÿ‡ธ

I recently reported an RCE to Happy-DOM (a Node.js HTML parser), and itโ€™s now fixed! The bug itself wasn't complex, but since finding an RCE in an HTML parser isnโ€™t very common, I'm quite happy with this one :D github.com/capricorn86/haโ€ฆ

kevin_mizu's tweet image. I recently reported an RCE to Happy-DOM (a Node.js HTML parser), and itโ€™s now fixed!

The bug itself wasn't complex, but since finding an RCE in an HTML parser isnโ€™t very common, I'm quite happy with this one :D

github.com/capricorn86/haโ€ฆ
kevin_mizu's tweet image. I recently reported an RCE to Happy-DOM (a Node.js HTML parser), and itโ€™s now fixed!

The bug itself wasn't complex, but since finding an RCE in an HTML parser isnโ€™t very common, I'm quite happy with this one :D

github.com/capricorn86/haโ€ฆ

Repost di Hazem El-Sayed ๐Ÿ‡ต๐Ÿ‡ธ

CSRF in JSON requests is often overlooked, but it's a hidden threat! In my latest post, I break down how to spot JSON-based CSRF before generating a PoC. ๐Ÿ” Check out how I caught it in a pentest at @CyberAR_LLC: #bugbountytips #csrf linkedin.com/posts/h0tak88rโ€ฆ


Repost di Hazem El-Sayed ๐Ÿ‡ต๐Ÿ‡ธ

ุนู†ุฏู…ุง ุดุงู‡ุฏุช ู‡ุฐุง ุงู„ููŠุฏูŠูˆ ู…ู† ุงู†ุชุตุงุฑุงุช ุงู„ูŠูˆู… ููŠ ุงู„ุณูˆุฏุงู† ูˆุฑุฃูŠุช ู‡ุฐู‡ ุงู„ูˆุฌูˆู‡ ุงู„ุทูŠุจุฉ ูˆููŠู‡ุง ุงู„ุฏูŠู† ูˆุงู„ุฎู„ู‚ ู„ุฃุจุทุงู„ ุงู„ู‚ูˆุงุช ุงู„ู…ุณู„ุญุฉ ุงู„ุณูˆุฏุงู†ูŠุฉุŒ ุชุฐูƒุฑุช ุจุฏุงูŠุฉ ุญุฑุจ #ุงู„ุณูˆุฏุงู† ุญูŠู† ู‚ุงู„ุช #ุงู„ุงู…ุงุฑุงุช ู†ุญู† ู†ุฏุนู… ูˆู†ู‚ู ู…ุน ู…ู„ูŠุดูŠุงุช ุงู„ุฏุนู… ุงู„ุณุฑูŠุน ู„ู„ู‚ุถุงุก ุนู„ู‰ ุงู„ุฅุณู„ุงู…ูŠูŠู†ุŸ! ุญู‚ูŠู‚ุฉ ุงู„ุฅู…ุงุฑุงุช ุชุฑูŠุฏ ูˆุฌูˆู‡ ุงู„ุนุฑุจุฏุฉ ูˆุงู„ูุณุงุฏ


Hello everyone , i coded a new golang package for bughunters who want to use webarchive in their tools , i am the first one that do this package in golang community with full documentation github.com/zomasec/webarcโ€ฆ #BugBounty #bugbountytip #bugbountytips #golang #tools


Loading...

Something went wrong.


Something went wrong.