@silentgh00st Profile picture

Mehdi

@silentgh00st

🚀 Cofounder @ Bleetz - Future Digital Payment Solution 🥷Cyber Security Engineer 🔴 Synack Red Team Member 💻 Node.js enthusiast ... --------------- OSCP-CRTO

Similar User
🇪🇨🍫 photo

@bxmbn

Godfather Orwa 🇯🇴 photo

@GodfatherOrwa

encodedguy - jsmon.sh photo

@3nc0d3dGuY

Rahmat Qurishi photo

@RahmatQurishi

Imamul Mursalin photo

@0x0_root

ReconOne photo

@ReconOne_bk

Hammad 🇵🇰🇵🇸 photo

@Hammad7361

Sina Yeganeh photo

@Sin4Yeganeh

Mike Takahashi photo

@TakSec

Jefferson Gonzales photo

@gonzxph

Sirat Sami (analyz3r) photo

@siratsami71

Deepak bug_vs_me photo

@bug_vs_me

Lu3ky13 ⚡️⚡️ photo

@lu3ky13

Anton photo

@therceman

Faiyaz Ahmad photo

@FaIyaZz007

Pinned

Here is short writeup on how I managed to access 200k+ of PII data by exploiting a simple vulnerability and accessing admin dashboard! 📌Thread📌 1. I created an account with a simple user and one endpoint caught my attention (it was /api/v1/session)

Tweet Image 1
Tweet Image 2

Hey @GoogleVRP @google ❌️🆘️🚨 Someone is exploiting your SMTP servers or maybe some vulnerabilites in the mailing functions, and sending random phishing emails from : mailer-daemon@googlemail.com the Mail Delivery Subsystem.. I have received 3 of them so far with a facebook…

Tweet Image 1
Tweet Image 2
Tweet Image 3
Tweet Image 4

Mehdi Reposted

Thrilled to release my latest research on Apache HTTP Server, revealing several architectural issues! blog.orange.tw/2024/08/confus… Highlights include: ⚡ Escaping from DocumentRoot to System Root ⚡ Bypassing built-in ACL/Auth with just a '?' ⚡ Turning XSS into RCE with legacy code…


Mehdi Reposted

I just Published - A Comprehensive Guide to Manually Hunting SQL Injection in MSSQL, MySQL, Oracle, and NoSQL (MongoDB) - nav1n0x.gitbook.io/a-guide-to-man… I tried to explain everything I could. Let me know your opinion and suggestions, if any. I will keep updating the article whenever I…

Tweet Image 1

Mehdi Reposted

Had an awesome time on the pod last week talking full-time bug bounties with @joaxcar Johan recently decided to take 3-months unpaid leave to try bug bounty hunting full-time. Here's his 10 step roadmap.

Tweet Image 1

#bugbountytips Tip of the day: The frontend JS codes are not revealing all backend endpoints. Sometimes backend have many other hidden endpoints that were created for internal testings.. and are not even used in the main app. What to do? : FUZZ for endpoints with GET/POST...


Mehdi Reposted

Hi everyone! Here it's my write-up for a postMessage vuln I found in a BBP: - why postMessage() and how can lead to a vuln. - when is jQuery really vulnerable and exploitable. - chain this issue with CORS to get a 5X bounty. medium.com/p/ec8f709f6dc4 #bugbountytips #xss #domxss


Mehdi Reposted

The story of fresh water 📹 The Water Rooms twitter.com/Earthlings10m/…


#bugbountytip If you want to scan for hosted web apps in cloud providers like (Azure, AWS...), You can use @securitytrails subdomains search feature under the main domain of 'Azurewebsites[.]net or amazonaws[.]com or whatever cloud provider .. #Recon - #bugbounty

Tweet Image 1

Loading...

Something went wrong.


Something went wrong.