🇵🇸Ayaa Hamed Profile Banner
🇵🇸Ayaa Hamed Profile
🇵🇸Ayaa Hamed

@AyaaHam82030201

Followers
758
Following
169
Media
17
Statuses
1,328

Security Researcher 🔍|| Bug Hunter 🐞 ||

Egypt
Joined June 2022
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
Pinned Tweet
@AyaaHam82030201
🇵🇸Ayaa Hamed
1 year
💚💚
@0x_rood
🇸🇦 ROOD | GOAT
1 year
نحنُ نستند على الله، حاشانا أنْ نحتاجَ كتفاً
0
3
17
2
0
9
@AyaaHam82030201
🇵🇸Ayaa Hamed
3 months
Finally, after 2 months they validated the bugs and paid 😅🤑
Tweet media one
20
6
277
@AyaaHam82030201
🇵🇸Ayaa Hamed
8 days
Hacking jquery is the Best 🤑❤❤ I submited 14 bug in @Bugcrowd for one program #bugbounty
Tweet media one
20
29
421
@AyaaHam82030201
🇵🇸Ayaa Hamed
9 months
Tip: 1.The business of the program is booking the hotel 2. In the process of the booking the program ask to provide the phone number. 3. Add the number and Intercept the request. #bugbounty #bugbountytips
Tweet media one
8
23
176
@AyaaHam82030201
🇵🇸Ayaa Hamed
3 months
Simple logic flaw lead to P3 bug in public BBP by Muhammad_Mostafa
6
12
131
@AyaaHam82030201
🇵🇸Ayaa Hamed
15 days
You're right😎 it was cool finding❤ #bugbounty
Tweet media one
Tweet media two
3
1
112
@AyaaHam82030201
🇵🇸Ayaa Hamed
3 months
Tip: Always try to bypass workflow mechanism and break the logic of the target 🤑 #bugbounty #bugbountytips
Tweet media one
2
5
95
@AyaaHam82030201
🇵🇸Ayaa Hamed
7 months
Nothing new just understand the application #bugbounty #bugbountytips
Tweet media one
1
3
85
@AyaaHam82030201
🇵🇸Ayaa Hamed
8 months
It's just the beginning 💪💪😁 @Bugcrowd #bugbounty
Tweet media one
5
0
80
@AyaaHam82030201
🇵🇸Ayaa Hamed
6 months
How I found it 👇 👇 1.The special role don't have permissions to view or access the transactions. 2. While I test different endpoint I found request allow me to download the transactions. 3. I try this request with unauthorized user and it worked. #bugbounty #bugbountytips
@AyaaHam82030201
🇵🇸Ayaa Hamed
6 months
Tip : Don't forget Check Download processes #bugbountytips #BugBounty
Tweet media one
3
1
38
1
6
65
@AyaaHam82030201
🇵🇸Ayaa Hamed
7 months
Thanks @EurofinsGroup for the nice swag ❤ #bugbounty
Tweet media one
7
0
66
@AyaaHam82030201
🇵🇸Ayaa Hamed
9 months
The first bounty in 2024 and faster bounty I had .... triaged and rewarded in the same day 😁😅 @Bugcrowd #bugbounty
Tweet media one
@AyaaHam82030201
🇵🇸Ayaa Hamed
9 months
Finally,I finished January with triaged after 5 dup in the same program😌 ... #bugbounty
Tweet media one
0
0
17
4
1
57
@AyaaHam82030201
🇵🇸Ayaa Hamed
1 year
Full account takeover — Bug bounty by Facundo Fernandez
1
13
51
@AyaaHam82030201
🇵🇸Ayaa Hamed
3 months
Tip:Try understand the target and his main goal🤑 Impact: The target focus on manage cards and spend money via workflow. When the attacker can edit workflow he can change the behavior of the company and he can control with all transactions or transmit of money. #bugbountytips
Tweet media one
4
1
52
@AyaaHam82030201
🇵🇸Ayaa Hamed
4 months
3 Easy cash via cache by Muhammad_Mostafa
2
13
46
@AyaaHam82030201
🇵🇸Ayaa Hamed
7 months
Tweet media one
1
0
46
@AyaaHam82030201
🇵🇸Ayaa Hamed
6 months
Tip : Don't forget Check Download processes #bugbountytips #BugBounty
Tweet media one
3
1
38
@AyaaHam82030201
🇵🇸Ayaa Hamed
8 days
@0x_rood @Bugcrowd Just understand GraphQL and dig deep in the apps. Some of these endpionts wasn't direct idor so, understand the app is important.
1
2
30
@AyaaHam82030201
🇵🇸Ayaa Hamed
9 months
Finally,I finished January with triaged after 5 dup in the same program😌 ... #bugbounty
Tweet media one
0
0
17
@AyaaHam82030201
🇵🇸Ayaa Hamed
7 months
Bypassing 2FA Authentication (0day) in TeamPass 3.0.10 System by @FaghaniSam24568
0
5
15
@AyaaHam82030201
🇵🇸Ayaa Hamed
9 months
6. We not finished >> change the body of the request and send it. 7. All information added successfully and we can add alot of the important info to any user account.
1
0
11
@AyaaHam82030201
🇵🇸Ayaa Hamed
9 months
The Achievements of the January 2024 in @Bugcrowd 2 P1 submissions is dup 😔 #bugbounty
Tweet media one
1
0
10
@AyaaHam82030201
🇵🇸Ayaa Hamed
1 year
Securing Data: How I Quickly Accessed 3000 Student Records in under 5 Minutes by Facundo Fernandez
0
2
6
@AyaaHam82030201
🇵🇸Ayaa Hamed
4 months
Abusing Business Logic of an Application to create backdoor in a form APP
0
1
4
@AyaaHam82030201
🇵🇸Ayaa Hamed
9 months
4. Change the user id to victim id (easy get victim id), then send the request. 5. Boom the number changed successfully and can see the victim info.
1
0
4
@AyaaHam82030201
🇵🇸Ayaa Hamed
10 months
How I Earned My First Bug Bounty Reward of $600 by @zikolaasec
0
3
3
@AyaaHam82030201
🇵🇸Ayaa Hamed
6 months
@Proxy936623 The special role don't have permissions to view or access the transactions. But While I test different endpoint I found request allow me to download the transactions. So, I try this request with unauthorized user and it worked.
0
0
3
@AyaaHam82030201
🇵🇸Ayaa Hamed
3 months
@MrxXb12 What happened with me was not direct access control, if you found the endpoint with any way you say not benefit as it was not direct access control and this is the importance of understand the app and try to tie all features with other. If I have time ,I will write writeup.
0
0
2
@AyaaHam82030201
🇵🇸Ayaa Hamed
1 year
Imazing Write up
@a13h1_
Abhi Sharma 𝕏
1 year
Check out :- ATO bug in twitter
0
0
8
0
1
2
@AyaaHam82030201
🇵🇸Ayaa Hamed
3 months
@MiniMjStar Access control and privilege escalation
1
0
2
@AyaaHam82030201
🇵🇸Ayaa Hamed
7 months
@yasmeena_rezk @EurofinsGroup اللهم آمين و اياكى ❤❤
0
0
1
@AyaaHam82030201
🇵🇸Ayaa Hamed
9 months
@GodfatherOrwa Thanks 🙏
0
0
2
@AyaaHam82030201
🇵🇸Ayaa Hamed
9 months
Business Logic Errors - A Logic Destruction by @JerrySh43332033
0
1
2
@AyaaHam82030201
🇵🇸Ayaa Hamed
1 year
Web Cache Deception Attack by @omer_gil
0
0
2
@AyaaHam82030201
🇵🇸Ayaa Hamed
3 months
@Ma7m0udJamal شهر تقريبا
0
0
2
@AyaaHam82030201
🇵🇸Ayaa Hamed
2 months
1
0
2
@AyaaHam82030201
🇵🇸Ayaa Hamed
9 months
@Sp3cia1m4n because It is used to add a lot important info to any user not only alternative email.
0
0
1
@AyaaHam82030201
🇵🇸Ayaa Hamed
9 months
@awaisaskanii The main body of the request contain only the number phone parameter , but I added more parameters as email , passport info and more important parameters.
1
0
1
@AyaaHam82030201
🇵🇸Ayaa Hamed
7 months
@yasmeena_rezk بارك الله فيك ❤
0
0
0
@AyaaHam82030201
🇵🇸Ayaa Hamed
9 months
0
0
1
@AyaaHam82030201
🇵🇸Ayaa Hamed
9 months
@Sp3cia1m4n Good question! But this alternative email is used to send the trip info > it is not used in login.
1
0
1
@AyaaHam82030201
🇵🇸Ayaa Hamed
3 months
@M7moud_mk99 بارك الله فيك
0
0
1
@AyaaHam82030201
🇵🇸Ayaa Hamed
6 months
0
0
1
@AyaaHam82030201
🇵🇸Ayaa Hamed
7 months
@Praveen73720670 @EurofinsGroup They have program on hackerone
0
0
1
@AyaaHam82030201
🇵🇸Ayaa Hamed
6 months
Decide Israel's Expulsion from the Paris 2024 Olympic Games - Sign the Petition! عبر @Change
0
0
1
@AyaaHam82030201
🇵🇸Ayaa Hamed
6 months
@yasmeena_rezk بارك الله فيكى❤
0
0
0
@AyaaHam82030201
🇵🇸Ayaa Hamed
4 months
@addydaddymc it's not my write-up .. the profile of the person who wrote it
0
0
1
@AyaaHam82030201
🇵🇸Ayaa Hamed
3 months
@DONPAULOSKII Search in Google
0
0
1
@AyaaHam82030201
🇵🇸Ayaa Hamed
4 months
@yasmeena_rezk مبارك ياسمين ❤❤
1
0
0
@AyaaHam82030201
🇵🇸Ayaa Hamed
1 year
الله أكبر الله أكبر ولله الحمد 🇵🇸🇵🇸💪🇵🇸💪🇵🇸
@Alsharway
الشعراوي.
1 year
نختم اليوم بهذا الجمال 🤍🤍🤍🤍🤍🤍🤍🤍🤍🤍🤍🤍🤍🤍
124
1K
11K
0
0
1
@AyaaHam82030201
🇵🇸Ayaa Hamed
9 months
1
0
1
@AyaaHam82030201
🇵🇸Ayaa Hamed
1 month
@yasmeena_rezk رائع 👏well done! go on👏
1
0
0
@AyaaHam82030201
🇵🇸Ayaa Hamed
3 months
0
0
1
@AyaaHam82030201
🇵🇸Ayaa Hamed
2 years
@Ali45598547 What is the impact ?? And what is the name of this
1
0
1
@AyaaHam82030201
🇵🇸Ayaa Hamed
3 months
@M7moud_mk99 @HackenProof Congratulation 👏👏
1
0
1
@AyaaHam82030201
🇵🇸Ayaa Hamed
3 months
@vxprz7 💥🙏
0
0
1
@AyaaHam82030201
🇵🇸Ayaa Hamed
3 months
@nader_3bnaser بارك الله فيك 🙏
0
0
1
@AyaaHam82030201
🇵🇸Ayaa Hamed
3 months
0
0
1
@AyaaHam82030201
🇵🇸Ayaa Hamed
7 months
1
0
1
@AyaaHam82030201
🇵🇸Ayaa Hamed
3 months
0
0
1
@AyaaHam82030201
🇵🇸Ayaa Hamed
1 year
0
0
1
@AyaaHam82030201
🇵🇸Ayaa Hamed
3 months
0
0
1
@AyaaHam82030201
🇵🇸Ayaa Hamed
9 months
@M7moud_mk99 @Hacker0x01 Congratulations 🎉🎉
1
0
1