Hazem Profile Banner
Hazem Profile
Hazem

@H4cktus

Followers
2,987
Following
292
Media
158
Statuses
1,118

Lead Offensive Security Engineer @cyrextech | PT bug hunter

Joined January 2017
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
@H4cktus
Hazem
9 months
As 2023 comes to a close, I'm thrilled to share my milestones for the year: - Surpassed 100k in bounties on @Hacker0x01 , with over 100k earned solely in 2023. - Reached 4.5k reputation, gaining 3200 of it in just the last few months of the year. - Ranked second in the Turkish
Tweet media one
32
12
287
@H4cktus
Hazem
1 year
Yay, I was awarded a $15,000 bounty on @Hacker0x01 ! #TogetherWeHitHarder I don't usually tweet such things but that's a new milestone for me :) last week I focused on a single program for 2 days and ended up with 4x critical, 1x high, and 1x medium.
28
12
277
@H4cktus
Hazem
8 months
Believe it or not, this laptop from 2013 is the reason I am where I am today, and I will always be grateful for it haha Despite its really poor condition, I'm amazed it still functions! I discovered my first bug around 2018 using that laptop and it was also the device I used
Tweet media one
Tweet media two
Tweet media three
8
9
237
@H4cktus
Hazem
1 year
In August, I earned approximately $50,000 on @Hacker0x01 , and can finally say that I'm 1 report away from crossing the 3k reputation. Here are the details: 📨 Total Reports: 24 ✅ Validated: 22 ⚠️ Severity: 2L / 2M/ 8H / 12C 💰 Bounties: $50,830
29
9
197
@H4cktus
Hazem
1 year
CSRFs are dead? Well, I don't think so 😄 @emre_selim8 and I were awarded $3000 for exploiting a CSRF vulnerability that compromised an entire organization on @Hacker0x01 . Happy hacking, everyone :)
Tweet media one
12
9
197
@H4cktus
Hazem
5 months
We hacked @Hacker0x01 's Hai back in Feb with @rez0__ , Well definitely disclose it once they fix it ;)
Tweet media one
8
5
185
@H4cktus
Hazem
1 month
What an event! Thrilled to have received the Eliminator award for scoring the best bug on a specific skill set from @EpicGames ! A huge thanks to @Hacker0x01 for hosting this event. I hope to attend in person next time and meet this amazing community ❤️ #h1702
Tweet media one
30
3
170
@H4cktus
Hazem
2 years
Yay, I was awarded a $3,000 bounty on @Hacker0x01 ! out of scope subdomain takeover to full account takeover. when you come across a bug don't hurry up and report it, chain it 🙂 #TogetherWeHitHarder #bugbountytips
9
4
153
@H4cktus
Hazem
3 years
Tweet media one
16
6
149
@H4cktus
Hazem
27 days
Just got invited to #h10131 @Hacker0x01 ! See you all in Scotland 🏴󠁧󠁢󠁳󠁣󠁴󠁿🫡
Tweet media one
7
0
139
@H4cktus
Hazem
4 months
I started to love programs who offer retesting @Hacker0x01 👀
Tweet media one
4
0
135
@H4cktus
Hazem
3 years
Tweet media one
3
22
132
@H4cktus
Hazem
10 months
🧵 1/9 I'm often asked about my initial steps in game hacking engagements, whether for penetration testing or bug bounty hunting. My answer surprises some: "Tutorial." That's right. Let's dive into why this is the go-to for me. #BugBounty #PenTesting #GameHacking #bugbountytips
Tweet media one
5
25
131
@H4cktus
Hazem
2 years
in 2 mins @Hacker0x01 just literally sent me over 40 invitations lol
Tweet media one
11
1
121
@H4cktus
Hazem
6 months
5k reputation has been achieved @Hacker0x01 !
Tweet media one
10
1
117
@H4cktus
Hazem
1 month
First LHE , first Show and Tell ! 🤠 #h1702 @Hacker0x01
Tweet media one
11
1
113
@H4cktus
Hazem
11 months
🧵 A Thread on VDPs & Beginning in #BugBounty :
Tweet media one
4
16
111
@H4cktus
Hazem
10 months
I've just hit a new milestone with a 4K reputation on @Hacker0x01 ! Astonishingly, nearly 3K of that has been earned in the past few months of 2023 alone, surpassing all my expectations. Time for 5k!
Tweet media one
8
1
110
@H4cktus
Hazem
3 months
First LHE here we go! Unfortunately the invitation came late and won't be able to make visa on time so I will have to attend it virtually, was gonna be really fun seeing you all! #H1702
Tweet media one
4
0
107
@H4cktus
Hazem
1 year
I guess I work for @Hacker0x01 now
Tweet media one
13
1
107
@H4cktus
Hazem
6 months
She is back with another one 👀 , I must say, this is so creative 😄
Tweet media one
@H4cktus
Hazem
2 years
My non geek gf decided to surprise me in my birthday , well , I’m speechless that she came up with these ideas especially for the cactus hoodie and the hacktus shirt 😅
Tweet media one
8
1
69
12
0
94
@H4cktus
Hazem
10 months
🎃 Unveiling the Arcane Art of Intercepting HTTPS Traffic in Desktop Apps & Games! NOTE: This journey is fraught with challenges like SSL pinning - a hurdle I'll tackle in my next tweet. For now, let's master the basics. ⏪ Quick Recap: In my last thread, we explored bugs in
Tweet media one
5
14
91
@H4cktus
Hazem
10 months
🔓 Mastering the Enigma of SSL Pinning Bypass for Desktop Apps & Games 🕹️ 🔄 A Brief Recap: We've scaled the lower slopes—setting up proxies and redirecting traffic with finesse. Yet, SSL pinning stands as the daunting gatekeeper. It's our mission to deftly pick this lock,
Tweet media one
1
14
89
@H4cktus
Hazem
4 months
It's raining bounties adjustments in @Hacker0x01 's hacktivity page rn What a lucky day to wake up on 5-10k bounty out of no where 👀
Tweet media one
4
2
82
@H4cktus
Hazem
9 months
Achieved a 12-month streak on @Hacker0x01 ! This year was incredibly challenging as I juggled a full-time job, university studies, and consistent participation in bug bounty. I guess I will take a long break lol
Tweet media one
5
0
74
@H4cktus
Hazem
2 years
My non geek gf decided to surprise me in my birthday , well , I’m speechless that she came up with these ideas especially for the cactus hoodie and the hacktus shirt 😅
Tweet media one
8
1
69
@H4cktus
Hazem
11 days
Unfortunately, my UK visa was rejected, so I’ll be attending this LHE virtually—again! :') Looks like no in-person LHEs for me this year, haha. Would have loved to meet you all there!
@H4cktus
Hazem
27 days
Just got invited to #h10131 @Hacker0x01 ! See you all in Scotland 🏴󠁧󠁢󠁳󠁣󠁴󠁿🫡
Tweet media one
7
0
139
8
0
70
@H4cktus
Hazem
10 months
🎮 Diving Back into Games-related Bugs! 1. Daily Rewards? 🗓️ Although we talked about it last time, this specific one can have a lot of attack vectors. Ever wondered if you could trick a game into giving you daily rewards early? Turns out, you often can. It's as simple as
Tweet media one
2
7
66
@H4cktus
Hazem
6 months
I believe this was one of my first AI-related engagements on @Hacker0x01 with Snapchat's new txt2img and img2img models back in 2023. It was a really fun engagement; I never imagined a day where I would be getting paid to make some weird AI prompts 😝.
Tweet media one
7
0
63
@H4cktus
Hazem
10 months
@Jayesh25_ Nice one @Jayesh25_ ! Bombon has some pretty good blogs about these kinds of bugs here if anyone is interested.
3
9
55
@H4cktus
Hazem
6 months
Hacktivity page on @Hacker0x01 got another update where it shows if the report was a collaboration or not 👀
Tweet media one
2
0
54
@H4cktus
Hazem
1 year
This year is flying by, and in the few months that I worked as a BH part-time, I managed to accomplish a lot more than I had in the previous year. I'm excited to join the 2k club on @Hacker0x01 :)
Tweet media one
@H4cktus
Hazem
2 years
My 2022 #BugBounty report card: - Did bug hunting for 3 months\ - passed 1200 rep with over 22 impact and 7 signal - Made ±20k from 3 programs. - Joined @cyrextech as a penetration tester - Got accepted in Synack #bugbountytips
1
0
49
2
3
52
@H4cktus
Hazem
7 months
Diving Back into Games-related Bugs! , especially, cards related games!🕹️💻 it's been a while since I tweeted about these kind of flaws, so here we are adding 3 more common bugs I see in games into the list ;) In the landscape of online games, particularly those involving cards
Tweet media one
3
6
52
@H4cktus
Hazem
2 months
In June, I submitted 34 vulnerabilities to 8 programs on @Hacker0x01 . #TogetherWeHitHarder
1
0
51
@H4cktus
Hazem
5 months
that's new 👀 @Hacker0x01
Tweet media one
2
0
50
@H4cktus
Hazem
2 years
My 2022 #BugBounty report card: - Did bug hunting for 3 months\ - passed 1200 rep with over 22 impact and 7 signal - Made ±20k from 3 programs. - Joined @cyrextech as a penetration tester - Got accepted in Synack #bugbountytips
1
0
49
@H4cktus
Hazem
1 year
I'm finally Clear Verified @Hacker0x01 ! It took that long due to an error occurred in h1 email logs but finally, it got sorted out. I'd like to thank @Arl_rose for helping me out on this matter.
Tweet media one
6
0
47
@H4cktus
Hazem
10 months
Got some great feedback from a @Hacker0x01 private program! Such comments have the same motivation feeling as getting a bounty for me 😄
Tweet media one
3
0
46
@H4cktus
Hazem
4 months
In April, I submitted 29 vulnerabilities to 3 programs on @Hacker0x01 . #TogetherWeHitHarder
2
0
43
@H4cktus
Hazem
1 year
In August, I submitted 24 vulnerabilities to 1 program on @Hacker0x01 . #TogetherWeHitHarder
4
0
37
@H4cktus
Hazem
2 years
Everytime I get this notification I get excited thinking that one of my bugs got paid 🙃 @Hacker0x01
Tweet media one
5
0
36
@H4cktus
Hazem
5 months
More of Games-related Bugs! If you prefer to read with markdown enabled, I got you ;) Exploring Chests or Boxes: Unraveling the Secrets 🎲 In the digital realm of gaming, chests and boxes are akin to Pandora's Box, each unveiling unique rewards and
0
4
38
@H4cktus
Hazem
1 year
What a quarter! However, with uni starting tomorrow you will not see me again till the end of this year 🥲 @alicanact60
Tweet media one
5
0
38
@H4cktus
Hazem
1 year
Thanks for the new update :P - @Hacker0x01 @jobertabma I was duplicated of a report that was submitted after me and just noticed it thanks to the new update.
Tweet media one
2
1
37
@H4cktus
Hazem
1 year
In March, I submitted 25 vulnerabilities to 5 programs on @Hacker0x01 . #TogetherWeHitHarder
1
1
36
@H4cktus
Hazem
2 years
when you think that you picked a nice fresh program and then they hit you with duplicates only. #bugbountytips #infosec #bugbounty #bugbountytip
Tweet media one
1
0
35
@H4cktus
Hazem
1 year
This is the first time I rank first on the Turkish leaderboard for this quarter @Hacker0x01 , which I have to say, pretty competitive leaderboard it is thanks to people like @alicanact60 and @P3ntestoR 😅 Hope it will last till the end of the quarter !
Tweet media one
7
0
34
@H4cktus
Hazem
1 year
I'm closer to dropping out of uni than dropping a 0 day
4
1
32
@H4cktus
Hazem
1 year
My first in person Live Hacking Event gonna be #1337UP1023 ! Thanks @intigriti , @IntelSecurity for the invitation. See you all in Lisbon 🇵🇹 “ if my visa process went smoothly lol “
3
1
29
@H4cktus
Hazem
5 months
Tweet media one
4
0
29
@H4cktus
Hazem
1 year
When I decide to work with a new target, I tend to send in just one report to begin with. I like to see how they manage their program first. If I like what I see, then I'm all in and put all my time into that program.
Tweet media one
2
0
27
@H4cktus
Hazem
11 months
DALL·E 3 magic! 🎨 I used it to visualize my blog post at . Where I made it look like a bug climbing out of a subdomain as if it's taking it over and dropping ASP cookies on my keyboard as if it's sharing it.
Tweet media one
0
2
26
@H4cktus
Hazem
1 year
I won’t be removed from all of these programs if i were banned from h1 lol , I hope @Hacker0x01 will be able to fix this clear issue soon enough.
Tweet media one
3
0
26
@H4cktus
Hazem
1 year
Lmao was it necessary to create such POC? it was obv that you had a bug no need to prove it in such way
@disclosedh1
publiclyDisclosed
1 year
HackerOne disclosed a bug submitted by @0xRAYAN7 : - Bounty: $7,500 #hackerone #bugbounty
Tweet media one
1
17
151
4
0
24
@H4cktus
Hazem
4 months
@alicanact60 @oz9un AC:H as the attack requires the hacker to have at least 1 laptop which is hard to get with this current economy.
2
1
25
@H4cktus
Hazem
8 months
I would really love to thank @Lenovo that even with this condition the laptop still work and the screen isn’t burned lol, i’m amazed considering this laptop age haha
0
0
24
@H4cktus
Hazem
1 month
In July, I submitted 30 vulnerabilities to 5 programs on @Hacker0x01 . #TogetherWeHitHarder
1
0
24
@H4cktus
Hazem
2 years
I love such comments, when the program appreciates the amount of time and effort you had to make to come up with such a report :) - feels better than bounties lol
Tweet media one
0
0
23
@H4cktus
Hazem
1 year
Invited to a program where is the only scoped asset, and it redirects to for operations, would you test or consider it out of scope? keep in mind that is just a static page #BugBounty
6
0
21
@H4cktus
Hazem
2 years
unpopular opinion: @Hacker0x01 should stop removing programs from researchers' thanks page if the researcher left the program or the program got closed
2
0
20
@H4cktus
Hazem
2 years
if anyone needs me I'll be in the Virgin Island with my homie @equat0rium
Tweet media one
2
0
18
@H4cktus
Hazem
5 months
In March, I submitted 28 vulnerabilities to 4 programs on @Hacker0x01 . #TogetherWeHitHarder
1
0
20
@H4cktus
Hazem
9 months
In November, I submitted 18 vulnerabilities to 2 programs on @Hacker0x01 . #TogetherWeHitHarder
1
0
20
@H4cktus
Hazem
3 years
Why don't I shut my mouth up already xD @ArmanTess @Hacker0x01
Tweet media one
4
0
19
@H4cktus
Hazem
1 year
@securinti I got 200-300$ " I don't remember " for an admin panel bypass that affects the in scope org, and was told that it was found via an OOS asset and they are being " generous " for offering a bounty for that.
2
1
18
@H4cktus
Hazem
10 months
@Jayesh25_ I’m thinking it’s time for Jayesh to do a shift career from a bug hunter to an influencer already.
2
0
18
@H4cktus
Hazem
2 years
Blind XSSs spammers these days became almost like @SaveToNotion #BugBounty
5
2
16
@H4cktus
Hazem
2 years
Does @instagram have an actual support team instead of these stupid bots they keep forwarding me to ? After 10 years of using their platform they disabled my account for no reason lol
20
0
6
@H4cktus
Hazem
5 months
@pxmme1337 my new way while asking for updates
Tweet media one
3
0
16
@H4cktus
Hazem
11 months
@Hacker0x01 @Jayesh25_ @X @Jayesh25_ is one of the most talented and humble hackers I've ever worked with, besides this huge milestone he is about to hit the top 10 on HackerOne all time soon as well! waiting for another post from @Hacker0x01 on that and maybe a hacker interview 👀
2
0
15
@H4cktus
Hazem
2 years
@exploit_msf @Hacker0x01 Amazing ! securing multi millionaire companies for free. I really hope these 644 0$ bugs will cover your expenses in life :D
2
0
14
@H4cktus
Hazem
2 years
@intigriti There is no sanitization of the user input which may lead to XSS, you can craft an XSS payload that can extract the credit card number from the HTML response, and send it to the attacker's server.
1
0
14
@H4cktus
Hazem
10 months
In October, I submitted 11 vulnerabilities to 6 programs on @Hacker0x01 . #TogetherWeHitHarder
1
0
15
@H4cktus
Hazem
11 months
6/🤝 For all the beginners out there, VDPs can be a stepping stone that prevents quick burnout and keeps the passion alive. Let's change the narrative and encourage every step of the journey, big or small! #InfoSec #HackerJourney
0
0
15
@H4cktus
Hazem
2 years
I think it's time to normalize that privileges required should be set to none when you can sign up easily under 1 minute. #bugbountytips #infosec #bugbounty #bugbountytip
0
2
14
@H4cktus
Hazem
11 months
1/📊 First things first, let's take a look at my personal journey in the realm of infosec, as depicted in the attached chart. I began my #hackerone journey in 2019, and it offers an interesting perspective on VDPs vs. paying programs.
Tweet media one
1
0
14
@H4cktus
Hazem
3 months
Tweet media one
1
1
14
@H4cktus
Hazem
11 months
5/🌟 Moral of the story: Starting your #BugBounty career with VDPs isn't a step back. It equips you with invaluable experience, teaches effective communication with triagers, helps you craft impactful reports, and most importantly, bolsters your confidence in your abilities.
1
0
14
@H4cktus
Hazem
11 months
@Jayesh25_ @Hacker0x01 Collaboration is undoubtedly beneficial. It motivates you and increases your commitment because you're not working alone and need to align with your partner. However, the crucial aspect of collaboration is choosing the right collaborator, which is often the most challenging part.
1
0
13
@H4cktus
Hazem
2 years
my luck in 1 picture :D
Tweet media one
1
0
12
@H4cktus
Hazem
1 year
@Hacker0x01 I started working on the new scope the program provided 7 mins after announcing it, was a small scope that's why it took 2 days max. got a bit lucky there :)
0
0
11
@H4cktus
Hazem
8 months
@bxmbn It’s that time of the year again. You’re pointing at Peter as if he has a say in who gets invited and who doesn’t , and as many fellow hackers already told you that, it’s not just about skills and it will never be. I wouldn’t like to invite someone to a LHE who will keep
0
0
11
@H4cktus
Hazem
3 years
Was a really lucky finding ngl !
@disclosedh1
publiclyDisclosed
3 years
Rockstar Games disclosed a bug submitted by @Sn0wd3n_ : - Bounty: $1,000 #hackerone #bugbounty
Tweet media one
1
7
40
0
0
11
@H4cktus
Hazem
2 years
@cyrextech - Met and collaborated with cool hackers such as @monkehack , @samm0uda " make sure to give them a follow! - - Got to know and learn from some other cool hackers such as @pmnh_ , @0xGodson_ , @0xDexter0us , @0xDexter0us , @kazem721 , @equat0rium , @_N0xi0us_ , etc
3
0
11
@H4cktus
Hazem
2 years
@intigriti Unfortunately, we cannot add you to the original report as this report contains additional information that we cannot share with you. This may include personal information or additional vulnerability information that shouldn't be exposed to other users.
1
0
11
@H4cktus
Hazem
1 year
1
1
11
@H4cktus
Hazem
1 year
Team #Turkey is going to the next round ! Well played other teams, was really nice competition 🔥
@Hacker0x01
HackerOne
1 year
That's a wrap for Round 1 of the #AmbassadorWorldCup ! Congrats on an incredible round of teamwork. 🙌 Take a look at the stats! 📊 👨‍💻 239 hackers 🪲 262 valid bugs 💰170 bounties awarded 🤑 $515K in bounties paid (so far) See the full recap here:
Tweet media one
Tweet media two
Tweet media three
Tweet media four
3
29
174
1
0
11
@H4cktus
Hazem
2 years
@renniepak @hgreal1 @hgreal1 restored my stolen NFT account in no time and he didn't ask for anything in return. He also saved my friend @monkehack when his crypto wallet got stolen.
3
1
6
@H4cktus
Hazem
1 year
Been a pleasure to work and learn beside you @dreyand_ , keep up the good work :)
@dreyand_
DreyAnd
1 year
Been collabing with @H4cktus during the past weeks, report queue slowly clearing out with payouts - feels good to break my bug bounty burnout, hopefully more to come👍🏻
2
1
14
1
1
10
@H4cktus
Hazem
3 years
My first bd in @nakitcoins ! Thank you guys ! Meant a lot to me 🥰
Tweet media one
4
0
10
@H4cktus
Hazem
7 months
@ilhan_mercan @Hacker0x01 Can't we spice it a bit more? hiding the program name and showing it alongside the bounties " if set to public " in the profile hacktivity page the same way as it's being done with reports to public programs - @ilhan_mercan
Tweet media one
2
0
10