Hammad 🇵🇰🇵🇸 Profile Banner
Hammad 🇵🇰🇵🇸 Profile
Hammad 🇵🇰🇵🇸

@Hammad7361

Followers
3,804
Following
122
Media
103
Statuses
971

Bug bounty hunter on @Bugcrowd |

Joined July 2021
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
Pinned Tweet
@Hammad7361
Hammad 🇵🇰🇵🇸
2 years
Finally today I achieved P1 Warrior Level 1, In Sha Allah soon I'll achieve P1 Warrior level 2 😍 Thanks @Bugcrowd #ItTakesACrowd #bugbounty Keep pushing yourself to achieve your goals and one day you will 🫡😎
Tweet media one
Tweet media two
35
9
230
@Hammad7361
Hammad 🇵🇰🇵🇸
1 year
Found another SQLi on @Bugcrowd 's private program #ItTakesACrowd #BugBounty #bugbountytips #bugbountytip Tip: Use this payload 0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z In the value of every parameter and check if response delays according to the provided time in payload
Tweet media one
Tweet media two
26
185
685
@Hammad7361
Hammad 🇵🇰🇵🇸
2 years
Reported my 3rd P1 on @Bugcrowd Thanks @RelentlessT7 for the fast Triage 😍 #ItTakesACrowd Tip: Used this payload /0'XOR(if(now()=sysdate(),sleep(10),0))XOR'Z/ in the URI Path. #BugBounty #bugbountytips #bugbountytip #infosec
Tweet media one
22
92
347
@Hammad7361
Hammad 🇵🇰🇵🇸
2 years
Wow the fastest Triage on @Bugcrowd I have ever experienced. Triaged in 4 minutes 🫣😍 Tip: payload used in POST request parameter (SELECT*FROM(SELECT(SLEEP(10)))a) #bugbounty #bugbountytip #bugbountytips #SQL #infosec #bugcrowd #ItTakesACrowd
Tweet media one
9
49
269
@Hammad7361
Hammad 🇵🇰🇵🇸
2 years
Started my journey in BugHunting from Nov 2021 and here is my 2022 report: -Earned $12600 in total -Submitted 130 reports -74 Duplicate -29 Rejected -27 Accepted #BugBounty #infosecurity @Bugcrowd #ItTakesACrowd
Tweet media one
18
20
245
@Hammad7361
Hammad 🇵🇰🇵🇸
20 days
Another hit! Let's hope it gets accepted 🙌🏻 Bt the way Is it just me or everyone facing Slow Triage experience on @Bugcrowd from last week? #bugbounty #infosec #infosecurity #bugbountytip #bugbountytips Tip: site.tld/xyz/xyz/xyz/?path=../../../../../../../../../etc/passwd
Tweet media one
17
14
243
@Hammad7361
Hammad 🇵🇰🇵🇸
2 years
This week was very exciting for me. Reported my first P1, Thanks @Bugcrowd for an Amazing platform. #ItTakesACrowd #BugBounty #infosec #bugbountytips #bugbountytip
Tweet media one
12
11
213
@Hammad7361
Hammad 🇵🇰🇵🇸
6 months
Happy Ramadan to everyone 🌙✨ and thanks @Bugcrowd for being such a great platform #bugbounty #bugbountytips #ItTakesACrowd #infosecurity Tip: If you find any SQL Injection in a target, send me the target I will give you more SQLs😂
Tweet media one
17
13
214
@Hammad7361
Hammad 🇵🇰🇵🇸
5 months
Spent 8 hours straight on @bugcrowd to identify these 😮‍💨 let's see how it goes👀 #bugbountytips #bugbounty #ittakesacrowd #infosecurity Tip: always try to find places where you are able to store values and test them for Stored XSS
Tweet media one
14
10
201
@Hammad7361
Hammad 🇵🇰🇵🇸
3 months
Al-Hamdulillah All Triaged got Accepted ☺️ Thanks @Bugcrowd for providing opportunities #Ittakesacrowd #bugcrowd #bugbounty #infosec
Tweet media one
15
3
198
@Hammad7361
Hammad 🇵🇰🇵🇸
10 months
Al-Hamdulillah reported 2 more SQLi on @Hacker0x01 #bugbounty #SQL #informationsecurity Tip: take some time to hunt on other platforms also 😉
Tweet media one
19
6
186
@Hammad7361
Hammad 🇵🇰🇵🇸
2 years
Reported my 2nd SQLi on @Bugcrowd #ItTakesACrowd Hope its not dup it will be my first Accepted P1 on Bugcrowd 🫣 #BugBounty #bugbountytips Tip: You always not get error using a ' (single quote). See the thread below How I found and confirmed it
Tweet media one
19
30
189
@Hammad7361
Hammad 🇵🇰🇵🇸
10 months
Al-Hamdulillah 😍 SQLi everywhere 😅 3 Triaged 1 Triaged -> Duplicate on @Bugcrowd #bugbounty #bugbountytip #bugbountytips Tip: Don't just fire the payloads blindly, try to understand the application where the request is interacting with the Database and then go for it !
Tweet media one
13
13
187
@Hammad7361
Hammad 🇵🇰🇵🇸
1 year
Al Hamdulillah made some nice bounties before my exams so that I can focus on studies but new invitations are distracting me from studies😂 Thanks @Bugcrowd for providing good programs to hunt #bugbounty #ItTakesACrowd #infosec Bugcrowd always send good invitations on my exams 🥹
Tweet media one
8
3
178
@Hammad7361
Hammad 🇵🇰🇵🇸
5 months
Eid Mubarak to everyone 🌛 First Exceptional report on @intigriti BBP program let's see how it goes 💪🏻 I don't hack for free #bycottVDP #BugBounty #infosec
Tweet media one
14
7
186
@Hammad7361
Hammad 🇵🇰🇵🇸
6 months
That's really amazing 👏🏻 Trim_Bugcrowd is Triaging submissions even on Sunday 🫣 #BugBounty @Bugcrowd #infosec #infosecurity
Tweet media one
12
5
171
@Hammad7361
Hammad 🇵🇰🇵🇸
2 years
After alot of duplicates I was awarded my first bounty of 2023 on @Bugcrowd #ItTakesACrowd #BugBounty
Tweet media one
14
6
160
@Hammad7361
Hammad 🇵🇰🇵🇸
1 year
When you are addicted to hacking 😅 Hunting during exams, found 3 RXSS on @Bugcrowd #ItTakesACrowd #BugBounty #bugbountytips #bugbountytip #infosec Tip: Didn't found anything to test on this subdomain from any source but found a juicy path using
Tweet media one
3
25
162
@Hammad7361
Hammad 🇵🇰🇵🇸
2 months
Al-Hamdulillah for everything❤️. Getting my hard work paid off! Thanks @Bugcrowd for the opportunities you provide! #ittakesacrowd #bugbountytip #bugbountytips #bugbounty #infosecurity Tip: Master 1 vulnerability type and keep learning more n more of it, +make notes of it too
Tweet media one
Tweet media two
12
6
167
@Hammad7361
Hammad 🇵🇰🇵🇸
27 days
Halfway done for August, not spending much time this month. Sometimes, you need to take care of your health too ✌️ Thanks @Bugcrowd #Ittakesacrowd #BugBounty #infosec #infosecurity
Tweet media one
18
4
165
@Hammad7361
Hammad 🇵🇰🇵🇸
5 months
Does anyone know why getting empty 0 size files while downloading the .php files from a Directory Listing? when .php files have size on Directory Listing? #bugbountytips #bugbountytip #BugBounty
Tweet media one
36
9
158
@Hammad7361
Hammad 🇵🇰🇵🇸
10 months
Everyone should hunt on different platforms also, I usually hunt on @Bugcrowd but sometimes I hack on @Hacker0x01 also when I am bored Reported 2 SQLis on Hackerone 1 Got Duplicated and other Got Triaged Al-Hamdulillah 🥰 #BugBounty #bugbountytip #infosec
Tweet media one
Tweet media two
9
3
146
@Hammad7361
Hammad 🇵🇰🇵🇸
4 months
Took me 13 min to bypass the fix and report the XSS again on @Bugcrowd #ItTakesACrowd #BugBounty #infosecurity Lets see how it goes 😅
Tweet media one
6
1
146
@Hammad7361
Hammad 🇵🇰🇵🇸
1 year
In June I submitted 11 vulnerabilities to 4 Programs doing only little hacking on @Bugcrowd and earned some Good bounties $$$$ #bugbounty #ItTakesACrowd #infosec
Tweet media one
12
4
132
@Hammad7361
Hammad 🇵🇰🇵🇸
6 months
Just discovered a new CVE Severity: Medium Bug type: RXSS #BugBounty #bugbountytips #infosecurity Shoot me a DM for collab if anyone is interested Note: You should know how to find targets using specific service
Tweet media one
7
2
140
@Hammad7361
Hammad 🇵🇰🇵🇸
1 year
First P1 of 2023 on @Bugcrowd #ItTakesACrowd #bugbounty #bugbountytips Tip: used ' (single quote) in POST request parameter and got this MySQL error after that gave it to by @r0oth3x49 and successfully fetched the Database
Tweet media one
7
20
138
@Hammad7361
Hammad 🇵🇰🇵🇸
5 months
This month I am trying to get on monthly Top 10 Leader Board on @Bugcrowd let's see how it goes 🙂 #bugbountytips #bugbountytip #Bugbounty #infosecurity see the (🧵) below for tip:
Tweet media one
Tweet media two
Tweet media three
10
5
133
@Hammad7361
Hammad 🇵🇰🇵🇸
4 months
Was unaware that P3 level XSS are OOS and got -1😂 Then escalated it to P2😉 @Bugcrowd #bugbountytips #bugbounty #infosecurity #Ittakesacrowd Tip: Always upgrade your XSS to P2 atleast, Steal session cookie, Update password/email or other sensitive information. DM if you can't😂
Tweet media one
5
7
129
@Hammad7361
Hammad 🇵🇰🇵🇸
1 year
Yay I was awarded my first bounty on @Hacker0x01 #BugBounty #infosec It was a Stored XSS but they set the severity to Medium because it required 1 user interaction according to them. Even though it was triggering on Admin-role and it was possible to takeover Admin-role.🫤😂
Tweet media one
14
4
126
@Hammad7361
Hammad 🇵🇰🇵🇸
5 months
The program is slow but it's worth hunting it ! I hope will be able to climb monthly leaderboard first time😂 on @Bugcrowd #bugbounty #infosecurity #ittakesacrowd
Tweet media one
Tweet media two
12
3
123
@Hammad7361
Hammad 🇵🇰🇵🇸
4 months
In the previous month, I worked a lot to get my name in the monthly leaderboard, and successfully, I secured the 5th rank, but that made me too much restless. Had decided to rest this month, but some programs are just love ❤️ #bugbounty #infosec #Ittakesacrowd @Bugcrowd
Tweet media one
13
0
122
@Hammad7361
Hammad 🇵🇰🇵🇸
4 months
Al-Hamdulillah hard work payed off! Secured 5th rank in P1/P2 and 9th rank in P1/P2/P3/P4 in April's Leaderboard on @Bugcrowd @codingo_ #Ittakesacrowd #bugbounty #bugbountytips Tip: "Don't be a Jack of everything and King of nothing." Master 1 vulnerability type atleast
Tweet media one
Tweet media two
13
0
117
@Hammad7361
Hammad 🇵🇰🇵🇸
23 days
19 Reports pending on @Bugcrowd and Just found a Stored XSS with help of ChatGpt cuz I don't know about these languages very much like Python etc Tip: Use AI to get help in things you don't understand or don't know #bugbountytip #bugbountytips #bugbounty #infosec #infosecurity
Tweet media one
5
1
118
@Hammad7361
Hammad 🇵🇰🇵🇸
4 months
Missed so many opportunity because I checked the new scope very late and the program also didnot made any announcement😥 It will be a duplicate rain on XSS😂 But SQLi got Triaged🫰by #Tal_Bugcrowd within 15 min of submitting #bugbounty #infosec @Bugcrowd #ittakesacrowd
Tweet media one
13
1
116
@Hammad7361
Hammad 🇵🇰🇵🇸
26 days
Hi Bug bounty hunters! I am first time going to analyze the JS files to find security vulnerabilities e.g Finding endpoints/parameters/secret data/info leak anything. I have 0 experience in this. Can anyone share some tools/tips to do so? #bugbountytips #infosec #bugbounty
7
10
116
@Hammad7361
Hammad 🇵🇰🇵🇸
5 months
This type of feeling is different🤩 Thanks @Bugcrowd for every opportunity #ittakesacrowd Program Resumed 11:04 Reported 8 Stored XSS Program Closed again 11:09 Program Owner Be like: I should not have resumed it😅 #bugbounty #infosecurity #infosec
Tweet media one
Tweet media two
8
1
111
@Hammad7361
Hammad 🇵🇰🇵🇸
5 months
3 Triaged remaining 5 are yet to be Triaged😉 @Bugcrowd #BugBounty #infosecurity But not satisfied with severity it should be P1 as I'm able to takeover other researcher's account. Since Stored XSS doesn't require user interaction & ATO without user interaction is P1 @codingo_ ?
Tweet media one
9
1
109
@Hammad7361
Hammad 🇵🇰🇵🇸
1 year
Resolved? No problem 😜 Bypassed both reports and Alhamdulillah Triaged @Bugcrowd #bugbounty #bugbountytips #ItTakesACrowd #infosecurity Tip: Use ` ` back quotes when () parantheses are blocked
Tweet media one
Tweet media two
6
8
99
@Hammad7361
Hammad 🇵🇰🇵🇸
3 months
Al-Hamdulillah, even having a very busy routines managed to secure some programs on @Bugcrowd #bugbounty #bugbountytips #infosec Tip: For stored xss, when you store input somewhere, do check page source of every page bcuz sometimes your payload executes on other paths
Tweet media one
Tweet media two
7
2
103
@Hammad7361
Hammad 🇵🇰🇵🇸
4 months
Al-Hamdulillah😍 The preparation of getting my name on April's Top 10 Leaderboard is going very well. Thanks @Bugcrowd for every opprtunity #Ittakesacrowd #BugBounty #infosecurity
Tweet media one
7
0
92
@Hammad7361
Hammad 🇵🇰🇵🇸
1 year
Thanks @bxmbn for motivating me that I can find something juicy during my exams and I scored my highest bounty of all time on @Bugcrowd #ItTakesACrowd #BugBounty
Tweet media one
Tweet media two
11
1
90
@Hammad7361
Hammad 🇵🇰🇵🇸
1 month
Al-Hamdulillah, now I am Top 250 worldwide on @Bugcrowd #ItTakesACrowd #BugBounty #infosec #infosecurity Next goal to get in Top 200 😎
Tweet media one
8
0
93
@Hammad7361
Hammad 🇵🇰🇵🇸
21 days
Yeeeet😬 Hope it get Accepted long time I have not submitted a P1 bug 😂 @Bugcrowd #bugbounty #infosec #infosecurity
Tweet media one
3
3
89
@Hammad7361
Hammad 🇵🇰🇵🇸
7 months
My 3rd submission Rewarded on @intigriti #bugbounty #infosec
Tweet media one
6
2
88
@Hammad7361
Hammad 🇵🇰🇵🇸
8 months
My frist accepted vulnerability on @intigriti Many more to come 😉 #bugbounty Hey @intigriti send me some good private programs haha 😆
Tweet media one
7
3
84
@Hammad7361
Hammad 🇵🇰🇵🇸
5 months
Al Hamdulillah , severities updated to High 💪🏻 @Bugcrowd #BugBounty #infosecurity #ItTakesACrowd
Tweet media one
Tweet media two
1
0
85
@Hammad7361
Hammad 🇵🇰🇵🇸
7 months
My 2nd Accepted Submission on @intigriti More to come In Sha Allah ♥️🙌🏻 #bugbounty #infosecurity
Tweet media one
12
3
85
@Hammad7361
Hammad 🇵🇰🇵🇸
1 month
Al-Hamdulillah I am Ranked 5th [ P1 , P2 ] & 6th [ P1 , P2 , P3 , P4 ] in July Leaderboard on @Bugcrowd #BugBounty #infosecurity #infosec
Tweet media one
Tweet media two
7
1
82
@Hammad7361
Hammad 🇵🇰🇵🇸
10 months
Another hit found another SQL injection and is now pending for program review on @Hacker0x01 #bugbounty #infosec
Tweet media one
3
2
80
@Hammad7361
Hammad 🇵🇰🇵🇸
2 years
#2023goals #infosec #BugBounty My Goals for 2023 🎉 - Reach 1000 reputation points on @Bugcrowd (current points 331) - Reach P1 Warrior lvl 4 (current lvl 1) - Earn $50k bounties in Total (current $12k) - Buy a New House🏡 - Buy my Dream Bike😂
6
3
76
@Hammad7361
Hammad 🇵🇰🇵🇸
3 months
Al Hamdulillah secured the Top 10 monthly leaderboard in May also 🥳 Thanks @Bugcrowd for the opportunities #Ittakesacrowd #bugbounty #infosecurity
Tweet media one
Tweet media two
4
0
77
@Hammad7361
Hammad 🇵🇰🇵🇸
5 months
@Bugcrowd SQL Tip: parameter=value = 200 OK parameter=value' = SQL Exception Error Exploited further with #ghauri and fetched the database names
Tweet media one
Tweet media two
5
6
72
@Hammad7361
Hammad 🇵🇰🇵🇸
2 years
Back after a long break 😂 I earned $300 on @Bugcrowd #ItTakesACrowd #bugbounty #bugbountytip Tip: Always try to bypass resolved reports. also take a break it really worth.
Tweet media one
0
4
68
@Hammad7361
Hammad 🇵🇰🇵🇸
6 months
When a program doesn't reward bounty for Low and Medium 😏 Just escalate your bug to High or Critical 😉 #BugBounty #infosecurity @intigriti
Tweet media one
1
0
67
@Hammad7361
Hammad 🇵🇰🇵🇸
1 month
Tweet media one
2
3
67
@Hammad7361
Hammad 🇵🇰🇵🇸
2 months
Satisfaction level 😮‍💨 time to take some break and rest Thanks @Bugcrowd for great opportunities #Ittakesacrowd #BugBounty #infosecurity #infosec
Tweet media one
5
0
65
@Hammad7361
Hammad 🇵🇰🇵🇸
10 months
Failed to exploit them using SQL-Map then tried #Ghauri from @r0ot_h3x49 and by using simple commands, successfully fetched the Database😀
@Hammad7361
Hammad 🇵🇰🇵🇸
10 months
Everyone should hunt on different platforms also, I usually hunt on @Bugcrowd but sometimes I hack on @Hacker0x01 also when I am bored Reported 2 SQLis on Hackerone 1 Got Duplicated and other Got Triaged Al-Hamdulillah 🥰 #BugBounty #bugbountytip #infosec
Tweet media one
Tweet media two
9
3
146
0
14
65
@Hammad7361
Hammad 🇵🇰🇵🇸
8 months
Good Bye @2023 . It was a great year with alot of experiences ✨ 1. I don't hunt much but earned more than in bounties from 2022 💰💰💰 2. Learned alot from twitter 🧑🏻‍💻 3. Completed many of dreams with the help of Bug Bounty🙌🏻 4. Got Married✌🏻 #bugbounty #infosec #HappyNewYear2024
4
0
64
@Hammad7361
Hammad 🇵🇰🇵🇸
2 years
I was awarded $500 for my submission on @Bugcrowd #BugBounty #ItTakesACrowd It was R-XSS
Tweet media one
6
0
62
@Hammad7361
Hammad 🇵🇰🇵🇸
4 months
Some ASEs are headache😮‍💨 Even you write a detailed POC they will not able to reproduce🙂 #BugBounty #infosecurity
Tweet media one
@Hammad7361
Hammad 🇵🇰🇵🇸
5 months
This type of feeling is different🤩 Thanks @Bugcrowd for every opportunity #ittakesacrowd Program Resumed 11:04 Reported 8 Stored XSS Program Closed again 11:09 Program Owner Be like: I should not have resumed it😅 #bugbounty #infosecurity #infosec
Tweet media one
Tweet media two
8
1
111
9
0
61
@Hammad7361
Hammad 🇵🇰🇵🇸
2 years
Thanks @Bugcrowd for this amazing swag "bugcrowd gaming mat" Looks Cool with my setup 🙌🏻🔥 #ItTakesACrowd #BugBounty
Tweet media one
Tweet media two
3
0
61
@Hammad7361
Hammad 🇵🇰🇵🇸
1 year
The beginning on @Hacker0x01 was very bad when I didn't had much experience in Bug Bounty and made my profile Signal (-1)😂 Time to start hunting on Hackerone also and building my profile😇 Wish me luck🥺 1 Triaged on BBP 1 Triaged on VDP #bugbounty #togetherwehitharder #infosec
Tweet media one
3
1
59
@Hammad7361
Hammad 🇵🇰🇵🇸
1 year
Joining @Hacker0x01 was a good decision at least getting something better than nothing #TogetherWeHitHarder #bugbounty #infosec Why the severity is set to Low can anyone from hackerone explain? Target have Low in CVSS section so it means if I find critical it will be still low?
Tweet media one
Tweet media two
5
1
55
@Hammad7361
Hammad 🇵🇰🇵🇸
2 years
I was awarded $250 for my submission on @Bugcrowd #BugBounty #bugbountytips #ItTakesACrowd @x_shebi_x @XSaadAhmedX @osamaavvan Finally its accepted 😂🙌🏻
Tweet media one
8
4
54
@Hammad7361
Hammad 🇵🇰🇵🇸
1 year
After 2 months of Triaged report I was awarded $$$ on @Bugcrowd #ItTakesACrowd #bugbounty Reward range was $100-$750 for P3 and they choosed to pay $100 😂, Submitted them 1 more XSS will have to wait 2 months again to get that $100 again 😂
Tweet media one
4
2
53
@Hammad7361
Hammad 🇵🇰🇵🇸
2 years
🧵(1/1) Scenario I faced: First got 302 So I put ' and got 200 OK I confirmed like this No value --> 302 Response ' --> 200 OK '' --> 302 ''' --> 200 '''' --> 302 ''''' --> 200 Then I gave it to SQL Map to confirm
2
10
49
@Hammad7361
Hammad 🇵🇰🇵🇸
1 year
Now I have to wait 2 months again to get rich 😂💰 #ItTakesACrowd #BugBounty @M7arm4n #bugbountytips Tip: Don't waste your time in this BBP Hunt other programs instead! 🫤
Tweet media one
2
1
51
@Hammad7361
Hammad 🇵🇰🇵🇸
7 months
Yeay, I was awarded for a valid submission on @HackenProof #hackenproofed #bugbounty
0
3
48
@Hammad7361
Hammad 🇵🇰🇵🇸
5 months
@akita_zen @Bugcrowd I usually put %20'"><details open ontoggle=alert(1)> but if I get any WAF I then try sending half of payload to check which is blocked and try bypassing it
2
3
44
@Hammad7361
Hammad 🇵🇰🇵🇸
2 years
When you report a bug and Company immediately disable the feature causing that issue. Thank God I had made the PoC just before the feature was disabled. @Bugcrowd #ItTakesACrowd #BugBounty #bugbountytips #bugbountytip See the (🧵) for tip.
Tweet media one
Tweet media two
3
3
43
@Hammad7361
Hammad 🇵🇰🇵🇸
1 year
When program validation time is this. I report and move on😂 #bugbounty #ItTakesACrowd
Tweet media one
Tweet media two
3
2
41
@Hammad7361
Hammad 🇵🇰🇵🇸
1 year
What the hell is going on @Hacker0x01 ? First report is Triaged then duplicate from a report made after me? Is it a joke? #BugBounty #infosec @bug_vs_me
Tweet media one
Tweet media two
11
1
41
@Hammad7361
Hammad 🇵🇰🇵🇸
7 months
In January I submitted 14 vulnerabilities to @Bugcrowd , 12 Vulnerabilities to @Hacker0x01 , 4 vulnerabilities to @intigriti and 1 vulnerability to @HackenProof #bugbounty #infosecurity
4
0
35
@Hammad7361
Hammad 🇵🇰🇵🇸
22 days
Note: [ I will upgrade to latest top variant of any brand, Apple , Dell , Lenovo , Hp etc ] Your suggestions would be appreciated @hakluke @badcrack3r @h4x0r_dz @OriginalSicksec @0x_rood @fattselimi @Masonhck3571 @codecancare #bugbounty #infosec #infosecurity
@Hammad7361
Hammad 🇵🇰🇵🇸
22 days
Hello guys, I want to upgrade my Laptop, what are your recommendations? Is there any benefits to move from Windows to Mac ? Rn I have Dell Inspiron 5515. My requirements: I want to do automation stuff Load heavy files Multi tasks Plus, that damn Burp that cosumes a lot of memory
7
0
17
17
0
34
@Hammad7361
Hammad 🇵🇰🇵🇸
2 years
Al Hamdulillah ♥️, First time qualified for a Bugcrowd MVP Program 🙌🏻 Thanks @Bugcrowd for an amazing platform #swag #MVP #ItTakesACrowd #infosec #bugbounty
Tweet media one
1
1
32
@Hammad7361
Hammad 🇵🇰🇵🇸
6 months
Only way to overcome this issue is all bug hunters should unite to not hunt on VDPs , they will automatically turn their programs into BBP when they will need to pay platforms without getting submissions. I have seen VDPs turning to BBPs when they were not recieving submissions.
@h4x0r_dz
H4x0r.DZ
6 months
Agreed 👍 Bug bounty platforms @Hacker0x01 @Bugcrowd @intigriti …… should stop accepting VDP programs for companies that worth billions #bugbountytip #bugbounty #infose
11
14
100
0
3
34
@Hammad7361
Hammad 🇵🇰🇵🇸
1 year
Hello Hackers, Can anyone tell how can I extract all the scopes of all bug bounty + VDP programs ( Private and Public) that ai have in my account? @ajxchapman @GodfatherOrwa @h4x0r_dz @HusseiN98D @Masonhck3571 #bugbountytips #bugbounty
3
0
25
@Hammad7361
Hammad 🇵🇰🇵🇸
26 days
@Hammad7361
Hammad 🇵🇰🇵🇸
26 days
Hi Bug bounty hunters! I am first time going to analyze the JS files to find security vulnerabilities e.g Finding endpoints/parameters/secret data/info leak anything. I have 0 experience in this. Can anyone share some tools/tips to do so? #bugbountytips #infosec #bugbounty
7
10
116
3
0
25
@Hammad7361
Hammad 🇵🇰🇵🇸
2 years
Refelcted XSS through redirecting parameter on @Bugcrowd #ItTakesACrowd #bugbountytip #bugbountytips Tip: when you see any parameter that redirects you to some path e.g redirectUrl/returnPath, try injecting javascript:alert(1) and send the request which sends you to this path
Tweet media one
1
4
21
@Hammad7361
Hammad 🇵🇰🇵🇸
1 year
Is there any way to check our target's all subdomains list that are using a specific technology e.g like HSTS,Wordpress,SQL ? I am using Wappalyzer but it will consume alot of time to check each single domain @GodfatherOrwa @naglinagli @zseano @codecancare @h4x0r_dz @hakluke
5
4
19
@Hammad7361
Hammad 🇵🇰🇵🇸
8 months
Who is Adam-bugcrowd ? anyone know do he have twitter? I want to do friendship with him 😂 #bugbounty #bugcrowd @Bugcrowd @Masonhck3571 you might know
3
0
20
@Hammad7361
Hammad 🇵🇰🇵🇸
2 years
Tip: Stick to 1 program and go deeper and deeper as you can. Do find bugs manually cuz scanner found nothing in this program and I did. 🙃
0
2
18
@Hammad7361
Hammad 🇵🇰🇵🇸
22 days
Hello guys, I want to upgrade my Laptop, what are your recommendations? Is there any benefits to move from Windows to Mac ? Rn I have Dell Inspiron 5515. My requirements: I want to do automation stuff Load heavy files Multi tasks Plus, that damn Burp that cosumes a lot of memory
7
0
17
@Hammad7361
Hammad 🇵🇰🇵🇸
1 year
I closed the program after reading that 😂 They believe their site is built like people will not fall for such attacks? #BugBounty #infosec #shit 💩
Tweet media one
4
0
18
@Hammad7361
Hammad 🇵🇰🇵🇸
6 months
Does @Toyota operate a BBP on @intigriti ? DM me if anyone know #BugBounty
6
0
17
@Hammad7361
Hammad 🇵🇰🇵🇸
1 year
@bxmbn I wish I may also have a month like this btw congratulations 👏
1
0
15
@Hammad7361
Hammad 🇵🇰🇵🇸
3 months
Happy Eid ul Adha Mubarak to everyone ✨️❤️ #infosecurity #eid
1
0
16
@Hammad7361
Hammad 🇵🇰🇵🇸
1 year
Thanks to @imranHudaA and @iambouali for this opportunity ❤️
@Hammad7361
Hammad 🇵🇰🇵🇸
1 year
Yay I was awarded my first bounty on @Hacker0x01 #BugBounty #infosec It was a Stored XSS but they set the severity to Medium because it required 1 user interaction according to them. Even though it was triggering on Admin-role and it was possible to takeover Admin-role.🫤😂
Tweet media one
14
4
126
2
0
15
@Hammad7361
Hammad 🇵🇰🇵🇸
6 months
A quick question for Triagers: 1 XSS on and is vulnerable and both main domain and subdomain have different IP addresses: hosted on IP 111.222.333.44 and hosted on IP 111.222.888.00
New/Different report
46
Duplicate report
25
1
2
13
@Hammad7361
Hammad 🇵🇰🇵🇸
10 months
1
0
13
@Hammad7361
Hammad 🇵🇰🇵🇸
2 years
Tip: Think out of the box. This asset was not listed in In-scope but it had an impact to In-scope asset 🫡
2
0
9
@Hammad7361
Hammad 🇵🇰🇵🇸
4 months
Does anyone have Cloudfront SQL bypass? #bugbountytips #bugbounty #infosecurity @nav1n0x
0
0
13
@Hammad7361
Hammad 🇵🇰🇵🇸
2 years
@GodfatherOrwa @Bugcrowd you found admin/campaigns.php by fuzzing?
1
1
11
@Hammad7361
Hammad 🇵🇰🇵🇸
2 years
@Bugcrowd SQL payloads from github/twitter/Scanners/disclosed reports/etc
0
1
11
@Hammad7361
Hammad 🇵🇰🇵🇸
2 years
Please @Bugcrowd @codingo_ do something about the triage team. They marked my valid **HTML INJECTION** report as Not Acceptable @XSaadAhmedX @osamaavvan #bugbountytips #BugBounty
Tweet media one
7
1
11
@Hammad7361
Hammad 🇵🇰🇵🇸
2 years
Amazing finding 🫡. Must read !!!
@samwcyo
Sam Curry
2 years
We played around with this for a while, until we tried something that worked: By adding a CRLF character at the end of an already existing victim email address during registration, we could create an account which bypassed the JWT and email parameter comparison check!
Tweet media one
5
39
344
0
3
12
@Hammad7361
Hammad 🇵🇰🇵🇸
2 years
@phayeesan @Bugcrowd No I haven't any idea when I started just struggled hard didn't gave up and continued learning and applying everything learned from all available sources.
1
0
11