SickSec 🇲🇦 🇵🇸 Profile Banner
SickSec 🇲🇦 🇵🇸 Profile
SickSec 🇲🇦 🇵🇸

@OriginalSicksec

Followers
6,414
Following
327
Media
240
Statuses
2,805

SRT Member | I love GraphQL | Hackerone Ambassador 🇲🇦 | Tweets are my own | Riichi #Mahjong Player Master Tier | see before DM :)

Morroco
Joined March 2018
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
9 months
SSL Pining Bypassed Tiktok APP [Android] 😎😎😎😎😎
Tweet media one
15
62
487
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
2 years
I really wanted to find a bug in Uber for a while Finally it happened @Hacker0x01
Tweet media one
41
10
472
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
4 months
Someone is getting fired today x)
Tweet media one
26
43
473
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
6 months
After 3 months of hacking on Airbnb BBP in @Hacker0x01 , here are the stats: - Ranked 10 on the Leaderboard - Earned 69K in bounties - Secured Rank 2 for 2024 - Bounties ranged from 2K to 22.5K. Excited for the challenges and rewards in the next 11 months!
Tweet media one
35
9
415
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
2 years
2022 was a fantastic year for me! I earned a massive 100K+$ in bounties, including a huge 60K$ from a single program in Q4. I also achieved Rank 1 in Uber bug bounty program and reached the top of the leaderboards, earning Rank 1 on 🇲🇦H1 2022. #hackerone #bugbounty
29
10
359
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
2 years
I'm happy to announce that I have achieved a small milestone which is Rank 1 in 🇲🇦 on the Q4 Leaderboard at @Hacker0x01 1 Target --> 17K$ Bounties and more to come
Tweet media one
22
6
256
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
9 months
@manniefabian This is faker than fake taxi
5
5
247
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
2 years
I finally got some time to make a blog about URL shortners misconfiguration for fun and profit Feedback is more than welcome #bugbounty #infosec #bugbountytips
6
80
249
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
8 months
¯\_(ツ)_/¯
Tweet media one
11
3
211
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
4 years
Quick tactic for Critical Bug #bugbountytips Add '_profiler' in your path `target/_profiler` if 200 OK Check for `Symfony` in the body if OK You can see logs and env and database credentials and any request cookies #retweet if you like it :) #hackerone #bugcrowd #bugbounty
Tweet media one
1
50
179
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
3 years
Hey Hackers 👋 I have created a small script to automate the workflow mentioned in by @m4ll0k I would love to hear some suggestions to the tools name #bugbounty #hackerone #bugcrowd N.B: Some of his tools used in the gist are still private
5
69
182
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
2 years
If your repeater tab is not like this then you are doing something wrong x) #Burpsuite #Bugbounty
Tweet media one
18
15
170
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
2 months
If you like Request Smuggling attacks make sure to check this and use To Practice ✌️
@gregxsunday
Bug Bounty Reports Explained
2 months
Request smuggling is an amazing bug class! But I barely ever did more than running Request Smuggler. So I've analysed tens of reports and in this video, I'll break down the most common root causes and I'll give you some ideas for future research. Enjoy!
4
34
201
1
34
152
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
2 years
Write up for these as REDACTED is soon stay tuned #bugbounty #infosec #bugcrowd @Nasser29951043 <3
Tweet media one
Tweet media two
7
8
142
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
4 years
Dear Hackers I made this tool To automate the process Based on @hakluke Talk regarding amass usage details in here #bugbounty #hackerone #Recon #togetherwehitharder
5
41
141
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
2 years
Yo, just wanted to shout out to the world that I'm now the top dog in Uber's Bug Bounty program for 2022. Big ups to the team at Uber for giving me the opportunity to flex my skills and keep their platform safe. Ain't no stopping me now! #1 #BugBounty #Uber
Tweet media one
13
2
138
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
3 years
#bugbountytips Sharing is caring <3
Tweet media one
2
39
134
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
3 years
Hey hackers 👋 Celebrating 1K followers I just published another write-up of one of my findings showing the power of Waybackurls by the legend @TomNomNom Check it out here #bugbountytips @Hacker0x01
4
36
131
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
1 year
This message made my day 😀 #BugBounty
Tweet media one
8
2
123
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
7 months
Thrilled to secure the #1 spot on HackerOne's Moroccan leaderboard! 🏆 Reflecting on a year of hard work and fun challenges. Hats off to the formidable competition, @Yukusawa18 , @Yassineaboukir & @wld_basha . Grateful for the learning and growth. Here's to more exciting bugs! 🚀
Tweet media one
10
1
117
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
9 months
Proud to have secured the top spot on the @Hacker0x01 Leaderboard in Morocco for Q3! 🏆🇲🇦
Tweet media one
9
0
118
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
2 years
Why there's only XSS challenges ? What about SQLi / LDAP / IDORS @intigriti @Bugcrowd
8
6
116
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
3 years
Hello Community 👋🤪 Wrote a small article to show how you can get your own Permanent @Burp_Suite collaborator and Hunt for SSRF and XXE #bugbountytips #burpsuite #SSRF #infosec
0
44
115
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
11 months
🏆 Delighted to announce reaching a major milestone: $100K in Uber bounties! 🚀 It's been a year-long journey of persistence and dedication. 🙌 Securing rank 1 in 2022/23, along with a solid 4th position on the Uber overall leaderboard, fills me with immense pride. #BugBounty
22
0
116
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
4 years
Got my first critical/RCE in a public program with @soufianelhabti at #hackerone #togetherwehitharder
Tweet media one
4
5
110
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
2 years
The most impressive triage time I have ever experienced P1 shoutout to @Bugcrowd and #Tal_Bugcrowd
Tweet media one
6
0
106
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
3 years
Sup Y'all 👋 Coming up to you again with another writeup about an RCE I found with @wld_basha on The World largest Russian Company #bugbounty #hackerone #infosecurity
3
43
101
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
6 months
😎
Tweet media one
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
7 months
Spent 3 hours diving into Admin GraphQL queries on a bug bounty mission, crafting them for a regular user. Encountered null responses, initially thinking they were non-functional. Plot twist: I was wrong! Always double-check. 👀🔍
Tweet media one
5
0
73
3
2
102
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
2 years
I was able to bypass OAuth using response manipulation using match & replace in @Burp_Suite #bugbountytips #BugBounty #hackerone #intigriti #bugcrowd
Tweet media one
7
6
94
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
9 months
"Excited to share that @wld_basha and I have successfully uncovered an ATO OAuth bug on @Hacker0x01 , earning a well-deserved $5,250 bounty! 🎉 #TogetherWeHitHarder . 👏💻 #BugBounty #Cybersecurity "
7
1
95
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
3 years
Hey Hackers 👋 I published my first writeup on #medium about an XSS using @FindomainApp More to come in the future waiting for permission to post them
0
34
85
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
3 years
How to get good at infosec / bug bounty & pentest ? - Simply get your @PentesterLab - Do badge's and Note what you learned - Add the learning to your To-Do list when Hacking - You will definitely improve Kudos to @snyff <3 #bugbountytips #Pentesting
3
14
86
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
2 years
When @Bugcrowd Triagers trust you <3 I make them Proud #bugbounty
Tweet media one
4
2
79
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
3 years
Want to check if #Amass Keys are working properly in your config ? amass enum -list -config $PATH/toyourconfig.ini #bugbountytips #Owasp #Amass #Hackerone
Tweet media one
1
24
77
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
1 year
Looks like XSS is the most reported bug in #hackerone #BugBounty
Tweet media one
6
0
77
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
2 years
How to be good at #infosec #bugbounty Steps: 1 - Read & Practice 2 - Do step 1 3 - See step 2
0
5
73
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
2 years
I earned $1500 for my submission on @bugcrowd #ItTakesACrowd
5
0
76
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
3 months
I'm glad to team up with @Yassineaboukir To bring @Hacker0x01 in Morocco If you are interested in bug bounties make sure to sign up in
@Yassineaboukir
Yassine Aboukir 🐐
3 months
Happy to be selected as HackerOne ambassador representing Morocco 🇲🇦 alongside @OriginalSicksec We'll also be recruiting for Ambassador World Cup (AWC) 2024 soon, so let us know if you're interested. In the meantime, we invite all fellow Moroccan hackers to sign up for our club
Tweet media one
17
15
188
4
3
75
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
3 years
Yes guys , Keep doing recon You will find crits in no time 😅 #hackerone #bugbountytips #Recon
Tweet media one
6
4
75
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
2 years
Tweet media one
0
1
70
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
3 years
I have joined @SynackRedTeam , Hoping for a great journey full of bugs and rewards #bugbounty #redteam
Tweet media one
4
2
72
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
11 months
Exciting news! 🎉 We're setting up a Discord server exclusively for the @Hacker0x01 community in the Morocco region. Join us to unleash your cybersecurity skills - Send DM for more info - Comment if you want opt-out - Retweet for reach
Tweet media one
19
20
70
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
2 years
@dccybersec Subfinder -> Amass -> dnsgen -> massdns This is my cycle for getting as much subs as possible
0
9
72
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
1 month
Cool UI change @Hacker0x01 Severity now looks more like a progress bar
Tweet media one
3
0
72
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
7 months
Spent 3 hours diving into Admin GraphQL queries on a bug bounty mission, crafting them for a regular user. Encountered null responses, initially thinking they were non-functional. Plot twist: I was wrong! Always double-check. 👀🔍
Tweet media one
5
0
73
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
3 years
Hello Hackers 🤪👋 Anyone has Openredirect or XSS on Netflix DM me I have an Critical Escalation 🔥🔥🔥 #BugBounty #bugcrowd #infosecurity
3
4
68
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
2 years
I sent an IDOR UUID based to a big company demonstrating how to obtain the <UUID> along with the impact If I get N/A'd I will blame @rez0__ x3
4
2
71
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
2 years
For those who says that @Hacker0x01 Mediation is useless 👀👀
Tweet media one
3
1
69
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
2 years
I earned $1,650 for my submission on @bugcrowd #ItTakesACrowd
Tweet media one
4
0
68
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
4 years
Yay, I was awarded a $250 bounty on @Hacker0x01 ! #TogetherWeHitHarder Bruteforce subs -> found a 302 in /admin -> tested credentials (admin|admin) -> got in Bounty is low since the panel is for testing not prod
4
4
61
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
2 years
I created a small blogpost on how to have a great mindset while doing bugbounty feedbacks are more than welcome :) #BugBounty #bugbountytips
3
21
59
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
11 months
@Rhynorater Everything I use is in this research
3
19
62
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
1 year
@silentgh00st I had a similar finding but I was able to chain 4 bugs to ATO including an IDOR
Tweet media one
4
0
59
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
10 months
Just put in a relentless 3-hour hustle into GraphQL like an absolute boss, sculpting a 566-line masterpiece Query with fragments nested 3 levels deep. 💻 All in the name of a Bug Bounty mission - and guess what? Mission accomplished, we've got PII for any order/user! 🔍🏆
0
0
58
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
2 months
@bxmbn Luck is not a factor in bug bounty, choice of targets, time spent, techniques learned that's based on your intelligence not luck
6
3
57
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
2 years
I had fun with @Nasser29951043 Finding a sick LFI Bypassed 3 security feature to reach this ✌🏼👌 #bugcrowd
Tweet media one
5
0
56
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
5 months
Just remember whenever you use a public bb tool that helps you tremendously in your tasks and in a daily basis, make sure to give back to the creator/owner to help and encourage them to create more and dedicate more time into them #bugbountytools
0
2
55
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
7 months
@nnwakelam I did that and managed to secure first rank in 2022 and 2023 on Uber bbp with more than 130k bounties
3
0
55
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
22 days
@Hacker0x01 #AWC2024 Team 🇲🇦, we're climbing the ladder
Tweet media one
11
4
55
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
2 years
I earned $2000 for 3 submissions on @bugcrowd IDORS GET Based /id/{ID} #ItTakesACrowd
1
1
50
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
5 years
#BugBounty2020Goals 1 - Do more colabs with @mashoud1122 & @Skeletorkeys 2 - Make 100K in 2020 3 - Be more active in @Hacker0x01 4 - Do some writeups about my finding 5 - Learn some android / IOS stuff
1
4
49
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
9 months
@LayahHeilpern You just short sighted, unfortunately
1
0
47
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
3 years
I think I'm gonna wait 30 days after the log4j release, just to give time to developers to fix and be sure that I will get a bounty for it, instead of scanning the whole internet and causing damage :)
9
1
46
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
1 year
@silentgh00st Great Find, you can use this To find electron in all your apps
2
10
46
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
8 months
I'm very close @Yukusawa18 x)
Tweet media one
0
0
47
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
2 years
@hunter0x7 Also check the response for additional parameter /users/me ==> Response {"userID":"123"} Try /users?UserID=122
0
6
44
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
10 months
Earthquake in Morocco 6.8 This is a tough one Prayers Everyone <3
6
1
43
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
10 months
@_naaash_ @rastogirushali Why is this on my feed x)
3
0
44
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
1 year
Exciting news! To commemorate the introduction of @OvercastASM , The innovative Attack Surface tool designed for bbh and pentesters, we're offering 3 premium @PentesterLab - Sign up at - Like & Retweet - Follow @OvercastASM for announcement of winners.
1
17
43
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
6 months
Le me waiting for bounties in holidays
Tweet media one
5
2
42
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
2 years
Both Triaged by client High/Medium Kudos to @rez0__ ✌🏼
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
2 years
I sent an IDOR UUID based to a big company demonstrating how to obtain the <UUID> along with the impact If I get N/A'd I will blame @rez0__ x3
4
2
71
5
1
41
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
4 years
I found almost 152K of valid emails of a private program via waybackurls is this a thing I can report ? #bugbounty #bugcrowd #hackerone #bugbountyhelp
5
3
37
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
2 years
Big shoutout to @Bugcrowd support The response time is unbelievable, feels like chatting Especially D-S 🍻
4
1
40
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
2 years
@h4x0r_dz ffuf support multiple wordlist ffuf -c -w HOST:hosts.txt -w ~/Wordlist/words.txt -u HOST/FUZZ -mc 200 ✌️
3
8
38
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
4 years
I was looking for some blind SSRF using #ffuf Then after 3 minutes ... #bugbounty #infosec #burp
Tweet media one
2
6
38
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
3 months
Great video by Ben So much covered in one video ✌️
@NahamSec
Ben Sadeghipour
3 months
The Truth About Bug Bounties
Tweet media one
1
25
209
0
2
38
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
8 months
Excited to hit that follow button for h1_analyst_bernard on Twitter [Link me] 🚀! This triager is setting some serious goals: 🔥 Lightning-fast triage skills 💡 Nailing those CVSS updates with crystal-clear explanations 👔 Always bringing the utmost professionalism and
2
0
38
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
5 months
@damian_89_ Yeap you're right, congrats on this month
Tweet media one
1
0
37
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
3 years
First time I reported a potential issue that can cause problem and it was triaged and the team understood the potential risk and working on a fix #hackerone #BugBounty
Tweet media one
4
4
37
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
2 years
Hey 👋 Twitter My friend has some serious health issues and I helped her setup a #GoFundMe Page If you can help or re-tweet will be much appreciated Here's her story <Her own words> #fundraising #charity #dogood
3
16
35
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
1 year
👀
Tweet media one
2
0
37
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
1 year
Braces yourselves, I got awarded xxxx$ from OpenAI tweets are coming 👌
3
0
36
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
9 months
Waiting for a crit to be paid 🫠
1
0
35
@OriginalSicksec
SickSec 🇲🇦 🇵🇸
2 years
New Feature @Bugcrowd 👀👀👀 ?
Tweet media one
4
0
35