Abu Maryam Rahmat Profile Banner
Abu Maryam Rahmat Profile
Abu Maryam Rahmat

@abumaryamrahmat

Followers
992
Following
186
Media
23
Statuses
587

Muslim | Bug hunter

Jember, Indonesia
Joined May 2023
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
Pinned Tweet
@abumaryamrahmat
Abu Maryam Rahmat
2 months
Biidznillah, finally got the first place (all-time) in the LinkedIn bug bounty program, It took 2 years to achieve this :) #bugbounty #bughunter #hackerone #infosec #linkedin
Tweet media one
21
4
156
@abumaryamrahmat
Abu Maryam Rahmat
3 months
Biidznillah, I was awarded a $2,500 bounty on @Hacker0x01 1. Type "amr" in the search feature 2. GET /user/api/search?keywords=amr&q=keywords 3. Change to 4. GET /user/api/search?email=victim @gmail .com&q=email Sensitive information about the victim was disclosed #bugbountytips
Tweet media one
28
95
592
@abumaryamrahmat
Abu Maryam Rahmat
4 months
Biidznillah, I was awarded a $5,000 bounty on @Hacker0x01 ! a simple IDOR ❌ GET /api/v1/user/detail?type=1&user_id=123 ✅ GET /api/v1/user/detail?type=0&user_id=123 alwys try changing the value if u find parameters similar to that (type, role, scene, etc.) #bugbountytips
Tweet media one
16
50
377
@abumaryamrahmat
Abu Maryam Rahmat
6 months
Alhamdulillah, I was awarded a $4,500 bounty on @Hacker0x01 ! Add any item to the basket->Intercept->checkout->in the parameter "address_id":"123" change it to the victim's address_id->look at the order->the victim's identity is disclosed #bugbountytips #TogetherWeHitHarder
Tweet media one
33
34
367
@abumaryamrahmat
Abu Maryam Rahmat
9 months
Looking for bugs on LinkedIn in early November 2022, Alhamdulillah the achievements for one year: - Ranked 2nd all-time - 1209 Reputation - 50+ Paid reports If you want to hunt there, LinkedIn has a lot of issues on access control and logic errors :) #hackerone #bugbountytips
Tweet media one
Tweet media two
12
6
155
@abumaryamrahmat
Abu Maryam Rahmat
10 months
Alhamdulillah Another bypass reports on LinkedIn, very interesting looking for bugs here :) #hackerone #bugbountytips
Tweet media one
11
2
128
@abumaryamrahmat
Abu Maryam Rahmat
4 months
@Moohd_Ilham @tanyarlfes Saya awal liat dia udah ragu, ntah kenapa seperti perasaan aja. Biasanya orang ikhlas keliatan dari gimick dan cara bicaranya
2
0
26
@abumaryamrahmat
Abu Maryam Rahmat
3 months
Hopefully @Hacker0x01 will soon reduce the VDPs program, for beginners VDP is very good but in reality many VDPs are used to boast points and this is very strange, they do that without being paid!
@codingo_
Michael Skelton
3 months
Today @bugcrowd , we're expanding our product line to offer VDP's for free , marking the next evolution of our VDP product, following our removal of incentives some time back. This marks a change in the industry, providing a no cost entry point for
Tweet media one
22
60
296
3
1
23
@abumaryamrahmat
Abu Maryam Rahmat
10 months
Alhamdulillah this is my trick to avoid self-duplicate when finding bugs with the same impact but on different urls/endpoints #hackerone #bugbountytips
Tweet media one
Tweet media two
0
2
23
@abumaryamrahmat
Abu Maryam Rahmat
1 year
alhamdulillah my first critical report, hits linkedin :) tips? always test the approve button on the admin side #bugbounty #bugbountytips #hackerone
Tweet media one
3
2
20
@abumaryamrahmat
Abu Maryam Rahmat
9 months
@0xNaeem I read a lot of Idor & Logic Error Writeups, especially here and
1
5
16
@abumaryamrahmat
Abu Maryam Rahmat
5 months
@moraevs @adnardn Ga masalah sama homo? Wkwkwk main lewat lubang *** masa ga dipermasalahi bang? Cmon man
6
0
14
@abumaryamrahmat
Abu Maryam Rahmat
4 months
@mouka0x hastag bugbounty? Are you sure? Try to hastag #vdp or #bugvdp
1
0
12
@abumaryamrahmat
Abu Maryam Rahmat
2 months
@santi_lopezz99 No music at all, quiet and focused
0
0
13
@abumaryamrahmat
Abu Maryam Rahmat
5 months
@intigriti Broken access control such as IDOR 100%
3
0
13
@abumaryamrahmat
Abu Maryam Rahmat
4 months
@_anonysm $8000 - LinkedIn - Account takeover
2
0
12
@abumaryamrahmat
Abu Maryam Rahmat
1 year
Bug bounty motivation from @AkashHamal0x01
Tweet media one
0
2
10
@abumaryamrahmat
Abu Maryam Rahmat
3 months
@696e746c6f6c @Hacker0x01 found IDOR in a unique way, the endpoints and sources were very different, instead of paying for dozens of my IDOR reports they paid for 1 and duplicated it all with the explanation that this was a "known issue" :) hmm
Tweet media one
3
0
12
@abumaryamrahmat
Abu Maryam Rahmat
4 months
@_public_void @Hacker0x01 yep you are right, from a small recon I found in several requests that the type=0 response corresponded to the highest user access and when I found this vulnerable request I tried changing it from type=1 to type=0 and yap it worked
2
1
12
@abumaryamrahmat
Abu Maryam Rahmat
3 months
@_0ranos @Bugcrowd Pornhub? I think you’re a muslim bro?
3
0
9
@abumaryamrahmat
Abu Maryam Rahmat
3 months
@yossygirsang @worksfess True, kalau bener bener big company udh terstruktur dan gak terkait sama 1 orang doang
0
1
10
@abumaryamrahmat
Abu Maryam Rahmat
6 months
@errorsec_ Why not both? Macbook with external monitor like mine
Tweet media one
2
0
9
@abumaryamrahmat
Abu Maryam Rahmat
1 year
Duplicate but get paid, what a nice program @linkedin #hackerone
Tweet media one
Tweet media two
3
0
9
@abumaryamrahmat
Abu Maryam Rahmat
3 months
@neozupernova @SammiSoh Lah malah ustadz khalid paling anti sama ghulluw habib habiban gini, persiapkan di hari kiamat ketemu beliau untuk pertanggung jawabkan foto itu.
0
0
8
@abumaryamrahmat
Abu Maryam Rahmat
11 months
@Rhynorater Wow good story, btw get 50 valid reports about IDOR and logic flaw, any suggestions? Does it continue to deepen or does it add other vulnerabilities? i've been in for almost a year (november 2022 i'm playing on h1)
1
0
7
@abumaryamrahmat
Abu Maryam Rahmat
3 months
@kingcoolvikas @Hacker0x01 I once read a write-up whose case involved disclosing information via email
2
0
7
@abumaryamrahmat
Abu Maryam Rahmat
23 days
@burniadi @AYB_id Wkwkwk dikaish tulisan itu trus bener gitu? Gimana kalau di badan babi kasih tulisan HALAL, berarti babinya halal?
2
0
6
@abumaryamrahmat
Abu Maryam Rahmat
7 months
@Annisamuch_ @ayatsucii @BosPurwa Maaf hadist nya tidak kuat semua, sudah sering dibahas permasalahan ini
1
0
6
@abumaryamrahmat
Abu Maryam Rahmat
6 months
@PrinceFaisal_I Only ahlul bida’ or munafiqun who hates saudi
0
0
6
@abumaryamrahmat
Abu Maryam Rahmat
3 months
@19whoami19 Free palestine, May Allah help our brothers in Palestine.
1
0
5
@abumaryamrahmat
Abu Maryam Rahmat
3 months
@shakti_sec @Bugcrowd @Hacker0x01 Yes, you have to maximize performance but don't forget to lower expectations
0
0
5
@abumaryamrahmat
Abu Maryam Rahmat
2 months
@badcrack3r Want something even more surprising? in Indonesia, people get a certificate from NASA's VDP and then they are invited to television and they are given the label "professional HACKER" to this person, now that person is opening a course because he is famous from a certificate. Hmmm
4
0
5
@abumaryamrahmat
Abu Maryam Rahmat
4 months
@confievil @Hacker0x01 That's right, requests don't appear in general, you have to do A B C before the request appears + when it appears you have to change the type to 0. The point is, read lots of writeups.
0
1
6
@abumaryamrahmat
Abu Maryam Rahmat
2 months
@Arif3114y @SammiSoh Dari video aja keliatan ngelesnya, orang keliatan dari gimick gerakan dan perkataan dia, apalagi pas baca bahasa arab nya malah amburadul
1
1
4
@abumaryamrahmat
Abu Maryam Rahmat
4 months
@0xMstar I’ve never done vdp
1
0
5
@abumaryamrahmat
Abu Maryam Rahmat
9 months
@3nc0d3dGuY @Jarvis0p1 Nice WU broo, keep it up
0
0
3
@abumaryamrahmat
Abu Maryam Rahmat
4 months
@Rafilsafat @bosmaryam Bilang aja mas males belajar agama, itu video dipotong2 saya sudah lihat penuhnya di youtube, nabi muhammad adalah manusia paling berilmu maka fatal anda mengatakan semakin dalam ilmu agama semakin aneh
0
0
4
@abumaryamrahmat
Abu Maryam Rahmat
3 months
@Biliyan7 @ArchTheodore @rynzifary @sosmedkeras Kaum LGBT lebih sadis, bagusnya lemparin dari atas gunung aja biar ga jadi penyakit kek di amerika sekarang, makin jadi aja kaum nabi luth
3
0
2
@abumaryamrahmat
Abu Maryam Rahmat
3 months
@omarsuleiman504 Israel is terorist state!!!!!!
0
0
4
@abumaryamrahmat
Abu Maryam Rahmat
4 months
@spaceboy2O @Hacker0x01 still there but they are getting worse now, lastly reporting PII email,address,phone any user and they set confidentiality to low, i mean what this is? this is too much hahaha
2
0
4
@abumaryamrahmat
Abu Maryam Rahmat
2 months
@hastapurnomo @Notarealgorilla @KemenperinRI Nggak juga sih, mereka itu tegas bukan keras.. saya dulu ngiranya begitu kok orangnya diem pendingin semua ternyata mereka lebih memilih diam daripda banyak bicara, sekali bicara no ghibah dan bermanfaat. Alhamdulillah sering dengerin pengajian dari ustadz salafi hati tenang
0
1
4
@abumaryamrahmat
Abu Maryam Rahmat
10 months
@h4x0r_dz May Allah protect our brothers in palestine
0
0
4
@abumaryamrahmat
Abu Maryam Rahmat
1 year
@RahmatQurishi Thanks for the tips, very great
1
0
4
@abumaryamrahmat
Abu Maryam Rahmat
6 months
1
0
3
@abumaryamrahmat
Abu Maryam Rahmat
9 months
@ShaZopyt yapp hunting on website, android and IOS app
0
0
2
@abumaryamrahmat
Abu Maryam Rahmat
3 months
1
0
3
@abumaryamrahmat
Abu Maryam Rahmat
10 months
@Fabrikat0r Thats same endpoints, Even though the method is different,but thats the same root cause
0
0
3
@abumaryamrahmat
Abu Maryam Rahmat
1 year
@errorrsec @being__aman I don't think so, they pay big according to the severity but sometimes you will meet staff who are not thorough with cvss calculations but that's rare
Tweet media one
1
0
2
@abumaryamrahmat
Abu Maryam Rahmat
6 months
@intigriti Social media
0
0
3
@abumaryamrahmat
Abu Maryam Rahmat
7 months
@spaceboy2O @Hacker0x01 Bounty > final exam
1
0
3
@abumaryamrahmat
Abu Maryam Rahmat
9 months
@Ramanur28 InsyaAllah, may Allah make it ez for you
2
0
3
@abumaryamrahmat
Abu Maryam Rahmat
2 months
@Bo7sain72 alhamdulillah, have to use unique methods for example I like changing parameters or trying to change the response from false to true which will then make the UI change and lead to hidden features. The point is to think outside the box
0
0
3
@abumaryamrahmat
Abu Maryam Rahmat
3 months
@danish_bhat777 @SirBagoza @Hacker0x01 have tried injecting some ID parameters but nothing works :)
0
0
3
@abumaryamrahmat
Abu Maryam Rahmat
9 months
@NoobHunter0x01 @alien2exe I read a lot of Idor & Logic Error Writeups, especially here and . Just learn enough, practice more on live targets
0
3
3
@abumaryamrahmat
Abu Maryam Rahmat
5 months
@intigriti skip? I find a lot of broken access controls in mobile apps
0
0
3
@abumaryamrahmat
Abu Maryam Rahmat
3 months
0
0
3
@abumaryamrahmat
Abu Maryam Rahmat
10 months
@IdoNaor1 Yeah and this is you right now
Tweet media one
0
0
4
@abumaryamrahmat
Abu Maryam Rahmat
2 months
@intigriti Frida, scrcpy
0
0
3
@abumaryamrahmat
Abu Maryam Rahmat
8 months
@L0daW MasyaAllah allahumma baariik bro
0
0
3
@abumaryamrahmat
Abu Maryam Rahmat
3 months
@MR_Prey3r @Hacker0x01 seeing the responses to several requests and inspiration from the writeups I read
0
0
3
@abumaryamrahmat
Abu Maryam Rahmat
10 months
@Hacker0x01 indonesia?? ;)
0
0
0
@abumaryamrahmat
Abu Maryam Rahmat
6 months
@Ali45598547 MasyaAllah nice WU brooo…
0
0
3
@abumaryamrahmat
Abu Maryam Rahmat
9 months
Tweet media one
0
0
3
@abumaryamrahmat
Abu Maryam Rahmat
11 months
@thebinarybot every 30 minutes away from the desk, do something else. or when you are very bored, get out of your house and go for a walk or pray
0
0
3
@abumaryamrahmat
Abu Maryam Rahmat
1 month
@santi_lopezz99 $8000 for an IDOR
0
0
3
@abumaryamrahmat
Abu Maryam Rahmat
6 months
@ojora @xavierjp__ the importance of studying aqidah and manhaj
0
0
2
@abumaryamrahmat
Abu Maryam Rahmat
2 months
@r__hidayah Full masalah akses kontrol, ga ada yang lain
1
0
2
@abumaryamrahmat
Abu Maryam Rahmat
3 months
0
0
2
@abumaryamrahmat
Abu Maryam Rahmat
1 year
@samm0uda MasyaAllah barakAllah fiik akhi
0
0
2
@abumaryamrahmat
Abu Maryam Rahmat
6 months
@shreyas_chavhan nice, keep it up :)
0
0
2
@abumaryamrahmat
Abu Maryam Rahmat
3 months
@hetmehtaa Shame on you!!
0
0
2
@abumaryamrahmat
Abu Maryam Rahmat
1 year
0
0
0
@abumaryamrahmat
Abu Maryam Rahmat
1 year
0
0
2
@abumaryamrahmat
Abu Maryam Rahmat
1 year
@HackenProof Prayying, go to a park,do a sports and dont waste too munch time for bug bounty
0
0
2
@abumaryamrahmat
Abu Maryam Rahmat
9 months
@GrabID @ovo_id @benihbaik Alhamdulillah uninstall meskipun suka banget pakai GRAB. Bismillah mengurangi dan boikot terhadap pendukung zionis
0
0
2
@abumaryamrahmat
Abu Maryam Rahmat
6 months
@SmashYourTV @ibnGhariba Never heard about islam?? Right now? Never heard? Cmon man
0
0
1
@abumaryamrahmat
Abu Maryam Rahmat
6 months
@roxanamuntian Why not both? Low mechanical keyboard
Tweet media one
0
0
2
@abumaryamrahmat
Abu Maryam Rahmat
3 months
@scriptalert999 @0xfxiii I prefer to test all existing functionality first, after everything is finished then do a recon, for example looking for another subdomain (if the target uses wildcards).
1
0
2
@abumaryamrahmat
Abu Maryam Rahmat
1 year
@im4x7 I've been like that too, read the code and how the app works and then add something to the body parameter and it generates idor.
Tweet media one
1
0
2
@abumaryamrahmat
Abu Maryam Rahmat
1 year
@Blaklis_ if only i was there, you really are a good person
0
0
2
@abumaryamrahmat
Abu Maryam Rahmat
11 months
@SirBagoza ‘’Sending the vuln parameter in other endpoints’’ can you explain this? I don’t get it
1
0
2
@abumaryamrahmat
Abu Maryam Rahmat
8 months
@cadillac_h1 Tiktok, hackerone, LinkedIn
2
0
0
@abumaryamrahmat
Abu Maryam Rahmat
4 months
1
0
2
@abumaryamrahmat
Abu Maryam Rahmat
2 months
@amihewman @anvie Bener bang tapi windows untuk server dibandingan linux untuk server kita udah jelas tau mana yang lebih aman apalagi kebanyakan virus ya targetnya nya untuk windows :)
1
0
2
@abumaryamrahmat
Abu Maryam Rahmat
10 months
@Zigoo0 Israel=real ISIS, attacks to hospital its crazyy
0
0
2
@abumaryamrahmat
Abu Maryam Rahmat
3 months
@x0verloadx @_nnxxrr_ @ssherlock_1 @w_n1rmala Branding dia udh kuat bang, ada kata kata gitu langsung inget siapa wkwkw
0
0
2
@abumaryamrahmat
Abu Maryam Rahmat
10 months
@YoKoAcc MasyaAllah allahumma baariik, semoga bisa kerja di KSA suatu hari :)
1
0
2
@abumaryamrahmat
Abu Maryam Rahmat
10 months
@7odamoo I once found a bypass bug up to 5 times, when the first report was resolved I reported the second bypass, if the second was resolved that day I reported the bypass. So far they have been fair to me
0
0
1
@abumaryamrahmat
Abu Maryam Rahmat
4 months
@RuttalaSurya @Hacker0x01 read a lot of wirteups hehe
1
0
2
@abumaryamrahmat
Abu Maryam Rahmat
1 year
@errorrsec @being__aman I think linkedin bbp has good bounty too
1
0
2
@abumaryamrahmat
Abu Maryam Rahmat
7 months
@seczq Mostly Informative :) depend on the impact
1
0
2
@abumaryamrahmat
Abu Maryam Rahmat
4 months
@MrHamza856298 @xavierjp__ Nah for this case they are wont
1
0
2
@abumaryamrahmat
Abu Maryam Rahmat
3 months
@OneAlphaKing Agree 100
1
0
2
@abumaryamrahmat
Abu Maryam Rahmat
2 months
0
0
2
@abumaryamrahmat
Abu Maryam Rahmat
4 months
@_nnxxrr_ @Hacker0x01 Alhamdulillah bang, rezeki hehe
0
0
2
@abumaryamrahmat
Abu Maryam Rahmat
1 year
@spaceboy2O @mux0x MasyaAllah nice finding bro
1
0
2