mohammed eldeeb Profile Banner
mohammed eldeeb Profile
mohammed eldeeb

@malcolmx0x

Followers
10,444
Following
706
Media
146
Statuses
994

Bug Bounty Hunter & security engineer

Cairo, Egypt
Joined April 2016
Don't wanna be here? Send us removal request.
Explore trending content on Musk Viewer
Pinned Tweet
@malcolmx0x
mohammed eldeeb
5 years
Huge thanks to @verizonmedia team @BugBountyHQ and for @Hacker0x01 to give such an opportunity New house&new car&wedding in next few months <3 #togetherwehitharder
Tweet media one
45
25
551
@malcolmx0x
mohammed eldeeb
4 years
got an admin access by doing the flowing - fuzzing got an endpoint /auth/github - after login i got nothing - adding the flowing parma to the auth endpoint ?admin=true&org_admin=true - logged in as admin :) #bugbountytips
4
110
421
@malcolmx0x
mohammed eldeeb
5 years
Yay, I was awarded a $30,650 bounty on @Hacker0x01 ! for Various reports #TogetherWeHitHarder
27
12
345
@malcolmx0x
mohammed eldeeb
4 years
How i was able to chain bugs and gain access to internal okta instance #bugbounty
4
93
289
@malcolmx0x
mohammed eldeeb
4 years
Yay, I was awarded a $10,000 bounty on @Hacker0x01 ! for auth bypass allow me to access any user account #TogetherWeHitHarder
9
17
274
@malcolmx0x
mohammed eldeeb
5 months
Always love to drop critical bugs in yahoo #BugBounty
Tweet media one
5
5
217
@malcolmx0x
mohammed eldeeb
2 years
Thanks @Hacker0x01 for the swag #BugBounty
Tweet media one
1
2
199
@malcolmx0x
mohammed eldeeb
4 years
Made it top 20 on all time on @Hacker0x01 💪🔥
Tweet media one
8
5
189
@malcolmx0x
mohammed eldeeb
5 years
host:attacker,com>> blcoked host:attacker,com x-forwarded-host:target,com>>ATO #bugbountytips
7
42
181
@malcolmx0x
mohammed eldeeb
4 years
me and @Zombiehelp54 found a critical LDAP injection on OpenAM check it out! #bugbountytips #bugbountytip
2
46
177
@malcolmx0x
mohammed eldeeb
5 years
Yay, I was awarded a $9,000 bounty on @Hacker0x01 ! #TogetherWeHitHarder
@malcolmx0x
mohammed eldeeb
5 years
Let's go to drop some critical on @Hacker0x01
Tweet media one
4
3
110
5
12
160
@malcolmx0x
mohammed eldeeb
2 years
it was a nice SQLI night thanks @DC3VDP for the reward #HackUS
Tweet media one
9
4
163
@malcolmx0x
mohammed eldeeb
4 years
happy birth day to me, today i made it up to 16k reputation on @Hacker0x01 🔥 #togetherwehitharder
Tweet media one
14
0
157
@malcolmx0x
mohammed eldeeb
1 year
Just did some serious fuzzing and found a /file/ with a 400 status code. Persistence pays off - I kept at it and eventually uncovered a path traversal vulnerability #bugbountytips #BugBounty
Tweet media one
Tweet media two
2
19
158
@malcolmx0x
mohammed eldeeb
3 months
Tweet media one
9
0
161
@malcolmx0x
mohammed eldeeb
3 years
My 0-day accepted from forti , if anyone has a target use fortigate your are vuln with unath bug :) #BugBounty #bugbountytips
Tweet media one
10
16
147
@malcolmx0x
mohammed eldeeb
4 years
SQL injection , is not critical, because attacker must guess the correct values to receive a valid response 🤷‍♂️ @0x4148 شفنا العجب والله
Tweet media one
20
8
144
@malcolmx0x
mohammed eldeeb
2 years
reached 1K valid reports [triaged&resolved] on @Hacker0x01 #bugbounty
Tweet media one
8
4
132
@malcolmx0x
mohammed eldeeb
3 years
want find an easy P1 run gau yourtrget |grep .zip you may find an ZIP FILE contain all the source code or other sensitive backup files #bugbountytips
3
16
125
@malcolmx0x
mohammed eldeeb
2 years
20K reputation club on @Hacker0x01 😎 #BugBounty
Tweet media one
9
0
128
@malcolmx0x
mohammed eldeeb
4 years
keep in mind that SQLI may work only on HTTP , if https i was getting error , just found a sqli on a public program #bugbountytips
3
13
120
@malcolmx0x
mohammed eldeeb
2 years
Trivy v0.31 open-source security scanner. It can scan various targets (AWS,filesystems, containers, git repositories and more) #Cloud
Tweet media one
3
33
118
@malcolmx0x
mohammed eldeeb
1 year
manipulating specific unkeyed inputs>>force the caching system to cache a response #bugbountytips #ittakesacrowd
Tweet media one
1
9
116
@malcolmx0x
mohammed eldeeb
5 years
i got 2,250 bounty at @Hacker0x01 for 1. stored xss 2. Auth bypass and access into internal instance #TogetherWeHitHarder
3
3
108
@malcolmx0x
mohammed eldeeb
5 months
24k club on @Hacker0x01 😎
Tweet media one
5
0
112
@malcolmx0x
mohammed eldeeb
3 years
i was testing a subdomain didn't find anything , after a while i just changed the "cookie id" which was the value of username to another username and authbypass 🤷‍♂️
5
7
109
@malcolmx0x
mohammed eldeeb
5 years
Let's go to drop some critical on @Hacker0x01
Tweet media one
4
3
110
@malcolmx0x
mohammed eldeeb
4 years
17k club @Hacker0x01 😎
Tweet media one
4
0
107
@malcolmx0x
mohammed eldeeb
11 months
23K Reputation club @Hacker0x01
Tweet media one
5
0
109
@malcolmx0x
mohammed eldeeb
3 years
Just got a CVE number for my fortigate 0day will add a @pdnuclei temp for it
Tweet media one
6
12
107
@malcolmx0x
mohammed eldeeb
3 years
18K club on @Hacker0x01 😎 any swag @luketucker 🤷
Tweet media one
4
1
106
@malcolmx0x
mohammed eldeeb
5 years
Yay, I was awarded a $500 bounty on @Hacker0x01 ! for subdomain takeover reported in 11:45 triaged and rewarded in 12:10 #TogetherWeHitHarder
4
3
102
@malcolmx0x
mohammed eldeeb
1 year
Tweet media one
8
1
107
@malcolmx0x
mohammed eldeeb
5 years
Yay, I was awarded a $1,700 bounty on @Hacker0x01 ! for auth bypass through Github allow access internal instace #TogetherWeHitHarder
1
5
103
@malcolmx0x
mohammed eldeeb
5 years
Yay, I was awarded a $2,500 bounty on @Hacker0x01 ! for RCE and database access #TogetherWeHitHarder
7
2
103
@malcolmx0x
mohammed eldeeb
5 years
Yay, I was awarded a $1,000 bounty on @Hacker0x01 ! as Initial Bounty for (IDOR,SQLI&admin access) #TogetherWeHitHarder
2
2
103
@malcolmx0x
mohammed eldeeb
1 year
reported,triaged,rewarded & fixed in one day @Bugcrowd #BugBounty #bugbountytips
Tweet media one
4
0
104
@malcolmx0x
mohammed eldeeb
3 years
was hacking on a subdomain redirect to SSO login the portal was for admin uploading docs ,start brute force the dir for a week nothing worked,i put the sub name after / and brute forced again ended up accessing the portal and see all docs 🤷‍♂️
3
14
95
@malcolmx0x
mohammed eldeeb
4 months
Just hacked Proofpoint with a critical vulnerability, Affecting multiple Big tech companies, Patch ASAP
Tweet media one
4
4
98
@malcolmx0x
mohammed eldeeb
6 years
six hundred vulnerabilities found in @Hacker0x01 #TogetherWeHitHarder
Tweet media one
12
1
93
@malcolmx0x
mohammed eldeeb
5 years
after getting some rewards 😂 #bugbounty
1
15
91
@malcolmx0x
mohammed eldeeb
3 years
first one on @SynackRedTeam
Tweet media one
7
1
93
@malcolmx0x
mohammed eldeeb
4 years
can't imagine when this being reported through H1 triage team! the severity is low 😂🤷‍♂️
@LaxmanMuthiyah
Laxman Muthiyah
4 years
Microsoft Account Takeover! 😊😇 Thank you very much @msftsecresponse for the bounty! 🙏🙏🙏 Write up -
Tweet media one
73
414
2K
6
5
93
@malcolmx0x
mohammed eldeeb
1 year
want to share interesting authentication bypass we have found recently 1. the app redirect users to SSO login page 2. read all javascript files we have found endpoint `/SessionStorage.aspx?USER_ID=` add user_id=1 (1)
1
20
93
@malcolmx0x
mohammed eldeeb
4 years
your target is using jfrog ? you can access it with anonymous login through .io use dork site: inurl:yourtarget and easy access it :) #BugBounty #bugbountytips
4
24
92
@malcolmx0x
mohammed eldeeb
4 years
special day with @Hacker0x01 today i sent my 2020 report 🔥 #togetherwehitharder
Tweet media one
6
0
88
@malcolmx0x
mohammed eldeeb
6 years
just joined to the 10k club on @Hacker0x01 💪
Tweet media one
15
1
87
@malcolmx0x
mohammed eldeeb
2 years
thanks apple team for the reward 🤘 #BugBounty
Tweet media one
6
3
86
@malcolmx0x
mohammed eldeeb
5 years
13k club @Hacker0x01 🔥😎
Tweet media one
3
0
78
@malcolmx0x
mohammed eldeeb
5 years
when you want to make 10k on your birthday but your bad luck comes out 🤦‍♂️🙅‍♀️
Tweet media one
11
0
78
@malcolmx0x
mohammed eldeeb
5 years
Yay, I was awarded a $400 bounty on @Hacker0x01 ! for access grafana instance #TogetherWeHitHarder
1
3
76
@malcolmx0x
mohammed eldeeb
7 years
I found my first critical vulnerability in 2018 @Hacker0x01 after reading&using @NahamSec RECON #TogetherWeHitHarder
3
2
79
@malcolmx0x
mohammed eldeeb
2 years
6 years ago 1k repitation on @Hacker0x01 #BugBounty
Tweet media one
1
0
77
@malcolmx0x
mohammed eldeeb
2 years
after @Blackhatmea I've picked up a target from @synack ended up with command injection ✌️ #BugBounty
Tweet media one
2
2
74
@malcolmx0x
mohammed eldeeb
4 years
one red notification is able to change your life, this @Hacker0x01
1
2
70
@malcolmx0x
mohammed eldeeb
1 year
Thanks @SynackRedTeam @synack For the swag 😎
Tweet media one
4
0
69
@malcolmx0x
mohammed eldeeb
5 years
wooho 12k club on @Hacker0x01
Tweet media one
2
0
68
@malcolmx0x
mohammed eldeeb
1 year
found multiple cache poisoning vulnerabilities with @VulnVision
Tweet media one
5
2
64
@malcolmx0x
mohammed eldeeb
4 years
really using @SpyseHQ is cool with such big org scope , you can get all related hosts, IPv4, IP CVE list...etc #BugBounty #bugbountytips
Tweet media one
2
13
62
@malcolmx0x
mohammed eldeeb
7 years
In November, I submitted 181 vulnerabilities to 10 programs on @Hacker0x01 (gained 1097 rep). #TogetherWeHitHarder
7
1
59
@malcolmx0x
mohammed eldeeb
1 year
after the new feature from @Hacker0x01 , you see most of your valid bugs were closed as duplicated to "informative" reports 💁‍♂️
Tweet media one
7
3
63
@malcolmx0x
mohammed eldeeb
6 years
need help in bypassing open redirect? read my new write up #BugBounty
0
22
57
@malcolmx0x
mohammed eldeeb
1 year
This month has been a real challenge with almost no free time.I can confidently say March was one of the most productive periods for me in terms of finding critical vulnerabilities. #BugBounty #bugbountytips
Tweet media one
Tweet media two
2
2
60
@malcolmx0x
mohammed eldeeb
4 years
In July, I submitted 63 vulnerabilities to 18 programs on @Hacker0x01 . #TogetherWeHitHarder
4
0
59
@malcolmx0x
mohammed eldeeb
1 year
what else 🥲
Tweet media one
4
1
57
@malcolmx0x
mohammed eldeeb
4 years
i want my reports get paid @Hacker0x01
Tweet media one
2
0
54
@malcolmx0x
mohammed eldeeb
1 year
I have been awarded the "Hero" recognition by @SynackRedTeam this year! This prestigious award is given to SRTs who generate significant value, as determined by overall production and customer impact.
Tweet media one
3
1
55
@malcolmx0x
mohammed eldeeb
5 years
This How zombie look like when he stuck in the cinema all night for endgame movie @Zombiehelp54 😂
Tweet media one
4
0
54
@malcolmx0x
mohammed eldeeb
4 years
finally got a nice catch from google
Tweet media one
1
0
53
@malcolmx0x
mohammed eldeeb
6 years
babies in @Hacker0x01 😂
Tweet media one
4
1
54
@malcolmx0x
mohammed eldeeb
7 years
On this day last year i got email from @Hacker0x01 congrats me about 1k reputation today i make it up to 5k+ reputation
Tweet media one
Tweet media two
6
0
55
@malcolmx0x
mohammed eldeeb
6 years
five hundred bugs found through @Hacker0x01 #TogetherWeHitHarder
Tweet media one
4
1
52
@malcolmx0x
mohammed eldeeb
2 years
got some time off from doing pentesting , here we go @SynackRedTeam #bugbounty
Tweet media one
5
0
51
@malcolmx0x
mohammed eldeeb
3 years
keep reading the PDF files of your target ,might ended up see all admin panel data 🤷‍♂️
Tweet media one
0
0
47
@malcolmx0x
mohammed eldeeb
6 years
Tweet media one
Tweet media two
1
0
45
@malcolmx0x
mohammed eldeeb
6 years
In February, I submitted 50 vulnerabilities to 14 programs on @Hacker0x01 . #TogetherWeHitHarder
2
0
48
@malcolmx0x
mohammed eldeeb
5 years
Yay, I was awarded a $250 bounty on @Hacker0x01 ! for a  Privilege Escalation bug #TogetherWeHitHarder
2
1
46
@malcolmx0x
mohammed eldeeb
3 years
yeah it has been a while 🤷‍♂️
Tweet media one
1
1
49
@malcolmx0x
mohammed eldeeb
4 years
what we can say customer always right, right? @Hacker0x01 🤷‍♂️
Tweet media one
Tweet media two
2
2
48
@malcolmx0x
mohammed eldeeb
3 years
open @Hacker0x01 select beach and start hacking
Tweet media one
2
0
46
@malcolmx0x
mohammed eldeeb
4 years
that's what happen when we report critical bugs on @Hacker0x01 #togetherwehitharder
Tweet media one
3
0
45
@malcolmx0x
mohammed eldeeb
4 years
Whatever is good for your soul, do that
Tweet media one
1
0
43
@malcolmx0x
mohammed eldeeb
7 years
Hi all, here is write up about open redirect i got
1
13
42
@malcolmx0x
mohammed eldeeb
2 years
Tweet media one
2
0
45
@malcolmx0x
mohammed eldeeb
1 year
found this today , was able to bypass the authentication using Username: test, Password: admin123 #BugBounty #bugbountytips
Tweet media one
0
3
42