Security researcher hunting zero-days & breaking systems to build better ones. Top 2% @TryHackMe. I post real-world vulns, red team ops, and cyber awareness.

Hydrabad
Mohammad Mudassir retweeted
Just like we have SQLi and blind SQLi, we also have XXE injection and blind XXE injection. Sometimes, you find a XXE injection that does not reflect the entity value in the response, but there are still ways to exfiltrate data. Learn here 👇 portswigger.net/web-security…
4
23
194
8,023
Mohammad Mudassir retweeted
Did you know you could bypass filters by "jumping" over characters? The solution to Highscore, is out! 💡 See how a mismatch between JavaScript string length and UTF-8 bytes can bypass character checks! 👀 Read the full write-up 👇 yeswehack.com/dojo/dojo-chal…
5
28
1,895
Mohammad Mudassir retweeted
Can you get RCE? 😎
12
10
282
23,886
Mohammad Mudassir retweeted
what's stopping you from hacking like this?
51
15
384
13,987
Mohammad Mudassir retweeted
How much automation do you need to reach the top of a #BugBounty leaderboard? 🤖 Less than you might think 👀 In our latest interview, our all-time #1 hunter @Issam_Rabhi shares his methodology, best finds, favourite vulns & tips for hackers 👇 yeswehack.com/community/auto…
2
8
113
5,104
Mohammad Mudassir retweeted
We just dove into our shelf of archived bug bounty write-ups from the most notable hackers! 🤠 In this issue, we selected 5 compelling articles (that are still relevant today) to share with you, from which you can learn something new! 😎 🧵 👇
1
11
97
7,314
Mohammad Mudassir retweeted
What is considered “Personal Data”? 🤔 It’s important to know this distinction if you’re hunting for information disclosure bugs. Here’s a quick explainer: 👇
3
3
46
7,538
Mohammad Mudassir retweeted
can you spot the security flaw? 👀
12
1
71
8,487
Mohammad Mudassir retweeted
Hackers asked for a third edition of The Web Hacker’s Handbook. Rather than releasing another book which will quickly get out-dated, we created the Web Security Academy, a living, constantly updated learning hub with hands-on labs and video walk-throughs so you can learn by doing, not just reading. portswigger.net/web-security…
1
26
276
11,017
Mohammad Mudassir retweeted
01100001 01100100 01101101 01101001 01101110 00111010 01100001 01100100 01101101 01101001 01101110
17
2
55
8,317
Mohammad Mudassir retweeted
Anthropic has released a 154-page report describing how bad actors used its Claude AI system for state-sponsored surveillance, propaganda operations and more. u.afp.com/SjAQ
7
135
179
36,487
Mohammad Mudassir retweeted
Think before you Buy the New iPhone Duo! ⚠️
686
3,150
21,038
979,055
Mohammad Mudassir retweeted
Python is a great first programming language, especially when you learn it by building projects. In this course, Treasure walks you through coding an expense splitter, word scramble game, and karaoke queue manager. You'll practice using variables, conditionals, loops, functions, input validation, and error handling. freecodecamp.org/news/learn-…
7
105
781
42,429
Mohammad Mudassir retweeted
Anthropic says it has shut down multiple cases of state-sponsored surveillance operations that used its AI models. It warns governments and state-aligned actors are increasingly using AI to spy on ethnic minorities and dissidents u.afp.com/SjYs
8
126
151
29,620
Mohammad Mudassir retweeted
Anthropic Says It Blocked Possible Biological Weapons Undertaking go.forbes.com/cc7YAO
23
69
240
82,680
Mohammad Mudassir retweeted
ChatGPT Images 2.5—faster, sharper, smarter, with better tools for creating whatever you can dream of. - Faster image generation to keep your ideas flowing - Improved fidelity for more natural, recognizable images - Consistent details across multiple edits - Comment-based edits to change only what you want
938
2,565
23,750
8,129,369
Mohammad Mudassir retweeted
Rookie hunters: skip the recon scripts at first. Just use the target app like a regular user. Say your target is an e-commerce webapp. Create a real account, complete a product checkout, and note every API call. You'll find endpoints and parameters that an automated crawler misses. ➡️ Record the entire flow with a proxy tool running in the background. ➡️ Note which parameters are incremental (userId, orderId). ➡️ Change IDs, replay requests in a different sequence, skip steps. Try the same checklist on a login flow, a password reset, or a multi-step form. Go find that P1. 💰
5
16
150
10,148