Mr_Tester999
COMMUNITY PROFILE

Muhammed Mubarak

@Mr_Tester999 ✓ VERIFIED ADMIN

160 points 0 CTF solves 13 public posts

🛡️ Bug Bounty Hunter | Security Researcher

Cybersecurity researcher focused on discovering real-world security vulnerabilities across Web Applications, APIs, Networks, and Source Code.

⚡ Skills

  • 🌐 Web Application Penetration Testing
  • 🔌 API Security Testing
  • 🔐 Authentication & Authorization
  • 🧩 Business Logic Vulnerabilities
  • 🔍 Source Code Review
  • 🌍 Network Security
  • 🐍 Python & Security Automation
  • 🐧 Linux
  • 🧪 Vulnerability Research
  • 🎯 Bug Bounty Hunting
Recent public posts
13 total
Sep 23, 2025 · 10:53 AM · UTC · UTC+00:00

Professional Bug Testing Guide P4 version 2

Failure to Invalidate Session After Password Change Description When a user updates their password, all previously issued sessions should be invalidated. If this is not enforced, …

Read post →
Sep 23, 2025 · 10:47 AM · UTC · UTC+00:00

Bug Testing Guide P4 issues

1️⃣ Failure to Invalidate Session After Password Change Description When a user changes their password, old sessions should be invalidated to prevent an attacker with a stolen ses…

Read post →
Apr 07, 2025 · 10:54 AM · UTC · UTC+00:00

XSS Bypass Sucuri WAF

[XSS] %22%3E%3Ca%20%20fooooooooooooooooooohref%20h%22r%22+%22%22;%20fooooooooooooooooooohref%20data-=%22%22href=jAvAsCrIpT%3Aconfirm`1`%3ECLICK%3C/a%3E if You Still Blocked You Ca…

Read post →
Dec 05, 2024 · 07:08 PM · UTC · UTC+00:00

Steps to Reproduce: Dependency Confusion in Node.js

1. Identify an Unclaimed Dependency Locate the target project’s package.json file and identify unclaimed dependencies. Example: The project references noderedactedsdk, which is no…

Read post →
Sep 28, 2024 · 06:08 AM · UTC · UTC+00:00

Elementor < 3.5.6 - DOM Reflected Cross-Site Scripting

Description The plugin does not sanitize and escape user input appended to the DOM via malicious Lightbox settings, resulting in a DOM Cross-Site Scripting issue. Proof of Concept…

Read post →
Sep 23, 2024 · 08:16 PM · UTC · UTC+00:00

API Testing Methodology

1. Information Gathering Start by gathering API details like documentation and authentication methods. Example Request: GET /api/v1/docs 2. Authentication Testing Check if the API…

Read post →
Sep 20, 2024 · 10:28 PM · UTC · UTC+00:00

OAuth Misconfiguration Scenarios with HTTP Request/Response Examples

1. Insufficient Token Expiry Hacker's Steps: The hacker steals the victim’s access token through some means (e.g., XSS, phishing, session hijacking). After a long period, the hack…

Read post →
Jun 24, 2024 · 09:19 PM · UTC · UTC+00:00

Converting Self XSS to Non-Self XSS for a $$$ Bounty

Overview: This report details how I upgraded the severity of a self XSS vulnerability to a non-self XSS via CSRF, changing its status from P5 to P3. Initial Discovery: Self XSS Id…

Read post →
Jun 24, 2024 · 06:14 PM · UTC · UTC+00:00

Information Disclosure Leading to a $$$ Bounty in 30 Minutes

Overview: This report describes how I discovered an information disclosure vulnerability that earned me a bounty in just 30 minutes. Steps to Discovery: Collecting Subdomains: I b…

Read post →
Jun 24, 2024 · 04:49 PM · UTC · UTC+00:00

Discovering XSS via Triple URL Encoding

Overview: This report outlines the process I used to discover an XSS vulnerability through triple URL encoding, which successfully bypassed the Web Application Firewall (WAF). Ste…

Read post →
Jun 24, 2024 · 04:28 PM · UTC · UTC+00:00

Cross-Site Scripting (XSS) module HTB Acdemy CBBH Path

Hello, XSS Module I am Muhammad, finished this path CBBH. This path is very useful for anyone who wants to enter the bug bounty field. I will explain this path on my site here tod…

Read post →
Jun 24, 2024 · 04:27 PM · UTC · UTC+00:00

Hacking with FFuf Recon

Subdomain Enumeration using FFUF To perform subdomain enumeration using FFuF, we will use the -w and -u options. -w: Specifies the subdomains word list. -u: Specifies the target. …

Read post →
Jun 24, 2024 · 04:24 PM · UTC · UTC+00:00

How To Hunt on Login Page

No Rate Limit on login Function (P4 - Low) How To Test: Visit the login endpoint. Enter any username and password. Intercept the request and send it to the Intruder tab. Select nu…

Read post →