Muhammed Mubarak
@Mr_Tester999 ✓ VERIFIED ADMIN
🛡️ Bug Bounty Hunter | Security Researcher
Cybersecurity researcher focused on discovering real-world security vulnerabilities across Web Applications, APIs, Networks, and Source Code.
⚡ Skills
- 🌐 Web Application Penetration Testing
- 🔌 API Security Testing
- 🔐 Authentication & Authorization
- 🧩 Business Logic Vulnerabilities
- 🔍 Source Code Review
- 🌍 Network Security
- 🐍 Python & Security Automation
- 🐧 Linux
- 🧪 Vulnerability Research
- 🎯 Bug Bounty Hunting
Professional Bug Testing Guide P4 version 2
Failure to Invalidate Session After Password Change Description When a user updates their password, all previously issued sessions should be invalidated. If this is not enforced, …
Read post → Sep 23, 2025 · 10:47 AM · UTC · UTC+00:00Bug Testing Guide P4 issues
1️⃣ Failure to Invalidate Session After Password Change Description When a user changes their password, old sessions should be invalidated to prevent an attacker with a stolen ses…
Read post → Apr 07, 2025 · 10:54 AM · UTC · UTC+00:00XSS Bypass Sucuri WAF
[XSS] %22%3E%3Ca%20%20fooooooooooooooooooohref%20h%22r%22+%22%22;%20fooooooooooooooooooohref%20data-=%22%22href=jAvAsCrIpT%3Aconfirm`1`%3ECLICK%3C/a%3E if You Still Blocked You Ca…
Read post → Dec 05, 2024 · 07:08 PM · UTC · UTC+00:00Steps to Reproduce: Dependency Confusion in Node.js
1. Identify an Unclaimed Dependency Locate the target project’s package.json file and identify unclaimed dependencies. Example: The project references noderedactedsdk, which is no…
Read post → Sep 28, 2024 · 06:08 AM · UTC · UTC+00:00Elementor < 3.5.6 - DOM Reflected Cross-Site Scripting
Description The plugin does not sanitize and escape user input appended to the DOM via malicious Lightbox settings, resulting in a DOM Cross-Site Scripting issue. Proof of Concept…
Read post → Sep 23, 2024 · 08:16 PM · UTC · UTC+00:00API Testing Methodology
1. Information Gathering Start by gathering API details like documentation and authentication methods. Example Request: GET /api/v1/docs 2. Authentication Testing Check if the API…
Read post → Sep 20, 2024 · 10:28 PM · UTC · UTC+00:00OAuth Misconfiguration Scenarios with HTTP Request/Response Examples
1. Insufficient Token Expiry Hacker's Steps: The hacker steals the victim’s access token through some means (e.g., XSS, phishing, session hijacking). After a long period, the hack…
Read post → Jun 24, 2024 · 09:19 PM · UTC · UTC+00:00Converting Self XSS to Non-Self XSS for a $$$ Bounty
Overview: This report details how I upgraded the severity of a self XSS vulnerability to a non-self XSS via CSRF, changing its status from P5 to P3. Initial Discovery: Self XSS Id…
Read post → Jun 24, 2024 · 06:14 PM · UTC · UTC+00:00Information Disclosure Leading to a $$$ Bounty in 30 Minutes
Overview: This report describes how I discovered an information disclosure vulnerability that earned me a bounty in just 30 minutes. Steps to Discovery: Collecting Subdomains: I b…
Read post → Jun 24, 2024 · 04:49 PM · UTC · UTC+00:00Discovering XSS via Triple URL Encoding
Overview: This report outlines the process I used to discover an XSS vulnerability through triple URL encoding, which successfully bypassed the Web Application Firewall (WAF). Ste…
Read post → Jun 24, 2024 · 04:28 PM · UTC · UTC+00:00Cross-Site Scripting (XSS) module HTB Acdemy CBBH Path
Hello, XSS Module I am Muhammad, finished this path CBBH. This path is very useful for anyone who wants to enter the bug bounty field. I will explain this path on my site here tod…
Read post → Jun 24, 2024 · 04:27 PM · UTC · UTC+00:00Hacking with FFuf Recon
Subdomain Enumeration using FFUF To perform subdomain enumeration using FFuF, we will use the -w and -u options. -w: Specifies the subdomains word list. -u: Specifies the target. …
Read post → Jun 24, 2024 · 04:24 PM · UTC · UTC+00:00How To Hunt on Login Page
No Rate Limit on login Function (P4 - Low) How To Test: Visit the login endpoint. Enter any username and password. Intercept the request and send it to the Intruder tab. Select nu…
Read post →