admin_Secone4all
COMMUNITY PROFILE

Muhammed Mubarak

@admin_Secone4all✓ VERIFIED ADMIN

Hacker

150 points0 CTF solves10 public posts
Recent public posts
10 total
Apr 07, 2025

XSS Bypass Sucuri WAF

[XSS] %22%3E%3Ca%20%20fooooooooooooooooooohref%20h%22r%22+%22%22;%20fooooooooooooooooooohref%20data-=%22%22href=jAvAsCrIpT%3Aconfirm`1`%3ECLICK%3C/a%3E if You Still Blocked You Ca…

Read post →
Sep 28, 2024

Elementor < 3.5.6 - DOM Reflected Cross-Site Scripting

Description The plugin does not sanitize and escape user input appended to the DOM via malicious Lightbox settings, resulting in a DOM Cross-Site Scripting issue. Proof of Concept…

Read post →
Sep 23, 2024

API Testing Methodology

1. Information Gathering Start by gathering API details like documentation and authentication methods. Example Request: GET /api/v1/docs 2. Authentication Testing Check if the API…

Read post →
Sep 20, 2024

OAuth Misconfiguration Scenarios with HTTP Request/Response Examples

1. Insufficient Token Expiry Hacker's Steps: The hacker steals the victim’s access token through some means (e.g., XSS, phishing, session hijacking). After a long period, the hack…

Read post →
Jun 24, 2024

Converting Self XSS to Non-Self XSS for a $$$ Bounty

Overview: This report details how I upgraded the severity of a self XSS vulnerability to a non-self XSS via CSRF, changing its status from P5 to P3. Initial Discovery: Self XSS Id…

Read post →
Jun 24, 2024

Information Disclosure Leading to a $$$ Bounty in 30 Minutes

Overview: This report describes how I discovered an information disclosure vulnerability that earned me a bounty in just 30 minutes. Steps to Discovery: Collecting Subdomains: I b…

Read post →