A guy who has a love hate relationship with minified JS

Joined February 2022
40 Photos and videos
Pinned Tweet
May 2
New Video Out ๐Ÿ™Œ In this one i explained how hackers use the Dev tools to find client side bugs, and bypass restrictions. And to not only focus on theory, i have used the dev tools live to find 2 vulnerabilities. Hope you guys will enjoy it ๐Ÿซก youtube.com/watch?v=bVL_m0qeโ€ฆ
7
14
130
6,997
May 24
Hackerone's export as pdf Feature is not working, and has not been working for weeks now. So i decided to vibe code a better version of it: github.com/Magn4/A-working-eโ€ฆ
4
1
88
7,009
Magn4 retweeted
So, do you want to do Bug Bounty in Mobile Apps? ๐Ÿ’ฐ๐Ÿ“ฑ ๐Ÿค” Frida maybe a headache with actual modern RASP protections, so I published my personal method to Bypass SSL Pinning on Play Store Android Emulators WITHOUT Frida!๐Ÿ‘‡ #bugbountytips #bugbounty #hacking mfumis.com/posts/bypassing-sโ€ฆ
23
98
5,124
May 12
Craaaazy stuff

9
34
254
17,355
Magn4 retweeted
Had a Self-XSS chain that I struggled to exploit alone, but after some brainstorming and help from @J0R1AN, I was able to successfully exploit it using disk cache here is the writeup medium.com/@spoderx555/escalโ€ฆ
14
60
4,487
Magn4 retweeted
Replying to @Magn4_
2
2
27
4,232
May 6
Its seems like this guy found something that could destroy the internet ๐Ÿคฏ hackerone.com/rcss?type=user
11
6
301
27,881
Magn4 retweeted
Hacking Meetup "Friendly Edition" ๐Ÿ‡ณ๐Ÿ‡ฑ vs ๐Ÿ‡ฉ๐Ÿ‡ช The @Hacker0x01 Club Netherlands and HackerOne Club Germany are teaming up for a cross-club bug bounty competition - inspired by the HackerOne Ambassador World Cup. #BugBounty #Meetup (1/3)
2
1
15
760
Magn4 retweeted
A guide on how to use the most Underrated HACKING TOOL by @Magn4_ video: youtube.com/watch?v=bVL_m0qeโ€ฆ
4
6
95
3,992
2nd MVH in the bag at @Hacker0x01 H1-21 Live Hacking Event in Lisbon ๐Ÿ‡ต๐Ÿ‡น
55
8
551
19,864
Found a very cool CSPT bug where a low privilege user can delete every account in the org the entire org itself with 0 interaction at all๐Ÿ”ฅ Thanks to @Magn4_ for explaining CSPT so well ๐Ÿ‘Œ Need a writeup? Follow me on Medium ๐Ÿ‘‡ mugh33ra.medium.com
3
9
142
5,348
Apr 28
Here is my intended solution for this small challenge. Please let me know if you have any other ones. I have used 2 screenshot, the first one explains what each part of the code does, and the second one shows the solution, and how it goes through the code. I would like to mention that the application that had this CSPT had a pretty strong WAF that blocked all of my path traversal payloads, so to bypass it i had to put it in the hash instead of using the query param as it doesn't reach the WAF and its still read by window.location.href Also, big thanks goes to @garethheyes for the nice code snippets tool (hackvertor.co.uk/snippet)
Apr 24
While looking into an application, i found an interesting piece of code that led to an interesting CSPT. And so i decided to share it as a mini Challenge. To solve this you need to take control over the whole path and query params of the POST request. You can run this code in your dev tools console on a website like example.com (see 2nd screenshot for how a successful exploitation should look like) I am interested in seeing how you guys would approach this, and hopefully learn new techniques. PS: I have changed some small details in this snippet to keep the original code confidential.
4
2
71
5,351
Apr 24
While looking into an application, i found an interesting piece of code that led to an interesting CSPT. And so i decided to share it as a mini Challenge. To solve this you need to take control over the whole path and query params of the POST request. You can run this code in your dev tools console on a website like example.com (see 2nd screenshot for how a successful exploitation should look like) I am interested in seeing how you guys would approach this, and hopefully learn new techniques. PS: I have changed some small details in this snippet to keep the original code confidential.
4
4
128
12,430
Magn4 retweeted
๐Ÿš€ First @intigriti Bug Bounty Meetup Stuttgart was a success! ๐Ÿ‡ฉ๐Ÿ‡ช ๐Ÿ”ฅ great conversations ๐Ÿ”ฅ knowledge sharing ๐Ÿ”ฅ awesome atmosphere ๐Ÿ”ฅ hands-on hacking Huge thanks to everyone who joined ๐Ÿ™Œ Next one coming soon ๐Ÿ‘€
5
5
43
2,807
Apr 14
A good tip for anyone hunting for postMessage vulnerabilities: While testing an app, I found a listener with a weak origin check that handled messages insecurely. The bug was accepted and fixed with a strict origin check. However, while reinvestigating the app, I found a different JS file that took an attacker controllable query param and used it to send the exact same postMessage internally. By adding my payload to that query param, I bypassed the new origin check and got a second bug. Moral of the story: Always look for internal postMessage senders that can act as a proxy. PS: The code below is just an example and is not the exact one I exploited
7
19
184
10,328
Apr 12
In this episode ive shared my small experience in client side hacking, so i hope you guys will enjoy it. And Thank you @SalhiMahdi72759 for the invitation, i had a really good time recording it.
ุญู„ู‚ุฉ ุฌุฏูŠุฏุฉ ู…ู† Hunter Cust ๐ŸŽ™๏ธ๐Ÿ”ฅ ุฃูˆู„ ุฎุทูˆุฉ ู„ูƒ ููŠ ุนุงู„ู… ุตูŠุฏ ุงู„ุซุบุฑุงุช (Client-Side) ุชุจุฏุฃ ู…ู† ู‡ู†ุง ๐Ÿ‘€ ููŠ ู‡ุฐู‡ ุงู„ุญู„ู‚ุฉ: ูƒูŠู ุชุชุนู„ู… Bug Bounty ุจุงู„ุทุฑูŠู‚ุฉ ุงู„ุตุญูŠุญุฉ ุฃุฎุทุงุก ุงู„ู…ุจุชุฏุฆูŠู† ู†ุตุงุฆุญ ุญู‚ูŠู‚ูŠุฉ ู„ู„ุชุทูˆุฑ ุจุณุฑุนุฉ ๐ŸŽ™๏ธ ุงู„ุถูŠู: @Magn4_ ุดุงู‡ุฏ ุงู„ุขู† ๐Ÿ‘‡ youtube.com/watch?v=zdFqr7XLโ€ฆ
4
2
67
3,935
Apr 12
Ok now this makes a lot of sense youtube.com/watch?v=fM7GIIylโ€ฆ

1
1
24
2,407
Apr 10
First and hopefully not last Testimony on @Hacker0x01, This really made my day ๐Ÿ˜๐Ÿ˜๐Ÿ˜
12
2
105
2,925