Cofounder @hackinghub_io | Advisor @CaidoIO. I hack companies and make content about it. #NahamCon organizer. ex @hacker0x01๐Ÿ‡ฎ๐Ÿ‡ท

Joined January 2014
1,842 Photos and videos
Ben Sadeghipour retweeted
Found a lame P4 open redirect a while back and instantly remembered that chaining video you dropped, turned that shit into a clean P1 takeover. Seeing you chain 5 broken access controls into $30k is crazy. Saving this one for sure. Keep killing it @NahamSec! ๐Ÿ™Œ๐Ÿฝ
I've made $30,000 from ONE bug class on a single program: broken access control. Not by spamming lows by chaining them. New vid: 5 BAC bugs โ†’ 1 full account takeover, live. And I built a free lab on @HackingHub so you can follow along. youtu.be/6v3B3FxDHbo
3
25
2,103
Ben Sadeghipour retweeted
If you aren't following all of Ben's content, you are making a mistake. Especially if you are still learning and want to learn awesome new tips and tricks
I've made $30,000 from ONE bug class on a single program: broken access control. Not by spamming lows by chaining them. New vid: 5 BAC bugs โ†’ 1 full account takeover, live. And I built a free lab on @HackingHub so you can follow along. youtu.be/6v3B3FxDHbo
7
12
158
10,364
I've made $30,000 from ONE bug class on a single program: broken access control. Not by spamming lows by chaining them. New vid: 5 BAC bugs โ†’ 1 full account takeover, live. And I built a free lab on @HackingHub so you can follow along. youtu.be/6v3B3FxDHbo
1
28
304
21,259
Ben Sadeghipour retweeted
One of the best AI hackers I know! @p1njc70r
This Hacker Made $7,000 Hacking AI With One Email youtu.be/3oARlXLiySw
1
3
32
5,872
Ben Sadeghipour retweeted
Be sure to watch the video
This Hacker Made $7,000 Hacking AI With One Email youtu.be/3oARlXLiySw
2
7
3,705
This Hacker Made $7,000 Hacking AI With One Email youtu.be/3oARlXLiySw
4
15
150
24,618
Ben Sadeghipour retweeted
When you send two values for the same parameter, different server stacks resolve it differently. PHP/mod_wsgi takes the last value. Node/Express gives an array. Python/Zope returns all as a list.ย  This inconsistency can sometimes bypass authz checks.
2
3
55
7,194
Shout out to @Bugcrowd for hosting an awesome event and a bigger shout out to these legends for making it so memorable. @sw33tLie, @bsysop, 0xmoose, @gr3pme.
9
4
181
19,363
Also shout out to Tatiana for going above and beyond. ๐Ÿ˜ญ Made everything so much easier and enjoyable!
3
18
3,675
If you haven't watched ep. 162 yet, we talked with @senorarroz from @Hacker0x01 and here are the most important questions and answers: 1. Are they training AI models on researcher reports? (8:50) No. The part of their ToS that mentions AI training was written a long time ago, back when "AI" just meant basic spam filters not the LLMs we have today. They are not using bug bounty reports to train or improve any large language model. They admitted they should have updated the ToS language sooner to make this clear, and they are working on it. 2. What about the new agentic pentest platform, where is its "exploit intelligence" coming from? (29:25) Not from bug bounty reports. The platform was trained using public benchmarks, internal test apps they built themselves, public CVEs, and pentest sessions where both the pentester and the client agreed to share the data. The only indirect overlap with bug bounty is that some CVEs originally came from BB submissions, but that's it. 3. Do researchers actually own their reports? (18:45) Yes. According to Section 8 of H1's community terms, you keep the intellectual property. You give H1 a limited license to run the platform, and the customer a slightly broader license to fix their own vulnerabilities. The real risk of your techniques leaking is on the customer side, through CVE advisories, internal security teams, or threat intel sharing. That's where things tend to get out. 4. Why did they cut bounties? (41:59) They changed how they benchmark their own program. Before, they were comparing themselves to Google, Meta, and Amazon. Now they're comparing to "high-growth tech companies" and targeting the 80th percentile instead of the top 1%. The biggest cuts were on lows and mediums, but highs dropped from $12,500 to $7,000 and crits from $25,000 to $15,000. They said they're watching engagement closely and will adjust if needed. Justin pushed back hard on this, cutting high and crit payouts sends a bad signal to the whole industry, not just H1's own program. They said they're going to take a second look at it. 5. If you think your techniques were leaked or fed into an AI, how do you report it? (21:28) Use the mediation button on the specific report. For something more serious, email their legal or privacy team directly. They also said they're setting up a dedicated tip line for exactly this kind of concern, it's not live yet but it's on their list. --- One last thing. Everything you just read came from a live, unscripted interview. No questions were shared in advance, nothing was edited after, Alex answered on the record. Watch the full interview: youtu.be/Pa4wWv_ONjM
3
1
52
7,085
I found a $3,000 bug in an AI chatbot using prompt injection. Video ๐Ÿ‘‰๐Ÿผyoutu.be/Q6hQlM6f6Cs Lab ๐Ÿ‘‰๐Ÿผ app.hackinghub.io/hubs/shopmโ€ฆ
2
34
379
13,939
Super excited to release our latest Broken Access Control (BAC) Masterclass on @hackinghub_io with 2 hours of content and almost 20 labs. I'm giving away 3 free seats to anyone who comments, reposts, and replies to this post. Drop a ๐Ÿ”ฅ below! More info ๐Ÿ‘‰๐Ÿผ hhub.io/BAC2026
168
142
376
18,995
If you want to skip the giveaway and get it on your own, it's currently $19 instead of our regular $39! ๐Ÿ‘‰๐Ÿผ hhub.io/BAC2026
13
2,565
Replying to @hackinghub_io
Winners announced on Friday!
1
14
1,989
Ben Sadeghipour retweeted
Mark your calendars. We have a surprise coming this Friday ๐Ÿ”ฆ
3
7
32
3,173
Your AI coding assistant can be turned into a worm. Hidden in a README file, a prompt injection can hijack your coding agents and spread from respository to repository like the old school MySpace XSS Worm. youtu.be/4PBD-9IG13I
2
17
127
7,724
Ben Sadeghipour retweeted
I also talk about this on @NahamSec's "Becoming an AI Hacker" episode #4: youtube.com/watch?v=_3TfHEfVโ€ฆ

1
1
15
6,046
Ben Sadeghipour retweeted
Super excited to have @NahamSec taking the stage as our keynote speaker at BSides Nashville 2026! ๐Ÿค  If youโ€™ve been thinking about coming, nowโ€™s the time to lock in your ticket ๐ŸŽŸ๏ธ๐Ÿ”ฅ Tickets: eventbrite.com/e/18256236625โ€ฆ #BSidesNashville2026
1
7
16
4,150