First Bug Report: HTML Injection Vulnerability 🔍
My first bug bounty report experience — finding an HTML Injection vulnerability on Prudential Financial's website and submitting it through HackerOne.
Category Filter
OWASP Top 10 vulnerabilities, bug bounty write-ups, and ethical hacking insights from real-world experience.
My first bug bounty report experience — finding an HTML Injection vulnerability on Prudential Financial's website and submitting it through HackerOne.
اليوم الأول من مسيرة 30 ثغرة في 30 يوم — نتعلم ازاي نلاقي ونستغل ونحمي من ثغرة Broken Access Control، أخطر ثغرة في OWASP Top 10.
اليوم الثاني — ثغرة Cryptographic Failures أو إخفاقات التشفير. نتعلم ازاي نلاقي البيانات المتخزنة بشكل مكشوف وكيف نحمي المواقع بتشفير صحيح.
اليوم التالت — Injection Attacks من أخطر الثغرات. نتكلم عن SQL Injection وCommand Injection وXSS بأنواعهم وكيفية الاستغلال والحماية.
اليوم الرابع — Insecure Design، لما التطبيق نفسه معمول بطريقة غلط حتى لو الكود صح. Business Logic Flaws وكيفية اكتشافها وتأمينها.
اليوم الخامس — Security Misconfiguration، أكتر الثغرات انتشاراً بسبب أخطاء بشرية بسيطة. Debug mode مفعّل، ملفات .env مكشوفة، وأدوات الفحص.
Contact
Open to cloud engineering positions, infrastructure consulting, and collaborations on automation.