Open in app

Sign in

Write

Sign in

NoorHomaid
NoorHomaid

128 Followers

Home

About

Oct 27

Open redirect & rXSS via profile image

Hello hackers, In this article, I will demonstrate how I found an open redirect by uploading an SVG image as a profile avatar. Let’s dive in. For such a vulnerability, we would want to create an account on the target first. Then, we will go to the profile and see if…

Bug Bounty

2 min read

Open redirect & rXSS via profile image
Open redirect & rXSS via profile image
Bug Bounty

2 min read


Oct 15

Apache HTTP Server /server-status information disclosure

Hello everyone, This is a short article to pinpoint a recent finding I have discovered in many targets. TBH, it’s an easy one that can be leveraged during recon and info gathering. However, I did not know about it until I found it lately. During the “fuzzing” process I found…

Bug Bounty

2 min read

Apache HTTP Server /server-status information disclosure
Apache HTTP Server /server-status information disclosure
Bug Bounty

2 min read


Sep 26

SQLi via API

Hello there, This is one of the recent things I learned for API injection. In fact, SQLi is one of the most common API security vulnerabilities. Honestly, I wasn’t giving APIs and attention in testing before. So here I am exploring and sharing this piece of knowledge. 1-Fuzzing You might be…

Web Security

2 min read

SQLi via API
SQLi via API
Web Security

2 min read


Sep 14

Looking for graduation project ideas?

هذا المقال سيكون باللغة العربية للطلاب والطالبات الذين يبحثون عن مصادر ممتازة لأفكار مشاريع التخرج (العملية/التطبيقية) في مجال علوم الحاسب والأمن السيبراني. من المهم جدًا البحث عن مصادر جيدة لاستلهام فكرة ذات قيمة وفائدة في المجال. ساطرح لكم في هذا المقال بعض المصادر التي يمكن الاستفادة منها للحصول على افكار…

2 min read

Looking for graduation project ideas?
Looking for graduation project ideas?

2 min read


Aug 30

From P4 to P3 using one additional step

Hello there! In this write-up, I will go through my recent P3. As you know, some platforms do not accept open redirect vulnerability and consider it out of scope. However, in some cases, you can upgrade the open redirect to XSS or other significant vulnerabilities. Started with waybackurls and greb for…

Cybersecurity

2 min read

From P4 to P3 using one additional step
From P4 to P3 using one additional step
Cybersecurity

2 min read


Aug 13

Sensitive Information Leakage via Log File

Hey there! It’s been a while since I published on Medium… In this article, I will introduce you to my steps in finding a “Sensitive Information leak via Log File” in one of the programs I worked on recently. I am not allowed to disclose the program name, so for…

Cybersecurity

2 min read

Sensitive Information Leakage via Log File
Sensitive Information Leakage via Log File
Cybersecurity

2 min read


Jul 9

My Top fav Google Dorks for web security testing

Hello folks In this short article, I will list the top favorite Google dorks I have been using on web penetration testing and they got me some awesome results and juicy endpoints. Introduction Google Dorks are very useful in the recon phase. Not only they are good in recon, but they…

Google

2 min read

My Top fav Google Dorks for web security testing
My Top fav Google Dorks for web security testing
Google

2 min read


Jun 30

My experience with CompTIA Cybersecurity Analyst (CySA+) 2023

Three months ago, I passed The CompTIA Cybersecurity Analyst (CySA+) certification exam CS0–002. Here, I will answer the most common question regarding the exam for those who are interested in taking it. I will go through the common questions from a specialized/technical perspective rather than the general info (e.g. price…

Cybersecurity

3 min read

My experience with CompTIA Cybersecurity Analyst (CySA+) 2023
My experience with CompTIA Cybersecurity Analyst (CySA+) 2023
Cybersecurity

3 min read

NoorHomaid

NoorHomaid

128 Followers

BS in cybersecurity . PenTester . Web security researcher

Following
  • r3aper__

    r3aper__

  • Gavin Kramer

    Gavin Kramer

  • Abdelrhman Allam (sl4x0)

    Abdelrhman Allam (sl4x0)

  • cyberyash

    cyberyash

  • c4sper0

    c4sper0

See all (11)

Help

Status

About

Careers

Blog

Privacy

Terms

Text to speech

Teams