Ben Sadeghipour(@NahamSec) 's Twitter Profileg
Ben Sadeghipour

@NahamSec

Cofounder @hackinghub_io, Advisor @Trick3st @CaidoIO. I hack companies and make content about it. Bug Bounty Village & #NahamCon organizer. ex @hacker0x01🇮🇷

ID:2281370629

linkhttp://NahamSec.com calendar_today08-01-2014 00:50:42

13,1K Tweet

198,0K Takipçi

1,0K Takip Edilen

Six2dez(@Six2dez1) 's Twitter Profile Photo

So.... reconFTW v2.5 out today!

- In this release, I've recovered ProjectDiscovery.io 's subfinder as many ppl prefer it
- New vars added to cfg file to choose amass or subfinder
- If you find your DNS resolution was acting weird now it's fixed!

Full changes:
github.com/six2dez/reconf…

So.... reconFTW v2.5 out today! - In this release, I've recovered @pdiscoveryio 's subfinder as many ppl prefer it - New vars added to cfg file to choose amass or subfinder - If you find your DNS resolution was acting weird now it's fixed! Full changes: github.com/six2dez/reconf…
account_circle
IPinfo.io – IP Data Provider(@ipinfoio) 's Twitter Profile Photo

See how Ben Sadeghipour utilizes IPinfo's ASN API to discover additional subdomains that can easily be missed during enumeration.

1️⃣ Find a company's ASN using IPinfo
2️⃣ Enumerate additional subdomains using the ASN's IP ranges.

Here's how👇

youtube.com/watch?v=6rKHTP…

account_circle
Hadrian(@hadriansecurity) 's Twitter Profile Photo

☁️In the era of digital transformation, assets are highly dynamic and often difficult to detect and monitor using traditional approaches.

👇Find out how Hadrian helps organizations to discover, classify and assess the risk profile of critical assets
bit.ly/3D8yKt6

account_circle
ReconOne(@ReconOne_bk) 's Twitter Profile Photo

- Good content from Nahamsec 💪

If you choose the free method in the video, check the Organization field in the domain certificate 😉

account_circle
Hadrian(@hadriansecurity) 's Twitter Profile Photo

🚀 Ben Sadeghipour is giving a live virtual talk today at Security@! Join the live stream at 1.15 PM PST to learn about ‘Modernizing Attack Surface Management with Hadrian’!
HackerOne
securityat.hackerone.events/2022/live-stre…

account_circle
Ben Sadeghipour(@NahamSec) 's Twitter Profile Photo

I've found this company's admin panel through Shodan. It's behind htpasswd but when I push cancel it load the entire admin panel and dumps data. I'm pretty sure I can also modify data and send a notification to all their users.

How do you mess htpasswd up so bad?? 🥴

account_circle
Justin Gardner(@Rhynorater) 's Twitter Profile Photo

Last week in my poll you asked for some more technical content. Here is a quick braindump of my postMessage testing methodology which has landed some great bugs over the past few live hacking events. Enjoy!
rhynorater.github.io/postMessage-Br…

account_circle