Qortora · Search · Indexed page

hashnode.comFetched 2026-08-17T16:19:51Z

Abdulaziz Saad (@b4zb0z) | Hashnode

INTJ | Self-made | Web Developer | Rusty Hacker. Read the latest articles by Abdulaziz Saad on Hashnode.

Open original source · Full cached text

Abdulaziz Saad (@b4zb0z) | Hashnode Toggle Sidebar Feed Pro Search Theme Sign in MoreDarkshift - a dark factory for softwareBug0 - The AI-native e2e QA regression testingThe foreword by Hashnode - official blog from the Hashnode teamPassmark - The open-source AI framework for regression testingHashnode gql skill - let your AI agent publish to your Hashnode blogHackathonsChangelogBrand@hashnode on XHashnode on LinkedInSupport - [email protected] of ConductTermsPrivacySitemap Search Hashnode Search posts, tags, users, and pages @b4zb0z Abdulaziz Saad @b4zb0z·Jeddah, SA·Joined February 2023 INTJ | Self-made | Web Developer | Rusty Hacker WebsiteShare About Nothing here yet. Available for Nothing here yet. Abdulaziz Saad's blogs Abdulaziz's Writeupsblog.abdulaziz-d.com6 posts About Nothing here yet. Available for Nothing here yet. Abdulaziz Saad's blogs Abdulaziz's Writeupsblog.abdulaziz-d.com6 posts ArticlesComments Recently published ASAbdulaziz Saadinblog.abdulaziz-d.com·1h ago · 12 min read From Editor to Owner: One Writable Field Was Enough to Take Over an Organization Severity: HighBounty: ~$315Platform: Standoff365 This one came down to a single field that should never have been writable by an editor: Firm[user_id] The application had a clear permission model. An 00 ASAbdulaziz Saadinblog.abdulaziz-d.com·Aug 7 · 12 min read A $2,000 API Key: Unauthorized Access to Paid Medical Transcription Severity: HighBounty: $2,000Retest Reward: $150Total Awarded: $2,150Program: Private ProgramPlatform: HackerOne This finding started with a familiar Android testing problem: What secrets were shipped 00 ASAbdulaziz Saadinblog.abdulaziz-d.com·Jul 30 · 13 min read From Profile IDOR to Zero-Click Account Takeover: Changing One userid Parameter Was Enough Severity: CriticalBounty: $1,805Program: Private Bug BountyPlatform: Bugbounty.sa This started as a straightforward profile IDOR. An authenticated user could change a userid parameter and load another 21N ASAbdulaziz Saadinblog.abdulaziz-d.com·May 21 · 6 min read IDOR in Government Ownership API Exposed Private Business Owner PII via CR Number Enumeration Severity: HighBounty Awarded: $1,506Program: Private Bug BountyPlatform: Bugbounty.sa Some IDORs are obvious immediately. You change an ID. Someone else’s data appears. Easy. Others look harmless at f 00 ASAbdulaziz Saadinblog.abdulaziz-d.com·May 18 · 9 min read Zero-Click Stored XSS in Chat: When “Just Open the Window” Is Enough Severity: HighBounty Awarded: $394Program: Private Bug BountyPlatform: Bugbounty.sa Most chat XSS bugs are noisy. You send a payload. The victim has to click something. Refresh the page. Open the mes 00 Load more