ExeC IQ ๐Ÿ‡ฎ๐Ÿ‡ถ
3.05K subscribers
155 photos
14 videos
14 files
130 links
Hi everyone.
I am ExeC from great Iraq ๐Ÿ‡ฎ๐Ÿ‡ถ.

Security Researcher on HackerOne
Also, I am in the Top 1 On the Leaderboard of Iraq 2024-2025.

In this channel, I will be sharing information to benefit you in cyber security and bug hunting.
Download Telegram
๐ŸŸก Bug Bounty Hunting search engine

https://www.bugbountyhunting.com/

- - - - - - - - - - - - - - - - - - - -
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ17๐Ÿ‘3๐Ÿคฏ3๐Ÿ‘2๐Ÿ’ฏ2
Media is too big
VIEW IN TELEGRAM
๐ŸŸฃ HackerOne Report: Critical Severity โš ๏ธ

OTP code Leaked in API Response

#ExeC_IQ
- - - - - - - - - - - - - - - - - - - -
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ28๐Ÿ’ฏ2๐Ÿ‘1๐Ÿคฏ1
๐ŸŸข How to Check if a Domain is Available in a Specific Country For Bypass WAF Blocked Using Check-Host.net

https://medium.com/@exec_iq/how-to-check-if-a-domain-is-available-in-a-specific-country-for-bypass-waf-blocked-using-check-host-e14dec46b29a

- - - - - - - - - - - - - - - - - - - -
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘7๐Ÿ‘3
ุณุชุณุชุฃู†ู ูุนุงู„ูŠุงุช Sully Cyber โ€‹โ€‹โ€‹โ€‹Con ุงู„ุณู†ูˆูŠุฉ ุงู„ุซุงู†ูŠุฉ ููŠ ุงู„ูุชุฑุฉ ู…ู† 16 ุฅู„ู‰ 18 ูุจุฑุงูŠุฑุŒ
ูŠู‚ุงู… ุงู„ู…ุคุชู…ุฑ ุจุงู„ุชุนุงูˆู† ู…ุน IQ ูˆุฌุงู…ุนุฉ ุงู„ุณู„ูŠู…ุงู†ูŠุฉ ูˆSully Cyber โ€‹โ€‹โ€‹โ€‹Con
ุณูŠูƒูˆู† ุงู„ู…ุคุชู…ุฑ ุงู„ุฃูƒุจุฑ ููŠ ุงู„ุนุฑุงู‚ ูˆูƒุฑุฏุณุชุงู† ุญูˆู„ ุงู„ุฃู…ู† ุงู„ุณูŠุจุฑุงู†ูŠ ูˆุงู„ู‚ุฑุตู†ุฉุŒ ูˆููŠ ุงู„ุนุงู… ุงู„ู…ุงุถูŠุŒ ุญุตู„ ุงู„ู…ุดุงุฑูƒูˆู† ุงู„ุนุดุฑุฉ ุงู„ุฃูˆุงุฆู„ ุนู„ู‰ ุฌูˆุงุฆุฒุŒ ูˆุฒุงุฏ ุนุฏุฏ ุงู„ุฑุคุณุงุก ูˆุงู„ุดุฑูƒุงุก
ุฅุฐุง ูƒู†ุช ุชุฑุบุจ ููŠ ุญุถูˆุฑ ู…ุคุชู…ุฑ ู‡ุฐุง ุงู„ุนุงู… ูˆุงู„ู…ุดุงุฑูƒุฉ ููŠ CTFs ู„ู‡ุฐุง ุงู„ุนุงู…ุŒ ููŠู…ูƒู†ูƒ ู…ู„ุก ุงู„ู†ู…ูˆุฐุฌ ุฃุฏู†ุงู‡ ุจู…ูุฑุฏูƒ ุฃูˆ ู…ุน ูุฑูŠู‚
ู‡ุฐุง ุงู„ู…ุคุชู…ุฑ ู…ูุชูˆุญ ู„ุฌู…ูŠุน ุงู„ุฌุงู…ุนุงุช ููŠ ุงู„ุนุฑุงู‚ ูˆูƒุฑุฏุณุชุงู†
ู„ู„ู…ุดุงุฑูƒุฉ ููŠ ู…ุณุงุจู‚ุฉ ุญูˆู„ ุงู„ุฃู…ู† ุงู„ุณูŠุจุฑุงู†ูŠ ูˆุงู„ุงุฎุชุฑุงู‚ ูˆุงู„ุชู‚ุงุท ุงู„ุฃุนู„ุงู… (CTF) ูŠู…ูƒู†ูƒ ุงู„ุชุณุฌูŠู„ ู‡ู†ุง.

https://docs.google.com/forms/d/e/1FAIpQLSdNrnWodE5iyYf-mJLqQbDKbh7HudPj6nZqYOykpmvV2Vo6fw/viewform

https://univsul.edu.iq/ku/news/2025/01/14/7168/
https://www.facebook.com/SulyCyberCon/posts/582186598103910
๐Ÿ’ฏ7๐Ÿ‘3
Media is too big
VIEW IN TELEGRAM
๐Ÿ“Œ Bypassing Restrictions Allows Unlimited User Invitations

#ExeC_IQ
- - - - - - - - - - - - - - - - - - - -
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ9๐Ÿคฏ5๐Ÿ‘4๐Ÿ‘2
ุชุชูˆู‚ุนูˆู† ูุฑูŠู‚ู†ุง ูƒุงุนุฏ ูˆุณุงูƒุช... ุŸ
ู…ุญุถุฑูŠู„ูƒู… ุดูŠ ุฑุงุญ ูŠุบูŠุฑ ูˆุฌู‡ ุงู„ุงู…ู† ุงู„ุณูŠุจุฑุงู†ูŠ ุจุงู„ุนุฑุงู‚ ู„ู„ุงุจุฏ ...
๐Ÿคฏ17๐Ÿ”ฅ11๐Ÿ‘4๐Ÿ’ฏ2๐Ÿ˜ข1
recording-1710507780161.webm
7.9 MB
๐Ÿ‘‘ PoC:
Stored XSS via PDF FILE UPLOADING.

#ExeC_IQ
- - - - - - - - - - - - - - - - - - - -
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘8๐Ÿ”ฅ4๐Ÿ’ฏ3๐Ÿคฏ1
ุชุชูˆู‚ุน ูƒู… ุซุบุฑุฉ ู…ูˆุฌูˆุฏุฉ ู…ู† ุฎู„ุงู„ ู‡ุฐุง ุงู„ูุญุตุŸ ๐Ÿ™‚
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ19๐Ÿคฏ11๐Ÿ‘5๐Ÿ‘2๐Ÿ˜ข1
๐ŸŸฃ L1B3RT4S โ€“ Jailbreak AI Without Limits

L1B3RT4S is an advanced tool designed to bypass AI restrictions and remove safety filters, allowing AI models to respond without censorship or limitations. This tool makes it easy to generate unrestricted AI outputs, bypass ethical blocks, and achieve full control over AI responses, uses for attackers
๐Ÿ“Œ
https://github.com/elder-plinius/L1B3RT4S
- - - - - - - - - - - - - - - - - - - -
#ExeC_IQ
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ9๐Ÿ‘1๐Ÿ‘1
๐Ÿ”ด ุงุฐุง ุชุฑูŠุฏ ุชุจุฏุฃ ูƒู€ Bug Hunter, ูˆุชุจุญุซ ุนู† ุจุฑุงู…ุฌ VDP ุชุญุตู„ ู…ู†ู‡ุง ู†ู‚ุงุท ูˆุชุจุฏุฃ ู…ุณูŠุฑุชูƒ,
ูู€ ู‡ุฐุง ุงู„ุจุฑู†ุงู…ุฌ ู…ูˆุฌูˆุฏ ุนู„ู‰ Hackerone Public ูŠุญุชูˆูŠ ุนู„ู‰ 11 ุงู„ู ุฏูˆู…ูŠู† ูŠุนู†ูŠ ู†ุณุจุฉ ุญุตูˆู„ูƒ ุนู„ู‰ ุซุบุฑุฉ ุฌุฏุงู‹ ุฌุฏุงู‹
ุนุงู„ูŠุฉ. โญ๏ธ

https://hackerone.com/fiserv

- - - - - - - - - - - - - - - - - - - -
#ExeC_IQ
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ‘21๐Ÿ”ฅ8๐Ÿคฏ4๐Ÿ‘3๐Ÿ’ฏ2
ุดูƒุฑุงู‹ ู„ูˆุฒุงุฑุฉ ุงู„ุฏุงุฎู„ูŠุฉ ู…ุฏูŠุฑูŠุฉ ุงู„ุฃู…ู† ุงู„ุณูŠุจุฑุงู†ูŠ ุงู„ู…ุชู…ุซู„ุฉ ุจุงู„ุฏูƒุชูˆุฑ ุญุณู† ู‡ุงุฏูŠ ุนู„ู‰ ุงู„ุฏุนู… ุงู„ู…ุณุชู…ุฑ.

ูˆุงู„ุดูƒุฑ ู…ูˆุตูˆู„ ุงู„ู‰ ู…ู†ุธู…ูŠู† SulyCyber ูˆุดุฑูƒุฉ iq group ุนู„ู‰ ุงู„ุงุณุชู‚ุจุงู„ ูˆุงู„ุชู†ุธูŠู… ุงู„ุฑุงุฆุน.
๐Ÿ‘3๐Ÿคฏ1
ุงุจุทุงู„ ูุฑูŠู‚ู†ุง ุงู„ูŠูˆู… ุตุนุฏูˆุง ุน ุงู„ู…ู†ุตุฉ ๐Ÿ™‚โ€โ†”๏ธ๐Ÿ”ฅ
๐Ÿ”ฅ36๐Ÿ‘5๐Ÿคฏ2
Media is too big
VIEW IN TELEGRAM
โžก๏ธ PoC: IDOR Exposing Sensitive Device Information Across Organizations

1,500$
โš ๏ธ

- - - - - - - - - - - - - - - - - - - -
#ExeC_IQ
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ13๐Ÿคฏ4๐Ÿ‘2๐Ÿ˜ข1๐Ÿ’ฏ1
ุฑู…ุถุงู† ูƒุฑูŠู… ุนู„ูŠูƒู… ๐ŸŒ™๐Ÿ’›
ุฃูˆู„ ูŠูˆู… ุฑู…ุถุงู†ุŒ
ุฑุงุญ ู†ุดุฑุญ ูˆุญุฏุฉ ู…ู† ุฃุดู‡ุฑ ุงู„ุซุบุฑุงุช ุจุงู„ู…ูˆุงู‚ุน: ุซุบุฑุฉ XSS (Cross-Site Scripting) ๐ŸŽญ๐Ÿ’€

---

## ๐Ÿ” ุดู†ูˆ ู‡ูŠ ุซุบุฑุฉ ุงู„ู€XSSุŸ
ู‡ูŠ ุซุบุฑุฉ ุชุฎู„ูŠ ุงู„ู…ู‡ุงุฌู… ูŠุญู‚ู† ูƒูˆุฏ JavaScript ุฎุจูŠุซ ุฏุงุฎู„ ุงู„ู…ูˆู‚ุนุŒ ูˆุจุงู„ุชุงู„ูŠ ูŠู‚ุฏุฑ ูŠุณุฑู‚ ู…ุนู„ูˆู…ุงุช ุงู„ู…ุณุชุฎุฏู…ุŒ ู…ุซู„ ุงู„ูƒูˆูƒูŠุฒ ๐ŸชุŒ ุฃูˆ ูŠู†ูุฐ ุฃูˆุงู…ุฑ ุบูŠุฑ ู…ุฑุบูˆุจ ุจูŠู‡ุง ๐Ÿ˜ˆ๐Ÿ’ฅ

---

## ๐Ÿšจ ุฃู†ูˆุงุน ุซุบุฑุงุช XSS:
1๏ธโƒฃ Reflected XSS (ุบูŠุฑ ู…ุณุชู…ุฑุฉ) ๐Ÿ”„
๐Ÿ”น ุงู„ูƒูˆุฏ ูŠู†ุญู‚ู† ุนุจุฑ ุฑุงุจุท (URL) ูˆูŠู†ูุฐ ู…ุจุงุดุฑุฉ ุจุฏูˆู† ู…ุง ูŠู†ุญูุธ ุจุงู„ู…ูˆู‚ุน.
โœ๏ธ ู…ุซุงู„:
https://example.com/search?q=<script>alert('XSS')</script>

2๏ธโƒฃ Stored XSS (ู…ุณุชู…ุฑุฉ) ๐Ÿ’พ๐Ÿ”ฅ
๐Ÿ”น ุงู„ูƒูˆุฏ ุงู„ุฎุจูŠุซ ูŠู†ุฎุฒู† ุฏุงุฎู„ ู‚ุงุนุฏุฉ ุจูŠุงู†ุงุช ุงู„ู…ูˆู‚ุน**ุŒ ู…ุซู„ู‹ุง ุฅุฐุง ูƒุชุจุชู‡ ุฏุงุฎู„ ุชุนู„ูŠู‚ ๐Ÿ’ฌุŒ ูƒู„ ู…ุง ูŠูุชุญ ุดุฎุต ุงู„ุตูุญุฉุŒ ูŠุชู†ูุฐ ุนู„ูŠู‡!

3๏ธโƒฃ **DOM-Based XSS ๐Ÿ—๐Ÿ’ป
๐Ÿ”น ู‡ุฐุง ุงู„ู†ูˆุน ูŠุนุชู…ุฏ ุนู„ู‰ ุชู„ุงุนุจ ุงู„ู…ุชุตูุญ ุจุงู„ูƒูˆุฏ**ุŒ ุจุญูŠุซ ูŠุณุชุบู„ ุทุฑูŠู‚ุฉ ู…ุนุงู„ุฌุฉ ุงู„ุจูŠุงู†ุงุช ุจุงู„ู€ DOMุŒ ุจุฏูˆู† ู…ุง ูŠูƒูˆู† ุงู„ูƒูˆุฏ ู…ูˆุฌูˆุฏ ุจุงู„ุณูŠุฑูุฑ.

---

## ๐ŸŽฏ ู…ุซุงู„ ุนู…ู„ูŠ ุจุณูŠุท:
ุชุฎูŠู„ ุนู†ุฏูƒ ุญู‚ู„ ุจุญุซ ููŠ ู…ูˆู‚ุน ุถุนูŠู ุฃู…ู†ูŠู‹ุงุŒ ูˆุฌุฑุจุช ุชุญู‚ู† ุงู„ูƒูˆุฏ ู‡ุฐุง :

<script>alert('XSS');</script>



ุฅุฐุง ุทู„ุน ู„ูƒ ุชู†ุจูŠู‡ ููŠ ุงู„ู…ุชุตูุญ ๐Ÿ””๐ŸคฏุŒ ูู‡ุฐุง ู…ุนู†ุงู‡ ุฃู† ุงู„ู…ูˆู‚ุน **ู…ุตุงุจ ุจุซุบุฑุฉ XSS! ๐Ÿ˜ฑ๐Ÿšจ

---

## ๐Ÿ›  ู…ูˆุงู‚ุน ู„ู„ุชุฌุฑุจุฉ ูˆุงู„ุชุนู„ู…:
1.
http://67.207.90.30/xss/index.html
2.
https://sudo.co.il/xss/
3.
https://zixem.altervista.org/XSS/


๐Ÿ”ฅ๐Ÿ’ก ุฃุชู…ู†ู‰ ุงุณุชูุงุฏูŠุชูˆุง ู…ู† ู‡ุงูŠ ุงู„ู…ุนู„ูˆู…ุงุชุŒ ูˆุฑู…ุถุงู† ู…ุจุงุฑูƒ ุนู„ูŠูƒู… ู…ุฑุฉ ุซุงู†ูŠุฉ! ๐ŸŒ™โœจ
ุฅุฐุง ุนู†ุฏูƒู… ุฃูŠ ุณุคุงู„ุŒ ูƒุชุจูˆุง ุจุงู„ุชุนู„ูŠู‚ุงุช ๐Ÿ“โค๏ธ

- - - - - - - - - - - - - - - - - - - -
#ExeC_IQ
๐Ÿ’ฏ29๐Ÿ”ฅ5๐Ÿ‘4
๐Ÿ“ SendGrid API Key Exposed PoC:
{SG.***********}

โ—๏ธ Curl Command:
curl -X "GET" "api.sendgrid.com/v3/scopes" -H "Authorization: Bearer 'Token'" -H "Content-Type: application/json"


Severity: Critical
๐Ÿ”ฅ

- - - - - - - - - - - - - - - - - - - -
#ExeC_IQ
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ7๐Ÿ‘2
Media is too big
VIEW IN TELEGRAM
โญ๏ธ PoC:
Participant Identity Exposure Despite Name Hiding in Meetings

โ—๏ธ Weakness:
Information Disclosure

- - - - - - - - - - - - - - - - - - - -
#ExeC_IQ
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿคฏ6๐Ÿ’ฏ3๐Ÿ‘1๐Ÿ”ฅ1
โžก๏ธ Report HackerOne @ExeC_IQ

Business Logic Errors
โš ๏ธ
- - - - - - - - - - - - - - - - - - - -

ุงู„ููƒุฑุฉ ุฌุงู†ุช ุนุจุงุฑุฉ ุนู† ูƒุฑูˆุจุงุช ุดุจูŠู‡ุฉ ุจูƒุฑูˆุจุงุช ุงู„ุณูˆุดูŠุงู„ ู…ูŠุฏูŠุงุŒ
ู„ู…ุง ุชุฏุฎู„ ู„ู„ูƒุฑูˆุจ ูˆุชุญุฏุฏ ุฑุณุงู„ุฉ ู…ูุนูŠู†ุฉ ุชู„ุงุญุธ ุชูƒุฏุฑ ุชุณูˆูŠ ุงู„ู‡ุง ุฑูŠุงูƒุดู† ูˆุชุชูุงุนู„ ุนู„ูŠู‡ุง ุน ุดูƒู„ ุงูŠู…ูˆุฌูŠุงุชุŒ ุจุนุฏ ุงู„ุชูุงุนู„ ุฑุงุญ ุชุญุตู„ ุทู„ุจ ูŠุญุชูˆูŠ ุนู„ู‰ ุจุงุฑุงู…ูŠุชุฑ
โžก๏ธ
"type":"emoji-1f4c2"

ู‡ุฐุง ุฎุงุต ุจุชุญุฏูŠุฏ ุงู„ุงูŠู…ูˆุฌูŠ ุงู„ูŠ ุชุฑูŠุฏ ุชุชูุงุนู„ ุนู„ูŠู‡ุŒ ุงู„ุซุบุฑุฉ ุงู„ู…ูˆุฌูˆุฏุฉ ู‡ู†ุง ู„ู…ุง ุชุญุงูˆู„ ุชุบูŠุฑ ู‚ูŠู…ุฉ ุงู„ุฃูŠู…ูˆุฌูŠ ุงู„ู…ูุญุฏุฏ ุงู„ู‰ ุฃูŠู…ูˆุฌูŠ ุบูŠุฑ ู…ุนุฑูˆู ู…ุซู„ุงู‹
"type":"emoji-1211212"

ู‡ู†ุง ู…ุจุงุดุฑุชุงู‹ ุงู„ู…ูˆู‚ุน ู…ุงุฑุงุญ ูŠุชุนุฑู ุนู„ูŠู‡ุง ูƒุฃูŠู…ูˆุฌูŠ ู…ูˆุฌูˆุฏ ูˆุฑุงุญ ูŠุธู‡ุฑ ุฎุทุฃ ู„ุฃู† ู…ู„ูุงุช ุงู„ุฌุงูุงุณูƒุฑุจุช ู…ุงุญุตู„ุช ุงู„ุฃูŠู…ูˆุฌูŠ ุงู„ูŠ ุบูŠุฑุช ู‚ูŠู…ุชู‡ุŒ ุฎุทูˆุฑุชู‡ุง ุฑุงุญ ุชุตูŠุฑ ู‡ุฐุง ุงู„ุฎุทุฃ ุงู„ูŠ ูŠุธู‡ุฑ ุฑุงุญ ูŠุธู‡ุฑ ู„ุฌู…ูŠุน ุงุนุถุงุก ุงู„ูƒุฑูˆุจ ูˆู…ุงุฑุงุญ ูŠูƒุฏุฑูˆู† ูŠุฏุฎู„ูˆู† ู„ู„ู…ุญุงุฏุซุฉ ุงูˆ ู„ู„ู…ุญุงุฏุซุงุช ุฌู…ูŠุนุงู‹ ุจุดูƒู„ ู†ู‡ุงุฆูŠ ุฏุงุฆู… ูˆู‡ุงูŠ ุงุณุชุบู„ุงู„ู‡ุง ุนู„ู‰ ุฌู…ูŠุน ุงู„ุงุนุถุงุก. ๐Ÿ’ฆ

CVSS: High 8.6 2000$
๐Ÿ’ฒ

@ExeC_IQ
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ30๐Ÿ‘7๐Ÿ’ฏ4๐Ÿ‘3
"ููุฒู’ุชู ูˆูŽุฑูŽุจู‘ู ุงู„ูƒูŽุนุจูŽุฉ"
๐Ÿ”ฅ31๐Ÿ˜ข22๐Ÿ’ฏ5๐Ÿ‘3๐Ÿ‘1๐Ÿคฏ1
This media is not supported in your browser
VIEW IN TELEGRAM
๐Ÿ”˜ PoC: Bypass the OTP for email verification by manipulating the response

- - - - - - - - - - - - - - - - - - - -
#ExeC_IQ
Please open Telegram to view this post
VIEW IN TELEGRAM
๐Ÿ”ฅ19๐Ÿ‘5๐Ÿ’ฏ4