Web appOpen in Telegram
FForBugHunters

ForBugHunters

@ForBugHunters · channel · Tech · indexed since 2026-07-10
6 013subscribers+10 in a week
2 390average post reach
39.8%ER — reach to subscribers
4posts in 30 days
F
ForBugHunters
Photo
click to show
Stored XSS ➜ $$$ 💰 Found a Stored XSS in the team creation flow. Steps: 1. Create a new team. 2. Set the team name to: "><script>alert(document.cookie)</script> 3. Enable the option requiring all team members to use 2FA. 4. Join the same team with another user. Result: The second user receives a message prompting them to enable 2FA in (Team Name). Since the team name is rendered without proper sanitization, the injected JavaScript executes, resulting in a Stored XSS. Status: ✅ Fixed & Rewarded. Linkedin : https://www.linkedin.com/posts/ayman-amer1_bugbounty-storedxss-xss-activity-7479481896792608768-NSxY
8 · 5K ·
F
ForBugHunters
Self hosted +Bug bounty programs⬇️ *.cleeng.com [email protected] ————————————— *.redsift.com [email protected] ————————————— *.plain.com [email protected] ————————————— *.linkdm.com [email protected] ————————————— *.ory.com [email protected] ————————————— *. aquanow.com [email protected] ————————————— https://github.com/swisscom/bugbounty ————————————— https://www.spendesk.com/.well-known/security.txt ————————————— https://help.spreaker.com/en/articles/5123644-bug-bounty-program ————————————— https://www.fjdynamics.com/jp/bug-bounty-program ————————————— https://www.klook.com/bugbounty ————————————— https://gobright.com/responsible-disclosure-policy/ ————————————— https://www.make.com/en/bounty ————————————— https://www.pubnub.com/bug-bounty-policy/ ————————————— https://help.doit.com/docs/vendor-information/bug-bounty-program ————————————— https://www.lenskart.com/vulnerability-disclosure-policy ————————————— https://www.talentlms.com/vulnerabilitypolicy ————————————— https://whatbox.ca/policies/security ————————————— *.perlego.com [email protected] ————————————— https://support.playerauctions.com/hc/en-us/articles/49330305602585-PlayerAuctions-Bug-Bounty-Program ————————————— *.lithicblue.com [email protected] ————————————— *.expensify.com [email protected]
66 · 5.4K ·
F
ForBugHunters
🔥 Live Hacking Session Today at 4:00 PM (Egypt Time) — Join us and bring your Bug Bounty & Pentesting questions!
4 · 5.4K ·
F
Link
click to show
Authz-ExeC is a Burp Suite extension that automatically tests authorization by replaying requests with different identities to detect IDOR, BOLA, Broken Access Control, privilege escalation, and cross-tenant vulnerabilities: https://github.com/execiq/Authz-ExeC
38 · 5K ·
F
ForBugHunters
Photo
click to show
Congratulations 🎉 Who’s next !🤷‍♂️
3.8K ·
F
ForBugHunters
Photo
click to show
Photo
click to show
🚨 Found a Critical 2FA Bypass Reward: $$$$ (4-digit) Severity: Critical Linkedin Wait for the full video coming soon on YouTube!
6 · 4.4K ·
F
ForBugHunters
Photo
click to show
Found another valid vulnerability in Google, but unfortunately, it turned out to be a duplicate. الحمدالله
3.1K ·
ForBugHunters
Photo
click to show
Photo
click to show
Found 2 vulnerabilities: Reward: $1,500 Critical — Authentication Bypass High — Authentication Bypass LinkedIn Post
2 · 3.3K ·
F
ForBugHunters
Photo
click to show
Photo
click to show
Photo
click to show
🏆 Officially #1 in Egypt on Google in 2026 2 more of my security reports have been accepted by Google. 🔥 Facebook LinkedIn
1 · 2.8K ·
F
ForBugHunters
Link
click to show
🔥The 2 New Videos Are Live! 2FA Bypass — Empty OTP Accepted = Account Takeover: Link MFA Enforcement Bypass — Invite Team Members Without Enabling MFA Link
1 · 1.3K ·

An open public feed from the search index ChatCrawler — “Google for public Telegram”; refreshed as the venue is crawled. Times are UTC.

Public content only, official Telegram API. About · FAQ · What we do not do · Remove a page · Catalog · Search · How we count