Mahmoud Youssef·Jun 30, 2025Business Logic Flaw: Chaining two endpoints to illegitimately claim purchasable rewardsHello everyone! After nearly 3 years away from bug bounty due to military service and pursuing a master’s in cybersecurity, I’m finally…A response icon2A response icon2
Mahmoud Youssef·Sep 6, 2022Exploiting Out-of-Band XXE in the WildHello all, I hope you’re fine! Our story today is about one of the most interesting bugs I found, actually, it’s my first time finding this…A response icon4A response icon4
Mahmoud Youssef·Jul 2, 2022Admin account takeover via weird Password Reset FunctionalityHello all, I hope you’re fine! Our story today is a funny ATO I recently found it, so I decided to share it with you.A response icon10A response icon10
Mahmoud Youssef·May 15, 20220-click ATO via Stored-XSSHello everybody, today we have a simple Stored XSS vulnerability that leads to stealing cookies and Taking over the account. Let’s startA response icon2A response icon2
InInfoSec Write-upsbyMahmoud Youssef·Dec 14, 2021How I Found multiple SQL Injection with FFUF and Sqlmap in a few minutesHello all, hope you’re OK. Our journey today is about how I found multiple SQL Injections in a bug bounty program in just a few minutes…A response icon11A response icon11
Mahmoud Youssef·Nov 6, 2021How I Found multiple SQL Injection with FFUF and Sqlmap in a few minutesHello all, hope you’re OK. Our journey today is about how I found multiple SQL Injection in a BugBounty program in just few minutes with a…A response icon15A response icon15
Mahmoud Youssef·Sep 20, 2020Cybertalents Quals : Saudi, Sudan, Egypt and Tunisia National CTF 2020 Write-UpCybertalents Quals Challenges Write-UpA response icon1A response icon1