Bypass Email Verification in MozillaHi, I’m Amr Kadry, a penetration tester and bug hunter, acknowledged by over 45 companies including Mozilla, CrowdStrike, Canva, Vimeo, and…Nov 21, 2024A response icon6Nov 21, 2024A response icon6
Account Takeover: How I Gained Access to Any User Account Through a Simple Registration FlawHi, I’m Amr Kadry, a penetration tester and bug hunter recognized by over 45 companies, including Mozilla, CrowdStrike, Canva, and Vimeo…Nov 14, 2024A response icon8Nov 14, 2024A response icon8
From an Out-of-Scope Bug to Unlocking Lifetime Premium Accounts in MozillaHi, I’m Amr Kadry, a penetration tester and bug hunter recognized by over 45 companies, including Mozilla, CrowdStrike, Canva, and Vimeo…Nov 7, 2024A response icon7Nov 7, 2024A response icon7
Unauthenticated IDOR in Employee Login Exposes PII to more than 100K Usersبِسْمِ اللَّـهِ الرَّحْمَـٰنِ الرَّحِيمِMay 25, 2024A response icon6May 25, 2024A response icon6
How I got JS Execution (DOM XSS) Via CSTIبِسْمِ اللَّـهِ الرَّحْمَـٰنِ الرَّحِيمِApr 15, 2024A response icon4Apr 15, 2024A response icon4