Open in app

Sign In

Write

Sign In

Mohsin khan
Mohsin khan

909 Followers

Home

About

Sep 6, 2022

What would I do if I start bug hunting from 0 again?

Hi everyone, I hope you are doing great. Finding bugs and making a lot of money. So many new bug hunters ask me this question: If I start doing bug hunting again what I would do? Note: Whatever I am telling you is not the best way or maybe not…

Bug Bounty

3 min read

Bug Bounty

3 min read


May 21, 2022

A business Logic issue worth $1500

Hello everyone, Its me Mohsin khan AKA tabaahi_.Today I would like to talk about one of my recent findings. It was a private bug crowd program. The issue is resolved now. But I don’t have permission from the program so will call it redirect.com. The program has a website, android…

Bug Bounty

2 min read

A business Logic issue worth $1500
A business Logic issue worth $1500
Bug Bounty

2 min read


May 8, 2022

Account verification code bypass lead to a $4000 bounty

Hello reader, I hope you are doing well. Today I want to talk about one of my findings. It was a private program and the bug is not fixed yet. So I am not going to include any information about the program/platform here. Let's call it redirect.com. So redirect.com has…

Bugbounting

2 min read

Account verification code bypass lead to a $4000 bounty
Account verification code bypass lead to a $4000 bounty
Bugbounting

2 min read


Apr 27, 2022

You need to hear this if you are new/want to start bug hunting

Hello everyone, It's me Mohsin khan. You maybe know me as tabaahi_. I hope you are doing well. Today I want to talk about what will make you a better bug hunter & how to ask the right questions. Mental health maybe. What mistakes do beginners make: They think bug…

Bugbounting

4 min read

You need to hear this if you are new/want to start bug hunting
You need to hear this if you are new/want to start bug hunting
Bugbounting

4 min read


Feb 15, 2021

Full account takeover worth $1000 Think out of the box

Hi everyone how are you doing today? I hope you are doing great and scoring lots of bounties. Today's story is about a bug I found on public disclosure program which allows me to take over any user's account. It was a P4 issue but I didn’t report and chain…

Bug Bounty

5 min read

Full account takeover worth $1000 Think out of the box
Full account takeover worth $1000 Think out of the box
Bug Bounty

5 min read


Feb 14, 2021

IDOR via Websockets allow me to takeover any users account

Hi everyone I hope you all are doing great and scoring lots of bounties. I am Mohsin khan I am from India and I do bug bounty full time for 1 year now. I found lots of bugs in the last year. Today I am sharing one of my finding…

Bug Bounty

4 min read

IDOR via Websockets allow me to takeover any users account
IDOR via Websockets allow me to takeover any users account
Bug Bounty

4 min read

Mohsin khan

Mohsin khan

909 Followers

https://twitter.com/tabaahi_

Following
  • Xcheater

    Xcheater

  • Hacktivities

    Hacktivities

  • Uber Privacy & Security

    Uber Privacy & Security

  • Valeriy Shevchenko

    Valeriy Shevchenko

  • Max

    Max

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech