Yaseen Zubair·Dec 23, 2025From “Add User” to Root: A 4-Digit Bug Bounty Command InjectionThis article documents a real-world security issue identified while performing a bug bounty assessment. The purpose of this write-up is…A response icon2A response icon2
Yaseen Zubair·Jul 30, 2024Race Conditions Uncovered: A Practical GuideA race condition occurs when two or more threads attempt to execute the same process simultaneously, leading to unintended consequences.
Yaseen Zubair·Feb 12, 2023IDOR Leads to MASS Account TakeoverIn most web applications, there is a high prevalence of misconfiguration problems, particularly with regard to authorization. While testing…
Yaseen Zubair·Jan 5, 2023Blind XSS in Email Field; 1000$ bountyWhere there is blind-xss, There always is xsshunter!
Yaseen Zubair·Jan 2, 2023Web-Cache Poisoning $$$? Worth it?In this article, I will try to guide the readers about a bug that is easy to miss and doesn’t get a lot of attention, but surely it’s worth…A response icon2A response icon2
Yaseen Zubair·Jan 2, 2023My Learning JourneyHello everyone, My name is Yaseen and I am a software engineer with a passion for ethical hacking. I have decided to document my findings…A response icon1A response icon1