Generated by All in One SEO v4.9.1, this is an llms.txt file, used by LLMs to index the site. # Prial Islam Ethical Hacker | Cyber Security Researcher ## Sitemaps - [XML Sitemap](https://0xprial.com/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [The Art Of Zendesk Hijacking](https://0xprial.com/the-art-of-zendesk-hijacking/) - Back in July 2023, I was testing a HackerOne Private Program [ let’s call this target xyz.com ] and this target scope was pretty limited. The scope was - xyz.com admin.xyz.com api.xyz.com The subdomain admin.xyz.com looks interesting and I quickly used search.censys.io to look for any beta or dev environment for this admin subdomain using the query - [External link warning page bypass in Zerocopter](https://0xprial.com/external-link-warning-page-bypass-in-zerocopter/) - Description: zerocopter.com is a bug bounty platform for Ethical hackers just like Hackerone. In Zerocopter reports, users can use Markdown. Users are also allowed to give external links in reports. If a user clicks on the External link in reports then it takes the user to an external warning page like the below screenshot But I - [Unclaimed Medium Publication takeover in WeTransfer](https://0xprial.com/wetransfer-unclaimed-medium-publication-takeover/) - Today I will share a Security issue I found on WeTransfer. WeTransfer has a paid bug-bounty program under Zerocopter. So I start testing their sites. While I was brute-forcing wetransfer.com with DIRB script I got some directories what was redirecting users to the Medium Publication link. Those directories look like https://wetransfer.com/blogger (CODE:301|SIZE:0) (Location: ‘https://medium.com/wetransferger') https://wetransfer.com/bloggers (CODE:301|SIZE:0) - [Subdomain takeover due to misconfigured project settings](https://0xprial.com/subdomain-takeover-due-to-misconfigured-settings/) - Hi readers, Today I will write about Subdomain takeover. It’s a common Security issue that is actually a developers mistake when they left an Unused/unclaimed 3rd party Service DNS CNAME record for a subdomain of theirs and Hackers can claim those subdomains with the help of external services, it pointing to what could lead to serious - [Vine User’s Private information disclosure](https://0xprial.com/vine-users-private-information-disclosure/) - What is Vine? Vine was an American social networking short-form video hosting service where users could share six or seven second-long, looping video clips. It was founded in June 2012; American microblogging website Twitter acquired it in October 2012, well before its official release on January 24, 2013. Today I will write about a Critical - [How I earned 5040$ from Twitter by showing a way to Harvest other users IP address](https://0xprial.com/how-i-earned-5040-from-twitter-bugbounty/) - Hi guys, This is one of my old finding adding to my blog. Recently I disclosed a POC on How I was able to get all vine user's sensitive Information including Phone no/IP Address/Emails and Many more that was reported to Twitter and they patched it and rewarded me 7560$. Those who missed it you - [XSS bypass using META tag in realestate.postnl.nl](https://0xprial.com/xss-bypass-using-meta-tag-in-realestate-postnl-nl/) - Hi readers, Today I will write about a XSS Vulnerability I reported to the postnl.nl bug bounty Program. Reflected XSS A reflected XSS (or also called a non-persistent XSS attack) is a specific type of XSS whose malicious script bounces off of another website to the victim's browser. It is passed in the query, typically, - [Unicode vs WAF — XSS WAF Bypass](https://0xprial.com/unicode-vs-waf-xss-waf-bypass/) - Hi readers, At 1st Eid Mubarak to all. May Allah bring you joy, happiness, peace, and prosperity on this blessed occasion. Wishing you and your family on this happy occasion of Eid! Eid Mubarak! So on this blessed occasion I thought let’s share one of my findings as an Eid bonus 😜 ! From the - [XSS WAF & Character limitation bypass like a boss](https://0xprial.com/xss-waf-character-limitation-bypass-like-a-boss/) - Hello fellow Hackers! I am sitting in my room for the last 3 days due to the coronavirus outbreak worldwide and feeling really bored. So I thought why not do a write-up of what I promised really long ago 🤭. A few months back in My Tweet I shared a way to bypass XSS WAF - [How to Get Into Bug Bounties - Part 01](https://0xprial.com/how-to-get-into-bug-bounties-part-01/) - A common question nowadays is "How to get started in Bug Bounties?" and I keep on getting this message on a day to day basis. It’s not possible for me to respond to each and every message, so I thought I’d rather do a blog post and would direct all those beginners to this blog - [IDOR Leads To Leak Any Uber Eats Restaurant Analytics](https://0xprial.com/idor-leads-to-leak-any-uber-eats-restaurant-analytics/) - Hi fellow Hackers,At first Ramadan Kareem! Wishing everyone a very happy Ramadan. Today I will write about an Insecure direct object references (IDOR) vulnerability that I recently discovered in Uber Eats Restaurant. The Uber Eats Restaurant web application at https://restaurant.uber.com/ is using GraphQL. Back in March, I was doing a collaboration on a Uber report - [Subdomain Hijacking Of Any Qwilr's Customer](https://0xprial.com/subdomain-hijacking-of-any-qwilrs-customer/) - First Happy new year to fellow Hackers, I was planning to write on my blog regularly for the last few months, but I could not do that due to my lack of time and laziness. So here's a new year gift for you guys ? Back in October 2022, I was testing a really old ## Pages - [HOME](https://0xprial.com/) - Hi I'm Prial Islam AKA OxPrial I am a full-time student of Power Engineering and a part-time learner at Cyber Security stuffs. Also doing Bug Bounty hunting and currently ranked 125th on Synack Red Team, 120th on Bugcrowd, and have over 3000 Reputation Points on HackerOne Bug Bounty Platform - [Blog](https://0xprial.com/blog/) - Test post Test post content The Art Of Zendesk Hijacking Back in July 2023, I was testing a HackerOne Private Program [ let’s call this target xyz.com ] and this target scope was pretty limited. The scope was – xyz.com admin.xyz.com api.xyz.com… Subdomain Hijacking Of Any Qwilr’s Customer First Happy new year to fellow Hackers, I was - [Contact](https://0xprial.com/contact/) - You Need To Know Something Drop A Line - [Privacy Policy](https://0xprial.com/privacy-policy/) - Privacy Policy Last updated: December 19, 2020 This Privacy Policy describes Our policies and procedures on the collection, use and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You. We use Your Personal data to provide and improve the Service. By using - [Terms & Condition](https://0xprial.com/terms-condition/) - Terms And Conditions Last Updated: December 19, 2020 Please Read These Terms And Conditions Carefully Before Using Our Service. Interpretation And Definitions Interpretation The Words Of Which The Initial Letter Is Capitalized Have Meanings Defined Under The Following Conditions. The Following Definitions Shall Have The Same Meaning Regardless Of Whether They Appear In Singular Or - [Site Map](https://0xprial.com/site-map/) - Post How to Get Into Bug Bounties – Part 01 IDOR Leads To Leak Any Uber Eats Restaurant Analytics XSS WAF & Character limitation bypass like a boss Unicode vs WAF — XSS WAF Bypass XSS bypass using META tag in realestate.postnl.nl How I earned 5040$ from Twitter by showing a way to Harvest other ## My Templates - [single post](https://0xprial.com/?elementor_library=single-post) - Back To Blog Back To Home RECENT TWEETS Tweets by 0xPrial RECENT POSTS - [Footer](https://0xprial.com/?elementor_library=footer) - Sometimes, Hacking Is Just Someone Spending More Time On Something Than Anyone Else Might Reasonably Expect Facebook Icon-x-twitter Linkedin Youtube Github Useful Link Contact Privacy Policy Terms & Condition Site Map Newsletter © All Rights Reserved By Prial Islam - [Header](https://0xprial.com/?elementor_library=header) - Contact Me - [Header Final](https://0xprial.com/?elementor_library=header-final) - Contact Me - [Default Kit](https://0xprial.com/?elementor_library=default-kit) - [sec1](https://0xprial.com/?elementor_library=sec1) - [sec4](https://0xprial.com/?elementor_library=sec4) - [sec3](https://0xprial.com/?elementor_library=sec3) - [sec2](https://0xprial.com/?elementor_library=sec2) - [sec5](https://0xprial.com/?elementor_library=sec5) - [zero](https://0xprial.com/?elementor_library=zero) - [zerocopter](https://0xprial.com/?elementor_library=zerocopter) - [Twitter](https://0xprial.com/?elementor_library=twitter) - [Microsoft](https://0xprial.com/?elementor_library=microsoft) - [Google](https://0xprial.com/?elementor_library=google) - [Facebook](https://0xprial.com/?elementor_library=facebook) - [Hacker1](https://0xprial.com/?elementor_library=hacker1) - [Bugcrowd](https://0xprial.com/?elementor_library=bugcrowd) - [Shopify](https://0xprial.com/?elementor_library=shopify) - [uber](https://0xprial.com/?elementor_library=uber) - [Quora](https://0xprial.com/?elementor_library=quora) - [yahoo](https://0xprial.com/?elementor_library=yahoo) - [nokia](https://0xprial.com/?elementor_library=nokia) - [Sony](https://0xprial.com/?elementor_library=sony) - [Github](https://0xprial.com/?elementor_library=github) ## Categories - [Bug Bounty](https://0xprial.com/category/bug-bounty/) ## Tags - [Bug Bounty](https://0xprial.com/tag/bug-bounty/) - [bypass](https://0xprial.com/tag/bypass/) - [Cyber Security](https://0xprial.com/tag/cyber-security/) - [fuzzing](https://0xprial.com/tag/fuzzing/) - [HackerOne](https://0xprial.com/tag/hackerone/) - [IP](https://0xprial.com/tag/ip/) - [Long/Decimal](https://0xprial.com/tag/long-decimal/) - [Zerocopter](https://0xprial.com/tag/zerocopter/) - [Medium Publication takeover](https://0xprial.com/tag/medium-publication-takeover/) - [WeTransfer](https://0xprial.com/tag/wetransfer/) - [Subdomain Takeover](https://0xprial.com/tag/subdomain-takeover/) - [IDOR](https://0xprial.com/tag/idor/) - [information disclosure](https://0xprial.com/tag/information-disclosure/) - [Insecure direct object references (IDOR)](https://0xprial.com/tag/insecure-direct-object-references-idor/) - [Vine](https://0xprial.com/tag/vine/) - [vine.co](https://0xprial.com/tag/vine-co/) - [Cross Site Scripting](https://0xprial.com/tag/cross-site-scripting/) - [PostNL](https://0xprial.com/tag/postnl/) - [WAF Bpass](https://0xprial.com/tag/waf-bpass/) - [XSS](https://0xprial.com/tag/xss/) - [XSS Bypass](https://0xprial.com/tag/xss-bypass/) - [Unicode](https://0xprial.com/tag/unicode/) - [Bug Bounties](https://0xprial.com/tag/bug-bounties/) - [Ethical Hacking](https://0xprial.com/tag/ethical-hacking/) - [Get Into Bug Bounties](https://0xprial.com/tag/get-into-bug-bounties/) - [Hacking](https://0xprial.com/tag/hacking/) - [Subdomain Hijacking](https://0xprial.com/tag/subdomain-hijacking/) - [Zendesk](https://0xprial.com/tag/zendesk/) - [Account Takeover](https://0xprial.com/tag/account-takeover/)