Ahmad Halabi·Aug 3, 2025Stored XSS to Privilege Escalation to Admin Takeover to Data BreachChain of Vulnerability Sequence (Stored XSS ➝ Privilege Escalation ➝ Admin Takeover ➝ Sensitive Data Leak ➝ Company at Risk)A response icon4A response icon4
Ahmad Halabi·Dec 23, 2023The ART of Chaining VulnerabilitiesDeep Dive into breaking applications and chaining vulnerabilities to hack complete infrastructures.A response icon5A response icon5
Ahmad Halabi·Aug 12, 2023From Revealing Emails to Taking Over Accounts (Hacking Telecom)Hacking Telecom — Revealing user’s emails then taking over their accounts.A response icon4A response icon4
Ahmad Halabi·Jul 7, 2022PII Disclosure of Apple Users ($10k)How I hacked Apple and was able to Disclose Apple Users Private Shipping Information and Mobile Numbers.A response icon15A response icon15
Ahmad Halabi·Dec 22, 2021Ultimate Reconnaissance RoadMap for Bug Bounty Hunters & PentestersAdvanced Reconnaissance and Web Application Discovery RoadMap to Find Massive Vulnerabilities.A response icon15A response icon15
Ahmad Halabi·Aug 13, 2021Taking Over Employee Accounts by Managers with Zero Employee InteractionHello,
Ahmad Halabi·Jun 26, 2021My Experience For 2 Years In Bug Bounty HuntingMy experience and achievements that were gathered during Bug Bounty Hunting that I started 2 years ago.A response icon7A response icon7
InInfoSec Write-upsbyAhmad Halabi·Apr 24, 2021RCE via Internal Access to Adminer Database Management (Critical)How I was able to access an internal Database Management leading to Remote Code Execution.A response icon3A response icon3
Ahmad Halabi·Mar 7, 2021Finding Hidden Login Endpoint Exposing Secret `Client ID`From Low to High Severity Vulnerability. Finding Hidden Login Endpoint Exposing Secret `Client ID`.A response icon4A response icon4
Ahmad Halabi·Feb 28, 2021Secret Key Exposure in API Config DirectorySecret Key Exposure - High SeverityA response icon2A response icon2