0_oNoProblem·Sep 1, 2025The Little CV + CSRF That Broke an Accountالسَّلاَمُ عَلَيْكُمْ وَرَحْمَةُ اللهِ وَبَرَكَاتُهُ. اللَّهُمَّ صَلِّ عَلَى مُحَمَّدٍ وَعَلَى آلِ مُحَمَّدٍ، كَمَا صَلَّيْتَ عَلَى…
0_oNoProblem·Feb 25, 2025How I Exploited a Hidden Race Condition to Bypass Licensing and Claim All Subdomains on the targetالسَّلاَمُ عَلَيْكُمْ وَرَحْمَةُ اللهِ وَبَرَكَاتُهُA response icon3A response icon3
0_oNoProblem·Feb 19, 2025Unauthorized Access to Internal Panel via Response ManipulationHi everyone, I’m Ahmed Ehab, but many in the security community know me as Nopr. Today, I’d like to share an interesting bug I discovered…A response icon2A response icon2
0_oNoProblem·May 20, 2024Reflected XSS Leading to Account TakeoverHello everyone,A response icon1A response icon1