<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Anas Hamidi</title>
    <link>https://anashamidi.com/</link>
    <description>Blog über Offensive Security: Bug Bounty, Penetration Testing, Write-ups, Tooling-Notizen und ausgewählte Security-News.</description>
    <generator>Hugo</generator>
    <language>de</language>
      <managingEditor>Anas Hamidi</managingEditor>
      <webMaster>Anas Hamidi</webMaster>
    <copyright>2026 Anas Hamidi</copyright>
      <lastBuildDate>Sat, 05 Sep 2026 00:00:00 +0000</lastBuildDate>
      <atom:link href="https://anashamidi.com/index.xml" rel="self" type="application/rss+xml" />
      <item>
        <title>Random Notes on Bug Bounty Tools That Actually Work</title>
        <link>https://anashamidi.com/en/posts/bug-bounty-tools-that-actually-work/</link>
        <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
        <guid>https://anashamidi.com/en/posts/bug-bounty-tools-that-actually-work/</guid>
        <description>A few tools I reach for every day in my bug bounty workflow: httpx, notify, anew, Param Miner, hakrawler, jq/cut/awk, Logger++ and GitHub recon, with the exact flags I use.</description>
          <category>bug-bounty</category>
          <category>recon</category>
          <category>tools</category>
          <category>automation</category>
          <category>web-security</category>
      </item>
      <item>
        <title>Be Patient and Keep it Simple, The Bug is There</title>
        <link>https://anashamidi.com/en/posts/be-patient-keep-it-simple/</link>
        <pubDate>Sat, 02 Aug 2025 00:00:00 +0000</pubDate>
        <guid>https://anashamidi.com/en/posts/be-patient-keep-it-simple/</guid>
        <description>Two simple but high-impact findings, and the lessons that led me to them.</description>
          <category>bug-bounty</category>
          <category>idor</category>
          <category>access-control</category>
          <category>web-security</category>
      </item>
      <item>
        <title>Hunting for Hidden API Endpoints Using Katana and Hakrawler</title>
        <link>https://anashamidi.com/en/posts/hunting-hidden-api-endpoints-katana-hakrawler/</link>
        <pubDate>Mon, 09 Sep 2024 00:00:00 +0000</pubDate>
        <guid>https://anashamidi.com/en/posts/hunting-hidden-api-endpoints-katana-hakrawler/</guid>
        <description>Crawling a target I thought I knew — with Katana, hakrawler, waybackurls, and unfurl — surfaced a hidden /HelpApi/ endpoint and an IDOR leaking users' PII.</description>
          <category>bug-bounty</category>
          <category>recon</category>
          <category>idor</category>
          <category>api</category>
          <category>web-security</category>
      </item>
      <item>
        <title>How easy I made $$$$</title>
        <link>https://anashamidi.com/en/posts/how-easy-i-made-money/</link>
        <pubDate>Tue, 23 Apr 2024 00:00:00 +0000</pubDate>
        <guid>https://anashamidi.com/en/posts/how-easy-i-made-money/</guid>
        <description>A reality check on bug bounty and the myth of easy money.</description>
          <category>bug-bounty</category>
          <category>mindset</category>
          <category>career</category>
      </item>
      <item>
        <title>Don&#39;t Trust the Cache: Exposing Web Cache Poisoning and Deception Vulnerabilities</title>
        <link>https://anashamidi.com/en/posts/web-cache-poisoning-and-deception/</link>
        <pubDate>Fri, 05 Apr 2024 00:00:00 +0000</pubDate>
        <guid>https://anashamidi.com/en/posts/web-cache-poisoning-and-deception/</guid>
        <description>A field guide to web cache attacks — from CP-DoS tricks (oversize headers, meta characters, method override, unkeyed ports, redirect DoS) to poisoning with XSS payloads and web cache deception via path confusion.</description>
          <category>bug-bounty</category>
          <category>web-cache-poisoning</category>
          <category>web-security</category>
          <category>dos</category>
          <category>xss</category>
      </item>
      <item>
        <title>Click, Intercept, Hack: Checkmate on Access Control Vulnerability</title>
        <link>https://anashamidi.com/en/posts/click-intercept-hack-access-control/</link>
        <pubDate>Thu, 07 Mar 2024 00:00:00 +0000</pubDate>
        <guid>https://anashamidi.com/en/posts/click-intercept-hack-access-control/</guid>
        <description>A Broken Access Control bug on a chess platform, via request interception and cookie swapping.</description>
          <category>bug-bounty</category>
          <category>access-control</category>
          <category>burp-suite</category>
          <category>web-security</category>
      </item>
      <item>
        <title>Bugs &amp; JS: A Closer Look at JavaScript for Successful Bug Hunting</title>
        <link>https://anashamidi.com/en/posts/javascript-for-bug-hunting/</link>
        <pubDate>Wed, 10 Jan 2024 00:00:00 +0000</pubDate>
        <guid>https://anashamidi.com/en/posts/javascript-for-bug-hunting/</guid>
        <description>Why JavaScript files are a goldmine for bug hunters — the tools (JSleak, JSecret, jsluice), the workflow, and the resources I use to dig secrets, endpoints, and client-side bugs out of JS.</description>
          <category>bug-bounty</category>
          <category>javascript</category>
          <category>recon</category>
          <category>web-security</category>
      </item>
      <item>
        <title>How One Bug Scored Me Double Rewards!</title>
        <link>https://anashamidi.com/en/posts/how-one-bug-scored-me-double-rewards/</link>
        <pubDate>Tue, 19 Dec 2023 00:00:00 +0000</pubDate>
        <guid>https://anashamidi.com/en/posts/how-one-bug-scored-me-double-rewards/</guid>
        <description>A forgotten subdomain, a Shodan dork, and a single PUT request — how one overlooked endpoint led to an information disclosure and then an IDOR into users' video session data.</description>
          <category>bug-bounty</category>
          <category>idor</category>
          <category>recon</category>
          <category>web-security</category>
      </item>
  </channel>
</rss>
