~/blog
HomeAboutTagsRSS
  • 2026-08-12 📌 مثبت

    تجربة تعلم لغة ثالثة

    بديت أتعلم أردو بدون سبب جِدّي.

    • أردية
    • لغة
  • 2026-07-27 📌 مثبت

    أفكار مجانية

    مجموعة من أفكار المشاريع التقنية، مطروحة للاطلاع والبناء عليها بحرية (بغض النظر عن جدواها الإقتصادية)، كل فكرة مصحوبة بنبذة موجزة، وبمصادر أو مراجع للاستزادة…

    • idea
  • 2026-08-12

    No Login Required: Breaking Down NumberBook's Caller-ID API

    NumberBook (نمبر بوك السعودية) is a Saudi caller-ID app: install it, hand over your contacts, and in exchange it tells you who's calling from a number you…

    • mobile
    • recon
    • privacy
    • disclosure
  • 2026-08-10

    Notes on Experiment!: Website Conversion Rate Optimization

    Some notes I took while reading Experiment! Website Conversion Rate Optimization with A/B and Multivariate Testing. It's less a testing-tool manual and more a…

    • ab-testing
    • ux
    • book
  • 2026-08-09

    One Bad Email Address, and a Dev Server Printed Its Database Password

    Early in 2025 I spent an evening poking at Shamela (المكتبة الشاملة), the huge Arabic Islamic-text library. It is the kind of site that is quietly load-bearing…

    • disclosure
    • secrets
  • 2026-08-08

    From a Google Search Result to a Live Cloud Key: Inside the StoryGo App's Backend

    It started with a single IP address in a Google search result. I was looking up an Android app's permissions, landed on an indexed page pointing at…

    • mobile
    • recon
    • secrets
    • disclosure
  • 2026-07-16

    Arguing a 'Not Applicable' Verdict: A Laravel Debug Page That Leaked a Private Repo

    Not every report closes the way the technical severity suggests it should. This is a writeup of a Laravel debug page finding that got marked Not Applicable,…

    • bounty
    • disclosure
  • 2026-07-16

    A Public sitemap.xml Isn't a Vulnerability, But What It Lists Might Be

    Not every closed report is wrong to close. This one is a case where the verdict was fair, but the report also stumbled onto a detail worth separating out from…

    • bounty
    • disclosure
    • recon
  • 2026-07-14

    Arguing a 'Not Applicable' Verdict: Hardcoded Google Maps API Keys Aren't Free

    Not every valid finding survives triage on the first pass. This is a short writeup of a report that got marked Not Applicable, and the case I made back, with…

    • bounty
    • disclosure
    • api
  • 2026-07-14

    Chaining a jQuery Prototype Pollution Bug with DOM XSS to Steal CSRF Tokens

    Old dependencies rarely die quietly, they just wait for someone to check the version string. This is a walkthrough of a bug bounty submission where a…

    • bounty
    • xss
    • prototype-pollution
  • 2026-07-14

    When Username Enumeration Isn't a Vulnerability

    Not every report I've filed has held up, and I think that's worth writing about as much as the ones that did. This one is a case where the triage call was…

    • bounty
    • triage