Open in app

Sign In

Write

Sign In

Muhammad Daffa
Muhammad Daffa

130 Followers

Home

About

Jul 20, 2022

Maximizing the potential of “Subfinder”

Hi guys, in this post I will be sharing about how to maximize the potential of subfinder. So, what is subfinder? and how to use it properly? Subfinder is a subdomain discovery tool created by the ProjectDiscovery team that discovers valid subdomains for websites. Designed as a passive framework to…

Bug Bounty

7 min read

Maximizing the potential of the “Subfinder”
Maximizing the potential of the “Subfinder”
Bug Bounty

7 min read


Mar 18, 2022

How to Create Your Own Nuclei Template: Part 1 (Indonesia Version)

Perkenalkan nama saya Muhammad Daffa, seorang mahasiswa di salah satu kampus di Surabaya. Sekarang saya sedang bekerja part time sebagai vulnerability researcher di salah satu perusahaan cybersecurity di Dubai. Dan saya juga menjadi top contributor di repositori nuclei-templates. …

Nuclei

6 min read

How to Create Your Own Nuclei Template: Part 1 (Indonesia Version)
How to Create Your Own Nuclei Template: Part 1 (Indonesia Version)
Nuclei

6 min read


Mar 28, 2021

AWS S3 Bucket Misconfiguration in Trading Website

Hello, my name is Muhammad Daffa, in this post I will share my simple writeup about AWS S3 Bucket Misconfiguration that I found on the trading website. First, I am registering on the trading website and then looking for some common vulnerability like XSS in form, or a business logic…

Bug Bounty

2 min read

AWS S3 Bucket Misconfiguration in Trading Website
AWS S3 Bucket Misconfiguration in Trading Website
Bug Bounty

2 min read


Mar 7, 2021

Writeup ARACTF 2021 Website

Pada tanggal 7 Maret 2021, saya mengikuti lomba CTF yang diadakan oleh HMIT (Himpunan Mahasiswa Teknologi Informasi). Event tersebut bernama ARACTF. Disini saya akan membagikan writeup dari soal-soal yang saya kerjakan di ARACTF, lebih tepatnya saya mengerjakan bagian Website namun hanya bisa mengerjakan 2 karena saat mengerjakan soal yang ke-3…

3 min read

Writeup ARACTF 2021 Website
Writeup ARACTF 2021 Website

3 min read


Mar 7, 2021

IDOR di Website Penyedia “Bootcamp”

Nama saya Muhammad Daffa, disini saya akan membagikan writeup dari bug yang saya temukan, langsung saja disimak Beberapa minggu lalu saya mengikuti program bootcamp dikarenakan libur kuliah yang membuat saya menganggur tanpa melakukan hal positif, sudah beberapa minggu saya jalani program bootcamp tersebut dan tiba-tiba muncul pikiran “iseng” yaitu mencoba…

Bug Bounty

2 min read

IDOR di Website Penyedia “Bootcamp”
IDOR di Website Penyedia “Bootcamp”
Bug Bounty

2 min read


Feb 16, 2021

Bypass 2FA Using Status Code Manipulation

Hello, my name is Muhammad Daffa, in this post I want to share about a vulnerability that I found on a private program First, when I’m login to the website, it requires an OTP code to go to the dashboard, in this case, I’m using random OTP code to test…

Bug Bounty

1 min read

Bypass 2FA Using Status Code Manipulation
Bypass 2FA Using Status Code Manipulation
Bug Bounty

1 min read


Jan 28, 2021

How to Get 50$ Within 3 Minutes

Hi guys my name is Muhammad Daffa and this is my first write-up and I hope you like it. So I found source code exposure vulnerability on a private program within 3 minutes and I want to share it step by step. In this write-up, I’ll disclose the program's name. Step 1 — RECON! …

2 min read

How to Get 50$ Within 3 Minutes
How to Get 50$ Within 3 Minutes

2 min read

Muhammad Daffa

Muhammad Daffa

130 Followers

Vulnerability Researcher at spiderSilk

Following
  • Muhamad Hidayat

    Muhamad Hidayat

  • Triple A

    Triple A

  • YoKo Kho

    YoKo Kho

  • Axel Briano

    Axel Briano

  • Abay

    Abay

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech