<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://ayoubsafa.com/</id><title>Ayoub Safa</title><subtitle>AppSec Engineer • Security Researcher </subtitle> <updated>2026-02-11T12:58:12+00:00</updated> <author> <name>Ayoub Safa</name> <uri>https://ayoubsafa.com/</uri> </author><link rel="self" type="application/atom+xml" href="https://ayoubsafa.com/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://ayoubsafa.com/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 Ayoub Safa </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>Neo4j Injection / Cypher Injection</title><link href="https://ayoubsafa.com/posts/Neo4j_injection_(Cypher-Injection)/" rel="alternate" type="text/html" title="Neo4j Injection / Cypher Injection" /><published>2025-01-30T17:00:00+00:00</published> <updated>2025-01-30T17:00:00+00:00</updated> <id>https://ayoubsafa.com/posts/Neo4j_injection_(Cypher-Injection)/</id> <content src="https://ayoubsafa.com/posts/Neo4j_injection_(Cypher-Injection)/" /> <author> <name>Ayoub Safa</name> </author> <category term="SQLi" /> <category term="Neo4j" /> <category term="Cypher" /> <category term="Burp" /> <category term="Time Based Payload" /> <category term="Out of Band Payload" /> <summary> Hi everyone, It’s been a while since I wrote a proper write-up. So recently I came across a class of vulnerability I’d never seen before, even after 10+ years poking at web apps. At first I assumed it was SQL injection, but it wasn’t. It turned out to be Neo4j / Cypher injection, a thing a lot of people overlook. In this write-up, I’ll walk you through how I identified and exploited this vuln... </summary> </entry> <entry><title>Hunting for bugs that Scanners miss, and WAFs fail to detect: SteelCon Talk UK 2023</title><link href="https://ayoubsafa.com/posts/SteelCon-Talk-2023/" rel="alternate" type="text/html" title="Hunting for bugs that Scanners miss, and WAFs fail to detect: SteelCon Talk UK 2023" /><published>2023-07-08T16:00:00+01:00</published> <updated>2023-07-08T16:00:00+01:00</updated> <id>https://ayoubsafa.com/posts/SteelCon-Talk-2023/</id> <content src="https://ayoubsafa.com/posts/SteelCon-Talk-2023/" /> <author> <name>Ayoub Safa</name> </author> <category term="JWT" /> <category term="UUID" /> <category term="Account Takeover" /> <category term="IDOR" /> <category term="Password Reset" /> <summary> Most web applications today are protected by WAFs, making it challenging for pentesters to test for payload-based vulnerabilities like SQL Injection and XSS. Additionally, automated tools and scanners can easily identify some of these vulnerabilities, making it even more challenging for bug bounty hunters to find such issues. In this talk, we will discuss a different class of vulnerabilities t... </summary> </entry> <entry><title>Uncommon and Advanced Techniques for Account Takeover Attacks: BSides Talk Leeds 2023</title><link href="https://ayoubsafa.com/posts/Bsides-Leeds-Talk-2023/" rel="alternate" type="text/html" title="Uncommon and Advanced Techniques for Account Takeover Attacks: BSides Talk Leeds 2023" /><published>2023-07-08T16:00:00+01:00</published> <updated>2023-07-08T16:00:00+01:00</updated> <id>https://ayoubsafa.com/posts/Bsides-Leeds-Talk-2023/</id> <content src="https://ayoubsafa.com/posts/Bsides-Leeds-Talk-2023/" /> <author> <name>Ayoub Safa</name> </author> <category term="JWT" /> <category term="UUID" /> <category term="Account Takeover" /> <category term="Password Reset" /> <summary> Account takeover attacks are a serious threat to individuals and organizations and are becoming increasingly common. In order to stay ahead of cybercriminals, it is important for Developers and Pentesters to have a strong understanding of advanced and uncommon techniques for performing account takeover attacks. In this talk, we will explore a range of techniques that are not commonly known or ... </summary> </entry> <entry><title>Story of OS Command Injection worth $7500</title><link href="https://ayoubsafa.com/posts/Story-of-Command_injection_worth_$7500/" rel="alternate" type="text/html" title="Story of OS Command Injection worth $7500" /><published>2021-10-15T18:00:00+01:00</published> <updated>2021-10-15T18:00:00+01:00</updated> <id>https://ayoubsafa.com/posts/Story-of-Command_injection_worth_$7500/</id> <content src="https://ayoubsafa.com/posts/Story-of-Command_injection_worth_$7500/" /> <author> <name>Ayoub Safa</name> </author> <category term="Command Injection" /> <category term="RCE" /> <category term="out-of-band" /> <category term="OOB" /> <summary> Command injection is a type of vulnerability that allows an attacker to execute arbitrary system commands on a vulnerable server. This type of attack occurs when an application fails to properly validate user input and passes it to a command shell, which can be exploited by an attacker to run malicious commands. Recently, I came across a private program on HackerOne that was vulnerable to comm... </summary> </entry> <entry><title>The Bad Twin: a peculiar case of JWT exploitation scenario leading to Account Taker Over</title><link href="https://ayoubsafa.com/posts/The-Bad-Twin-a-peculiar-case-of-JWT-exploitation-scenario/" rel="alternate" type="text/html" title="The Bad Twin: a peculiar case of JWT exploitation scenario leading to Account Taker Over" /><published>2020-05-07T18:00:00+01:00</published> <updated>2020-05-07T18:00:00+01:00</updated> <id>https://ayoubsafa.com/posts/The-Bad-Twin-a-peculiar-case-of-JWT-exploitation-scenario/</id> <content src="https://ayoubsafa.com/posts/The-Bad-Twin-a-peculiar-case-of-JWT-exploitation-scenario/" /> <author> <name>Ayoub Safa</name> </author> <category term="JWT" /> <category term="ATO" /> <category term="Acoount Takeover" /> <summary> Hey Everyone, Hope you’re doing well. It’s been a While since my first write-up, I hope you learn something new from this one and enjoy it. This post presents a new technique to exploit a bad implementation of JWT under specific circumstances, which allowed me to perform an Account Takeover attack and score a nice $3000 bounty. This is a simple yet very interesting thing I found, that’s why I... </summary> </entry> </feed>
