YamiSec

YamiSec Hey, I'm Yamisec I’m a learner and a builder, focused on growth and self-improvement. I believe in consistency, discipline, and earning every step forward.

Just published a deep dive into JWT (JSON Web Tokens)!In this article, I cover JWT fundamentals from the ground up — inc...
26/07/2026

Just published a deep dive into JWT (JSON Web Tokens)!

In this article, I cover JWT fundamentals from the ground up — including token structure, claims, signing algorithms, authentication flow, symmetric vs asymmetric cryptography, key management, and common JWT security vulnerabilities.

If you're interested in Web Security, Application Security, or Bug Bounty, this guide should help you build a strong foundation in JWT.

Read the full article on Medium and let me know your thoughts!

🔗 https://yamisec.medium.com/everything-you-need-to-know-about-jwt-from-basics-to-advanced-concepts-e15b84587eee

JWT Fundamentals: A Complete A-to-Z Guide to JSON Web Tokens

29/06/2026

Nullsec is now Yamisec

11/01/2026

Grateful to have participated in HackerOne and Bug Bounty Community Bangladesh Presents HackerOne BUG HUNT 2026, one of Bangladesh’s premier cybersecurity events that brings together real-world bug hunting challenges, expert-driven learning and networking.

Events like this play a crucial role in bridging the gap between academic learning and real-world cybersecurity practices. Looking forward to applying these learnings in future research and community initiatives.

11/01/2026

HackerOne Bughunt 2026

Top 10 Advanced Nikto Commands for Bug Bounty & Pe*******on Testing>> Full Advanced Scan (All Ports & All Tests) > Ultra...
19/12/2025

Top 10 Advanced Nikto Commands for Bug Bounty & Pe*******on Testing

>> Full Advanced Scan (All Ports & All Tests) > Ultra Stealth WAF Bypass Scan > SQL Injection & Authentication Bypass > XSS, LFI, RFI & Command Ex*****on > Hidden Admin Panels & Subdomain Bruteforce > Directory & Sensitive File Discovery > Quick High-Speed Scan > Web Server & Misconfiguration Detection > CMS (WordPress, Joomla, Drupal) Exploit Scan > Full Vulnerability Scan with Maximum Mutation

Advanced API Fuzzing with External Mutators >> Using Radamsa to Fuzz JSON API Payloads Command >>ffuf --input-cmd 'radam...
19/12/2025

Advanced API Fuzzing with External Mutators >> Using Radamsa to Fuzz JSON API Payloads

Command >>
ffuf --input-cmd 'radamsa --seed $FFUF_NUM example_payload.json' -H "Content-Type: application/json" -X POST -u https://target/api/endpoint -mc all -fc 400


What it does:
>> Fuzzes JSON data using radamsa, generating mutated payloads from example_payload.json.

>> Sends POST requests with each fuzzed payload to the target API.

>> Filters out 400 responses (usually indicating invalid input), but logs all others for analysis.

Address

Tejgaon
Dhaka

Alerts

Be the first to know and let us send you an email when YamiSec posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Shortcuts

Share

Category