therceman
الذهاب إلى القناة على Telegram
2 256
المشتركون
لا توجد بيانات24 ساعات
لا توجد بيانات7 أيام
+530 أيام
جاري تحميل البيانات...
القنوات المماثلة
سحابة العلامات
لا توجد بيانات
هل تواجه مشاكل؟ يرجى تحديث الصفحة أو الاتصال بمدير الدعم الخاص بنا.
الإشارات الواردة والصادرة
---
---
---
---
---
---
جذب المشتركين
أكتوبر '24
أكتوبر '24
+20
في 0 قنوات
سبتمبر '240
في 0 قنوات
Get PRO
أغسطس '24
+41
في 1 قنوات
Get PRO
يوليو '24
+67
في 0 قنوات
Get PRO
يونيو '24
+29
في 1 قنوات
Get PRO
مايو '24
+58
في 0 قنوات
Get PRO
أبريل '24
+47
في 0 قنوات
Get PRO
مارس '24
+53
في 0 قنوات
Get PRO
فبراير '24
+73
في 0 قنوات
Get PRO
يناير '24
+149
في 0 قنوات
Get PRO
ديسمبر '23
+138
في 0 قنوات
Get PRO
نوفمبر '23
+60
في 0 قنوات
Get PRO
أكتوبر '23
+775
في 0 قنوات
Get PRO
سبتمبر '23
+145
في 0 قنوات
Get PRO
أغسطس '23
+32
في 0 قنوات
Get PRO
يوليو '23
+37
في 0 قنوات
Get PRO
يونيو '23
+54
في 0 قنوات
Get PRO
مايو '23
+38
في 0 قنوات
Get PRO
أبريل '23
+53
في 0 قنوات
Get PRO
مارس '23
+142
في 0 قنوات
Get PRO
فبراير '23
+263
في 0 قنوات
Get PRO
يناير '23
+115
في 0 قنوات
Get PRO
ديسمبر '22
+109
في 0 قنوات
Get PRO
نوفمبر '22
+276
في 0 قنوات
| التاريخ | نمو المشتركين | الإشارات | القنوات | |
| 15 أكتوبر | +5 | |||
| 14 أكتوبر | +6 | |||
| 13 أكتوبر | +6 |
منشورات القناة
| 2 | TryHackMe Room
🔗 https://lnkd.in/dddbzjUb
Python Scanner
🔗 https://lnkd.in/d44YnG9U
Cheers!
#BAC | 903 |
| 3 | #XSS | 844 |
| 4 | Bug Bounty Tip
Bypass XSS WAF protection using Whitespace Separators between a JS function name and parameters
<img/src/onerror=alert(1337)>
Refer to the attached image for the full list of Whitespace Separators.
P.S. can be used before function name too.
Cheers! | 911 |
| 5 | Bug Bounty Tip
When testing an app for SQL injection, don't forget to check the form keys in addition to the values
Sometimes, developers may overlook applying protection to form keys
To bypass spaces, you can use the encoded tab %09. For other symbols, simply URL encode them
#SQLinjection | 919 |
| 6 | <img/src/onerror=setTimeout(atob(/YWxlcnQoMTMzNyk/.source))>
#XSS | 1 067 |
| 7 | <img/src/onerror=setTimeout(atob(/YWxlcnQoMTMzNyk/.source))>
#XSS | 1 |
| 8 | #DefaultCreds | 1 031 |
| 9 | #XSS | 920 |
| 10 | More info here
https://x.com/godfatherorwa/status/1647406811216072705
#SQLinjection | 898 |
| 11 | #XSS | 771 |
| 12 | #XSS | 723 |
| 13 | - (function(x){this[x+`ert`](1)})`al`
- window[`al`+/e/[`ex`+`ec`]`e`+`rt`](2)
- document['default'+'View'][`\u0061lert`](3)
#XSS | 663 |
| 14 | #XSS | 584 |
| 15 | #XSS | 527 |
| 16 | #XSS #CRLF | 508 |
| 17 | #XSS #SQLi #SSTI #CSTI | 499 |
| 18 | More info here
https://blog.detectify.com/industry-insights/bypassing-cloudflare-waf-with-the-origin-server-ip-address/
#WAF | 518 |
| 19 | Text version can be found on X
https://x.com/therceman/status/1711828964103147871
#WAF | 561 |
| 20 | Bug Bounty Tip
PHP Info Page Exposure.
There's a lot of sensitive information that can be obtained from an exposed PHP Info page, from configuration secrets to exposed user session cookies.
For example, when chained with XSS, this can lead to a full account takeover.
Cheers!
#Recon #XSS #InformationDisclosure | 543 |
