BePractical
Open in Telegram
If you have any doubts then email at faiyazahmad.online@gmail.com
Show more7 357
Subscribers
No data24 hours
-417 days
-4630 days
Posts Archive
7 357
Discussion #2: Which is the tool that you commonly use when doing web recon?
(Comment it down below)
For me it's Ffuf
7 357
POV: It's late at night.. Your internet pack has just expired.. So you hacked your neighbors WiFi
#hackerman😎
7 357
#Discussion 1: How can you start in bug bounty?
(Comment down your thoughts on how can be begin the hunting journey & let's start discussion on it!)
7 357
Found XSS by bypassing the misconfigured CSP in one of the govt website of India!
Tip: Check out this new amazing tool that will be very useful in fuzzing interesting payloads, tags & events that will be useful when bypassing waf or csp (https://github.com/Asperis-Security/xssFuzz)
7 357
+1
I still remember the time(2020)when I had no laptop/pc so I used to run kali linux on my Android device to learn hacking & pen testing.
And now, 4 years later: I have three awesome laptop with each of them hazing unique use cases!
(The one at the top is my first laptop and it is really priceless to me)
I would really like to thank God, my parents, all of my fellow subscribers on BePractical and telegram members here for supporting me throughout my journey! ❤️
7 357
Hi everyone, The new video is out!
Learn how to chain reflected xss with cors misconfiguration to increase its impact
Video Link: https://www.youtube.com/watch?v=Rz44oTCxULs
7 357
Just finished up the video! Will be releasing tomorrow, I am pretty sure you all will learn something valuable from it
7 357
Hey everyone! I can’t believe I’m saying this, but we’ve just crossed over 21K subscribers on the channel! 🎉
Honestly, I’m so grateful to each and every one of you. Your support, comments, and just being here means the world to me. This journey has been an incredible ride, and I couldn’t have done it without you all cheering me on. Thank you for being part of this adventure—I appreciate you more than words can say!
7 357
Hi everyone! The new video is out!!!
Check out this video and learn everything about CORS Misconfiguration with live demonstration
Video Link: https://youtu.be/LqkElGac3oA
7 357
This is why I never recommend anyone to be full time bug bounty hunter. I have reported a SSRF protection bypass vulnerability to a private program. Normally they used to reply in 1 day but this time they took around 1 week!
In the meantime, They quietly fixed this vulnerability in the background and now saying that they cannot reproduce the issue. Trust me, when this happens, it just shatters your heart
Therefore, I always recommend everyone to do bug bounty only to upskill their hacking game!
7 357
Just finished shooting the next video. Will be releasing it this week! Can anyone guess the topic? 😉
Hint: It's a little similar to CSRF but on modern applications using REST api
7 357
August was overall a blessed month for me!
This month, I had some time to look back and hack on some private bug bounty programs. I was committed focus on only two private programs and the result? Well, I have:
* Reported over 20 valid vulnerabilities
* Five bounties pending
* Reported High severity vulnerability
* Improved my focus and consistency on hacking!
Overall, it was an awesome month for me!
7 357
Pov: It's late night, You were just about to sleep then suddenly you come up with a new method to bypass SSRF protection and it worked!!
7 357
Hi guys, In case you are free then do checkout this awesome report: https://hackerone.com/reports/180074
