Bug Bounty
Open in Telegram
Bugbounty Resources • Tips • Security Zines • Writeups • Vulnerability Update • Notes • Mindmaps • Cheatsheets • Checklists • Article / Blogs • PDFs • ebooks •
Show more9 446
Subscribers
No data24 hours
-37 days
-6030 days
Posts Archive
9 446
Bug Report as Document
Apache Tomcat :
• 🐞 BUG: HTTP Request Smuggling
• 📄 CVE ID: 2024-21733 | CWE: 444
Detailed Documentation : https://x.com/vulncure/status/1753271047355240874?s=20
9 446
API Testing Series #1 ✍️🪸
🔍 Key Highlights:
• 🫐 API Endpoints
• 🫑 Collection & Subcollection:
• 🥗 Gateway & 🥥Microservices Demystified
• 🥝 Web API Types
• ⚡️ CRUD Operations
• ❄️ 6 Constraints of Restful API
Let's Dive into the Details 👇⤵️
https://x.com/vulncure/status/1748018742158569966?s=20
9 446
PART - #4 ⚙️🔨
💨Mastering Jenkins RCE - Crafting and Modifying Projects 💼💻
Now, let's explore the art of Remote Code Execution (RCE) by creating and modifying projects in Jenkins.
🔑 Authority to tweak? Potent, if noisy! 🌪
Ready to amplify Jenkins skills? 🧵📷
https://x.com/vulncure/status/1746033898746736840?s=20
9 446
PART - #3 🕵️♂️🛠
Let's Crack The Jenkins Instance 🔓
Now, let's take the plunge into Remote Code Execution (RCE) using Groovy scripts. This method is stealthier than creating a new project, so buckle up:
Dive into the details 🧵:📷
https://x.com/vulncure/status/1745514588001701991?s=20
9 446
PART - #3 🕵️♂️🛠
Let's Crack The Jenkins Instance 🔓
Now, let's take the plunge into Remote Code Execution (RCE) using Groovy scripts. This method is stealthier than creating a new project, so buckle up:
Dive into the details 🧵:📷https://x.com/vulncure/status/1745514588001701991?s=20
9 446
PART - #2 🔐🛡
Understanding the Foundation: Jenkins Security Overview 🔐🛠
Before delving into exploitation, let's establish a solid understanding of key Jenkins security components:
Dive into the details 🧵:📷
https://x.com/vulncure/status/1744722597194186854?s=20
9 446
PART - #2 🔐🛡
Understanding the Foundation: Jenkins Security Overview 🔐🛠
Before delving into exploitation, let's establish a solid understanding of key Jenkins security components:
Dive into the details 🧵:📷
https://x.com/vulncure/status/1744722597194186854?s=20
9 446
Series #5
Top Known Bug Checklist ✅
Business Logic Error Cheatsheet🔻👇
#bugbounty #infosec
9 446
Bugbounty Reports in Threads 🧵
Bug : HTML sanitizer that allows an attacker to inject arbitrary unsafe HTML into emails, potentially lead to account compromise for hey .com's users who view the malicious emails
Type: XSS
Company: Basecamp
Siverity: Critical (9 ~ 10)
Bounty: $5,000
Dive into the details 🧵:📷
https://x.com/vulncure/status/1743998521575936387?s=20
9 446
Some Shodan Dorks that might useful in Bug Bounty.
1. org:"http://target.com"
2. http.status:"<status_code>"
3. product:"<Product_Name>"
4. port:<Port_Number> “Service_Message”
5. port:<Port_Number> “Service_Name”
6. http.component:"<Component_Name>"
7. http.component_category:"<Component_Category>
8. http.waf:"<firewall_name>"
9. http.html:"<Name>"
10. http.title:"<Title_Name>"
11. ssl.alpn:"<Protocol>"
12. http.favicon.hash:"<Favicon_Hash>"
13. net:"<Net_Range>" (for e.g. 104.16.100.52/32)
14. http://ssl.cert.subject.cn:"<http://Domain.com>"
15. asn:"<ASnumber>"
16. hostname:"<hosthame>"
17. ip:"<IP_Address>"
18. all:"<Keyword>"
19. “Set-Cookie: phpMyAdmin”
20. “Set-Cookie: lang="
21. “Set-Cookie: PHPSESSID"
22. “Set-Cookie: webvpn”
23. “Set-Cookie:webvpnlogin=1"
24. “Set-Cookie:webvpnLang=en”
25. “Set-Cookie: mongo-express="
26. “Set-Cookie: user_id="
27. “Set-Cookie: phpMyAdmin="
28. “Set-Cookie: _gitlab_session”
29. “X-elastic-product: Elasticsearch”
30. “x-drupal-cache”
31. “access-control-allow-origin”
32. “WWW-Authenticate”
33. “X-Magento-Cache-Debug”
34. “kbn-name: kibana”
9 446
PART - #1 🕵️♂️🛠
Let's Crack The Jenkins Instance 🔓
https://x.com/vulncure/status/1743241088968638513?s=20
9 446
Series #4
Top Known Bug Checklist ✅
Tips From Twitter Community🔻👇
#bugbounty #infosec
