en
Feedback
Bug Bounty

Bug Bounty

Open in Telegram

Bugbounty Resources • Tips • Security Zines • Writeups • Vulnerability Update • Notes • Mindmaps • Cheatsheets • Checklists • Article / Blogs • PDFs • ebooks •

Show more
9 446
Subscribers
No data24 hours
-37 days
-6030 days
Posts Archive
Bug Report as Document Apache Tomcat : • 🐞 BUG: HTTP Request Smuggling • 📄 CVE ID: 2024-21733 | CWE: 444 Detailed Documenta
Bug Report as Document Apache Tomcat : • 🐞 BUG: HTTP Request Smuggling • 📄 CVE ID: 2024-21733 | CWE: 444 Detailed Documentation : https://x.com/vulncure/status/1753271047355240874?s=20

API Testing Series #1 ✍️🪸 🔍 Key Highlights: • 🫐 API Endpoints • 🫑 Collection & Subcollection: • 🥗 Gateway & 🥥Microservices Demystified • 🥝 Web API Types • ⚡️ CRUD Operations • ❄️ 6 Constraints of Restful API Let's Dive into the Details 👇⤵️ https://x.com/vulncure/status/1748018742158569966?s=20

🪵 Portion of CWE Structure 🪻 https://nvd.nist.gov/vuln/categories/cwe-layout

PART - #4 ⚙️🔨 💨Mastering Jenkins RCE - Crafting and Modifying Projects 💼💻 Now, let's explore the art of Remote Code Execu
PART - #4 ⚙️🔨 💨Mastering Jenkins RCE - Crafting and Modifying Projects 💼💻 Now, let's explore the art of Remote Code Execution (RCE) by creating and modifying projects in Jenkins. 🔑 Authority to tweak? Potent, if noisy! 🌪 Ready to amplify Jenkins skills? 🧵📷 https://x.com/vulncure/status/1746033898746736840?s=20

AEM MISCONFIGURATION CHEATSHEET.pdf

PART - #3 🕵️‍♂️🛠 Let's Crack The Jenkins Instance 🔓 Now, let's take the plunge into Remote Code Execution (RCE) using Groo
PART - #3 🕵️‍♂️🛠 Let's Crack The Jenkins Instance 🔓 Now, let's take the plunge into Remote Code Execution (RCE) using Groovy scripts. This method is stealthier than creating a new project, so buckle up: Dive into the details 🧵:📷 https://x.com/vulncure/status/1745514588001701991?s=20

PART - #3 🕵️‍♂️🛠 Let's Crack The Jenkins Instance 🔓 Now, let's take the plunge into Remote Code Execution (RCE) using Groovy scripts. This method is stealthier than creating a new project, so buckle up: Dive into the details 🧵:📷https://x.com/vulncure/status/1745514588001701991?s=20

PART - #2 🔐🛡 Understanding the Foundation: Jenkins Security Overview 🔐🛠 Before delving into exploitation, let's establish
PART - #2 🔐🛡 Understanding the Foundation: Jenkins Security Overview 🔐🛠 Before delving into exploitation, let's establish a solid understanding of key Jenkins security components: Dive into the details 🧵:📷 https://x.com/vulncure/status/1744722597194186854?s=20

PART - #2 🔐🛡 Understanding the Foundation: Jenkins Security Overview 🔐🛠 Before delving into exploitation, let's establish a solid understanding of key Jenkins security components: Dive into the details 🧵:📷 https://x.com/vulncure/status/1744722597194186854?s=20

File Upload Cheatsheet.pdf

Series #5 Top Known Bug ChecklistBusiness Logic Error Cheatsheet🔻👇 #bugbounty #infosec

Bugbounty Reports in Threads 🧵 Bug : HTML sanitizer that allows an attacker to inject arbitrary unsafe HTML into emails, pot
Bugbounty Reports in Threads 🧵 Bug : HTML sanitizer that allows an attacker to inject arbitrary unsafe HTML into emails, potentially lead to account compromise for hey .com's users who view the malicious emails Type: XSS Company: Basecamp Siverity: Critical (9 ~ 10) Bounty: $5,000 Dive into the details 🧵:📷 https://x.com/vulncure/status/1743998521575936387?s=20

Some Shodan Dorks that might useful in Bug Bounty. 1. org:"http://target.com" 2. http.status:"<status_code>" 3. product:"<Product_Name>" 4. port:<Port_Number> “Service_Message” 5. port:<Port_Number> “Service_Name” 6. http.component:"<Component_Name>" 7. http.component_category:"<Component_Category> 8. http.waf:"<firewall_name>" 9. http.html:"<Name>" 10. http.title:"<Title_Name>" 11. ssl.alpn:"<Protocol>" 12. http.favicon.hash:"<Favicon_Hash>" 13. net:"<Net_Range>" (for e.g. 104.16.100.52/32) 14. http://ssl.cert.subject.cn:"<http://Domain.com>" 15. asn:"<ASnumber>" 16. hostname:"<hosthame>" 17. ip:"<IP_Address>" 18. all:"<Keyword>" 19. “Set-Cookie: phpMyAdmin” 20. “Set-Cookie: lang=" 21. “Set-Cookie: PHPSESSID" 22. “Set-Cookie: webvpn” 23. “Set-Cookie:webvpnlogin=1" 24. “Set-Cookie:webvpnLang=en” 25. “Set-Cookie: mongo-express=" 26. “Set-Cookie: user_id=" 27. “Set-Cookie: phpMyAdmin=" 28. “Set-Cookie: _gitlab_session” 29. “X-elastic-product: Elasticsearch” 30. “x-drupal-cache” 31. “access-control-allow-origin” 32. “WWW-Authenticate” 33. “X-Magento-Cache-Debug” 34. “kbn-name: kibana”

Upload Function Exploit Techniques.📚 #infosec #bugbountytip #cybersecurity
Upload Function Exploit Techniques.📚 #infosec #bugbountytip #cybersecurity

PART - #1 🕵️‍♂️🛠 Let's Crack The Jenkins Instance 🔓 https://x.com/vulncure/status/1743241088968638513?s=20
PART - #1 🕵️‍♂️🛠 Let's Crack The Jenkins Instance 🔓 https://x.com/vulncure/status/1743241088968638513?s=20

Series #4 Top Known Bug ChecklistTips From Twitter Community🔻👇 #bugbounty #infosec

Series #3 Top Known Bug ChecklistPasswd Reset Checklist 🔻👇 #bugbounty #infosec

Series #2

IDOR.pdf