en
Feedback
Bug Bounty

Bug Bounty

Open in Telegram

Bugbounty Resources β€’ Tips β€’ Security Zines β€’ Writeups β€’ Vulnerability Update β€’ Notes β€’ Mindmaps β€’ Cheatsheets β€’ Checklists β€’ Article / Blogs β€’ PDFs β€’ ebooks β€’

Show more
9 446
Subscribers
No data24 hours
-37 days
-6030 days
Posts Archive
Hey πŸ– , Those Who are Interested in AI & ML learning Tips & Tricks can join This Telegram Group : https://t.me/ai_ml_tips

What I learned from reading 220* IDOR bug reports. Credit: _nyan https://medium.com/@nynan/what-i-learnt-from-reading-220-ido
What I learned from reading 220* IDOR bug reports. Credit: _nyan https://medium.com/@nynan/what-i-learnt-from-reading-220-idor-bug-reports-6efbea44db7

photo content

photo content

API Hacking - RESTful API.pdf0.81 KB

[+] Card Payment Functionality - Checklist #bugbounty #infosec
[+] Card Payment Functionality - Checklist #bugbounty #infosec

01_Burp_Suite_Dashboard.pdf3.85 KB

TIP: Admin panel access using %20 #cybersecurity #infosec #ethicalhacking #bugbounty #bugbountytips #bugbountytip
TIP: <img src="assets/img/emoji/1f6e1.png" class="emoji" alt="πŸ›‘οΈ"> Admin panel access using %20 <img src="assets/img/emoji/1f6e1.png" class="emoji" alt="πŸ›‘οΈ"> #cybersecurity #infosec #ethicalhacking #bugbounty #bugbountytips #bugbountytip

TIP: πŸ›‘οΈ Admin panel access using %20 πŸ›‘οΈ #cybersecurity #infosec #ethicalhacking #bugbounty #bugbountytips #bugbountytip
TIP: πŸ›‘οΈ Admin panel access using %20 πŸ›‘οΈ #cybersecurity #infosec #ethicalhacking #bugbounty #bugbountytips #bugbountytip

πŸ˜„πŸ€£

Tips πŸŒΏπŸŒ»πŸ‚ whenever you saw any email input field! 70% bug hunters don't try XSS there as compared to name field. always try this in email input field! "<img/src/onerror=alert(0)"@xss.com This don't work every time but give it a try found 2 XSS today using this! Tips πŸŒΏπŸŒ»πŸ‚ πŸ‘†

First I reported XSS trigged as medium! I am not satisfied with that later I chained it with account takeover! Got additional
First I reported XSS trigged as medium! I am not satisfied with that later I chained it with account takeover! Got additional. $650 Tips: - if application have feature of Api key and you can't steal session cookies! 1/n More : πŸ‘‡ https://twitter.com/bug_vs_me/status/1634090120658780162?t=X54aRAVY05Ajv0zosKda4Q&s=19