en
Feedback
therceman

therceman

Open in Telegram

Bug Bounty & Cyber Security

Show more
The country is not specifiedTechnologies & Applications35 003
2 256
Subscribers
No data24 hours
No data7 days
+530 days
Posts Archive
Text Version available at X https://x.com/therceman/status/1710918773782278466 #Recon
Text Version available at X https://x.com/therceman/status/1710918773782278466 #Recon

#CSRF
#CSRF

#XSS #WAF
#XSS #WAF

#XSS #WAF
#XSS #WAF

#XSS
#XSS

#WAF #XSS
#WAF #XSS

#WAF #XSS
#WAF #XSS

#Encoding
#Encoding

#auth
#auth

#SQLinjection
#SQLinjection

#SQLInjection
#SQLInjection

MongoDB NoSQL Injection #NoSQLInjection
MongoDB NoSQL Injection #NoSQLInjection

#SQLInjection
#SQLInjection

Bug Bounty Tip Google Dork for Open Redirect or XSS URLs Site:*.example.com inurl:return_to Lost of redirect query parameters
Bug Bounty Tip Google Dork for Open Redirect or XSS URLs Site:*.example.com inurl:return_to Lost of redirect query parameters will be in comment πŸ‘‡ Cheers!

You can prevent your command from appearing in your command history by including a space before entering it. The shell ignore
You can prevent your command from appearing in your command history by including a space before entering it. The shell ignores commands prefixed with a space and, therefore, fails to register them in the history. Tested on Ubuntu 22.04.3 / 23.04 Credits to: Qusai Alhaddad

What types of apps do you usually target for bug bounty? 1. Blogs 2. E-commerce 3. Car Rentals 4. Online Casinos 5. CRM 6. Social Media 7. Financial Services 8. News Websites 9. Travel Booking 10.Educational 11. Health Care 12.Streaming 13.Forums 14.APIs Other? (comment)

New Milestone 14k friends on X (Twitter)
New Milestone 14k friends on X (Twitter)

#XSS #CachePoisoning
#XSS #CachePoisoning

Don’t rely solely on tools while doing Bug Bounty. Manual testing can uncover vulnerabilities that automated tools might miss. P.S. 99% of my findings were found manually. Cheers!

Read the documentation and understand the business while doing Bug Bounty. Docs can reveal lesser-known functionalities, and understanding how the target company operates will help you to find potential vulnerabilities in their business logic. Cheers!