Bug hunters, how do you usually test for IDOR?
I know the basics (checking params, object IDs, user IDs etc.), but curious what patterns or workflows you use in real hunts.
#BugBounty#WebSecurity#InfoSec
120 Days of Web3 Security
Day 1
Read through the entire Silo Protocol documentation.
Concepts covered: Silos/Isolated Pairs, Managed Vaults, Borrowing and Depositing mechanism, Liquidation Logic, Interest Rates and Oracle design.
SQL vs NoSQL — When to Use What (With Real Examples)
A lot of devs struggle with choosing between SQL and NoSQL.
Here’s a no-fluff breakdown that will save you hours of research.
Most apps block localhost, 127.0.0.1, 169.254.169.254 & validate file types to stop SSRF.
But in my recent webinar, I showed a very unique way to bypass all that.
Watch the full recording here:
youtube.com/watch?v=Fwahyq…
Bug bounty, feedback, strategy, and alchemy
frequently asked for advice, roadmaps, and more, I finally took the time, after 2–3 years of bug bounty, to write down my vision, thoughts and perspective on the subject
non-technical, no research this time!
zhero-web-sec.github.io/thoughts/bugbo…
🚨 2FA Bypass in Bug Bounty: Top Techniques You Need to Know
Two-Factor Authentication (2FA) ≠ invincible. Poor implementation = golden opportunity for hunters. Here’s how pros break weak 2FA ⬇️
#bugbountytip
Quick tip and script : ✅️
If you are hunting or scanning a WordPress instance, don't forget to look for exposed plugins' or WP core REST endpoints, under /wp-json.. many plugins like payments gateways are exposing the webhooks or callback plugins in order to…
Hunter Cust #2 –
@Ahmex000
مع أحمد الهنى أحمد صياد مميز في الـ Recon والـ Manual Testing، وبيشاركنا رحلته في المجال، طرق التعلم، والتغلب على التشتت، وتنظيم الوقت، وأدواته المفضلة. حلقة مليانة نصايح للمبتدئين والمحترفين 👇 📷 رابط الحلقة:
youtu.be/l7_Iv9RZK3s#BugBounty
11K Followers 226 FollowingElevating Innovation with AI & Web Tech
AI Explorer | Web Dev Pro | Promo Collabs Welcome
📩 Reach Out: [email protected] | DM for Paid Promotion
4K Followers 68 FollowingA Leading Blockchain Development Firm and Venture Studio. Delivering Value Creation Through Decentralization for the best teams in Web3.
564K Followers 135 FollowingFather of three, Creator of Ruby on Rails + Omarchy, Co-owner & CTO of 37signals, Shopify director, NYT best-selling author, and Le Mans 24h class-winner.
39K Followers 90 FollowingRevolutionary NFT Marketplace & Launchpad that locks $USDC liquidity into every NFT on the liquid platform! The days of NFTs having no value have come to an end
359K Followers 1K FollowingA cold wallet built for you. Wear it, use it, hide it. Your crypto, your custody.
Posts are not directed towards UK users.
Get Tangem👇
2.5M Followers 23K FollowingReposting Trump’s Truth Social posts (with date/time) on X + news/commentary. Unofficial. Profile Artist: @ElenaRuseva1 Not affiliated with @realdonaldtrump.
22K Followers 69 FollowingA 'by Hackers for Hackers' podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest exploitation techniques.
234K Followers 1K FollowingCofounder @hackinghub_io | Advisor @CaidoIO. I hack companies and make content about it. #NahamCon organizer. ex @hacker0x01🇮🇷
483K Followers 750 Followingباحث في التاريخ والحضارة الإسلامية، ماجستير الاقتصاد الإسلامي، عضو الأمانة العامة لـ @SupportProphetM، رئيس تحرير @AnsarMagazine للتواصل: [email protected]
282K Followers 712 Followingبهجت صابر مصري امريكي ضد الظلم والظالمين مهمته هي الوعي نشر الحريه وخاصة حرية التعبير ضد حكم العساكر الخونه القتله تحيا مصر ويحيا العرب القدس عربيه ضدالصHيونيه
67K Followers 349 FollowingGrand Chief Rabbi Kingdom of Saudi Arabia الحاخام الاكبر للمملكة العربية السعودية وجزيرة العرب للتواصل مع مدير https://t.co/bnUAF4fHRS مكتب الحاخام تيليغرام
No recent Favorites. New Favorites will appear here.