As promised: Here's my story about 8 CVEs resulting in a plugin removal and more than $30,000 in bounties!
I've chained 3 of them to go from unauthenticated to admin, aka how to exploit a blind SQL Injection via XSS.
rcesecurity.com/2022/07/WordPr…#BugBounty#security
I decided to make a homage-post to @homakov and @Nirgoldshlager about different OAuth-token leakage methods I've been researching – ten years after their blog posts that inspired me to start hunt for bugs ♥️ thank you.
labs.detectify.com/2022/07/06/acc…
I have created an article for the Bug Bounty community which is focused on how to orchestrate hacking tools through Slack using python, ideal to be able to work with a workspace and thus be able to manage the tools easily, I hope it can help you.
webs3c.com/t/how-to-orche…
Good to be back at H1 after a long break.
Dont just blindly bruteforce 6-8 OTP. Try to understand the applications logic and bypass with alternative path which dev might not notice about.
#bugbounty
Blockchain & Smart Contract Security #1
Understanding Access Control in Smart Contracts and the Hospowise smart contract hack.
Detailed blog post and a thread 1/6
blog.solidityscan.com/access-control…
As promised, here is the blog about my recent finding which was a NoSQL injection on a @SynackRedTeam client:
Let me know if you guys like it :)
Feebacks are appreciated.
kuldeep.io/posts/nosql-in…
the best ATO i've ever found. At first, I didnt realize how I was able to takeover but reported. @SynackRedTeam VO gave me a chance to prove the vulnerability instead of rejecting the report and then I fingured out the root cause and it was accepted.
I just published Bug Hunting Journey of 2021
I have included some of my bugs which I found fascinating along with that it also includes some bypasses of my own reports :)
As always Feedbacks are appreciated.
link.medium.com/E9qRQHnarmb
135 Followers 1K Followingاللهم إليك أشكو ضعف قوتي وقلة حيلتي وهواني على الناس،
إن لم يكن بك غضب علي فلا ابالي، غير ان عافيتك هي اوسع لي
.. اللهم فرجاً قريب 🤲🏻
1K Followers 1K FollowingBug Bounty Amateur, Ambitious to be Information Security Developer. Aspirant to improve IT & CySec. https://t.co/aJptMzdum2 https://t.co/0hE2tMp1nx
558 Followers 3K FollowingAlpha Capital | Trading profissional com VWAP | Copytrade em tempo real, disciplina, risco controlado e resultados consistentes 🚀
9 Followers 489 FollowingA guy interested in infosec, pentest & bug bounty. I'm just starting this path.
Please text me if you have any tips! I would appreciate it a lot!
235K Followers 1K FollowingCofounder @hackinghub_io | Advisor @CaidoIO. I hack companies and make content about it. #NahamCon organizer. ex @hacker0x01🇮🇷
65K Followers 2 FollowingThis is an unofficial HackerOne public disclosure watcher who keeps you up to date about the recently disclosed bugs. By @NOBBD
37K Followers 530 FollowingHacker, bug bounty hunter, guy behind https://t.co/TBAtP71Cop. 1st in Meta bug bounty program for the last 6 years. YES Team Member
27K Followers 631 FollowingWeb hacker and Burp Suite Pro trainer
Refer to https://t.co/D5tRH7U2hg for trainings
Follow @MasteringBurp for free tips and tricks
8K Followers 438 FollowingI'm an engineer from Turkey, who is interested with biotechnology, computer science and digital gaming. Proud father of three little devils. A.K.A nukedx
273K Followers 184 FollowingThe democratically elected MPs from #Myanmar overthrown by unlawful military coup are working to bring lasting peace and stability to the country.