Here is how I chained two bugs to exploit a UUID based IDOR and gained access to admin panel.
🧵THREAD🧵
1. How I knew that the target uses the same panel for both (normal users and admins)?! This is because of two things, the first one is through subdomain enumeration
So I finally wrote an article on Medium. This article is about my recent SQL Injection found in a maga retail outlet.
How I got Owned A Multi-Billion Dollar Retailer’s MySQL Databases Using Simple SQL Injection -
nav1n.medium.com/how-i-got-owne…#BugBounty
Getting 1 payout for 1 bug is good. But how about getting many payouts for 1 0day? Sounds better but how on Earth do you achieve that? To answer this question, I interviewed @mikey96_bh who has developed bug bounty automation to do it regularly. Enjoy!
youtu.be/ovvh2bvKZ_E
Updated my XSSHunter fork with full Trufflehog support, detect more than 750 credentials in the pages your payload fired.
Simple to setup, single/multi user, no blurred screenshots, Slack/Discord notifications.
github.com/rs-loves-bugs/…#xss#bugbountytips #bugbounty#infosec
Wanted to do this for some time and finally managed to do it, I forked XSS Hunter to make it simple to setup and deploy.
Added some new features too(Discord/Slack/custom hook notifications, no blurred screenshots, single user/multi user support)!
github.com/rs-loves-bugs/…
Here is short writeup on how I managed to access 200k+ of PII data by exploiting a simple vulnerability and accessing admin dashboard!
📌Thread📌
1. I created an account with a simple user and one endpoint caught my attention (it was /api/v1/session)
New blog post looking back on my first 2 years in bug bounty, happy to answer questions or comments about the experience here: h1pmnh.github.io/post/2022-sep-…
Using Turbo Intruder to create more resources (here notes) than a free account normally can 🛠️ (by @soyelmago)
An highly reusable strategy 💎
medium.com/@soyelmago/byp…
We've released the first episode! Check it out here and at MOST of your favorite podcast provider locations. Apple and Google are being a bit slow... but should be up by the end of the week at the latest.
Hope you all enjoy and shoot us some feedback!
rss.com/podcasts/ctbbp…
📝Just published a blog about the data leak I found at @LHVhuisartsen and @nhgnieuws; +15k 👨⚕️medical doctors usernames and hashed passwords leaked due to an unprotected API endpoint. The bug existed for 3 years, fixed within 48 hours.💡Read and learn more: medium.com/@jonathanbouma…
People are going to tell you exactly where the ceiling is and put onto you the extent of what you can and can't achieve. Don't "lower your expectations". Aim further than you think you are capable of achieving and work back from there.
It is almost 2023 - we gotta stop writing Nuclei Templates by hand;)
We are working on something that will make creating a template and running it on thousands of hosts a matter of minutes
It will empower newcomers and veterans - this is a sneak peek of what we are building
8 Followers 243 FollowingA mistake that makes you humble is better than achievement that makes you arrogant.
Ethical-Hacker 🖥
Bugs-Hunter 🐛
Pentester
Cyber-Security Enthusiast's
955K Followers 12K FollowingFOLLOW to engage, think, laugh & converse. SUBSCRIBE for $4. Get introduced to verified accounts. DM me after you subscribe Turn on 🔔 𝕏 PREMIUM +
22K Followers 69 FollowingA 'by Hackers for Hackers' podcast focused on technical content ranging from bug bounty tips, to write-up explanations, to the latest exploitation techniques.
218 Followers 457 FollowingApplication Security Engineer and Penetration Tester.
Finding my way through Digital Forensics and blog writing.
Hope you enjoy https://t.co/RqpSS1ZdOr
1.4M Followers 0 FollowingA universe of atoms, an atom in the universe. Tribute to the great explainer. Tweets about Science and Wisdom. Portrait by L.V Patten.
593 Followers 62 FollowingEthical Technology builder, hacker, pentester, bug-bounty hunter. Current all-time rank 12th @Bugcrowd. securing systems along with the great folks at InfoSec.
2.9M Followers 275 Following🇨🇦 We post memes, comics, wholesome stuff & anything we like. Get original shirts to raise money for charity https://t.co/Upa2OFOAJk
10K Followers 1 FollowingUser friendly unofficial HackerOne public disclosures, keeps you updated about the recently disclosed bugs.
Made With ♥ By Hackers For Hackers. - @rohsec
4K Followers 690 FollowingIT Security guy, penetration testing is my thing. One of the SANS Internet Storm Center handlers at https://t.co/KLxU4pooKI. SANS SEC542 instructor and course co-author.
170K Followers 709 FollowingHonoring the legacy and Mamba Mentality. Largest Kobe Bryant community in the world. Preorder Vanessa’s new Mamba and Mambacita book 📖 ⬇️
2K Followers 629 FollowingI'm mnz. A security researcher, penetration tester and member of the @thegooniesctf team in Australia. No logs, no crime.
PGP: 9F7D 181D 1F4A 51B2
8K Followers 438 FollowingI'm an engineer from Turkey, who is interested with biotechnology, computer science and digital gaming. Proud father of three little devils. A.K.A nukedx