Het Mehta :verified: · @hetmehtaa
43 followers · 20 posts · Server infosec.exchange
Renaud Lifchitz :verified: · @nono2357
256 followers · 1524 posts · Server infosec.exchange

RT @dk4trin
Splunk Info Disclosure

Shodan Dork => product:"Splunk"

Exploit like this=>
127.0.0.1:8000/en-US/splunkd/__raw/services/server/info/server-info?output_mode=json

#bugbountytips #bugbountytip

Last updated 3 years ago

admiralarjun · @admiralarjun
9 followers · 27 posts · Server infosec.exchange

πŸ’  XSSHunter setup for blind xss via 4ways By @Dheerajydv19

πŸ”— hacklido.com/blog/289

- - - # Tags - - -

#cybersecurity #infosec #bugbountytip

Last updated 3 years ago

Marc · @MarcVDC
11 followers · 54 posts · Server ioc.exchange

RT @GodfatherOrwa
url/?f=etc/passwd ==> 403
encode etc/passwd as base64

url/?f=L2V0Yy9wYXNzd2Q= ==> 200


you can use this trick in SQL , SSTI , XSS , LFI , Etc...

#note #bugbountytips #bugbountytip

Last updated 3 years ago

Lauritz · @lauritz
53 followers · 13 posts · Server ruhr.social

In times of HttpOnly-Cookies and SPAs which make heavy use of OAuth, alert(JSON.stringify({...localStorage})) kind of feels like the modern equivalent to traditional alert(document.cookie) payloads.

Definitely worth checking to increase impact of XSS vulns.

#xss #bugbountytip

Last updated 3 years ago

sumgr0 · @sumgr0
180 followers · 110 posts · Server infosec.exchange

RT @GodfatherOrwa@twitter.com

I back with new account same username handle @GodfatherOrwa@twitter.com

So all who know me you can follow me again πŸ˜‚

And from today

A lot of

And lts get back and make it rain P1s✌️

πŸ¦πŸ”—: twitter.com/GodfatherOrwa/stat

#bugbountytips #bugbountytip

Last updated 3 years ago

RT @JayateerthaG@twitter.com

Blog about vulnerability reported to Firefox and few other browsers that could lead to code execution when browser's Save Page As feature is not implemented correctly.

Blog Link - lnkd.in/g8VbP3sE

πŸ¦πŸ”—: twitter.com/JayateerthaG/statu

#cybersecurity #infosec #hacking #bugbounty #bugbountytip

Last updated 3 years ago

sumgr0 · @sumgr0
180 followers · 110 posts · Server infosec.exchange

RT @marcos_iaf@twitter.com

πŸ§΅πŸ‘‡
Over the time doing bug bounties, I have learned it's okay to not know everything beforehand. I have started "learning on the fly". Stop wasting too much time learning everything beforehand and start doing.
1/n

πŸ¦πŸ”—: twitter.com/marcos_iaf/status/

#bugbountytip #bugbounty #bugbountytips #cybersecutiy #infosec

Last updated 3 years ago

Blog about vulnerability reported to Firefox and few other browsers that could lead to code execution when browser's Save Page As feature is not implemented correctly.

Blog Link - lnkd.in/g8VbP3sE

#cybersecurity #infosec #hacking #bugbounty #bugbountytip

Last updated 3 years ago

tXambe · @tXambe
1 followers · 323 posts · Server mastodon.social

RT @Aacle_@twitter.com

Local File Inclusion -{One-Liner Bash}

By: @dwisiswant0@twitter.com

πŸ¦πŸ”—: twitter.com/Aacle_/status/1613

#bugbounty #bugbountytip

Last updated 3 years ago

tXambe · @tXambe
1 followers · 323 posts · Server mastodon.social

RT @Aacle_@twitter.com

Open-redirect -{One-Liner Bash}

By: @dwisiswant0@twitter.com & @N3T_hunt3r@twitter.com

πŸ¦πŸ”—: twitter.com/Aacle_/status/1613

#bugbounty #bugbountytip

Last updated 3 years ago

kingthorin_rm · @kingthorin_rm
102 followers · 164 posts · Server infosec.exchange
Gregor Longariva · @anfalas
37 followers · 210 posts · Server social.tchncs.de

RT @Krevetk0Valeriy@twitter.com

I just published a new article. Are a few stories of how my XSS Payload neutralized hackers' campaigns. Enjoy reading✌🏻

krevetk0.medium.com/hacking-ha

πŸ¦πŸ”—: twitter.com/Krevetk0Valeriy/st

#bugbountywriteup #bugbountytip #bugbountytips #bugbounty #togetherwehitharder

Last updated 3 years ago