Exploring WordPress Juicy Endpoints: A Guide for Bug Bounty Hunters
#bug #bugs #bugbounty #bugbountytip #bugbountytips #hacking #hacker #ethicalhacking #ethicalhacker #ethicalhackers #cybersecurity
#bug #bugs #bugbounty #bugbountytip #bugbountytips #hacking #hacker #ethicalhacking #ethicalhacker #ethicalhackers #cybersecurity
Wordlists Real-world infosec wordlists, updated regularly
https://github.com/trickest/wordlists
#bug #bugs #bugbounty #bugbountytip #bugbountytips #hacking #hacker #ethicalhacking #ethicalhacker #ethicalhackers #cybersecurity
#bug #bugs #bugbounty #bugbountytip #bugbountytips #hacking #hacker #ethicalhacking #ethicalhacker #ethicalhackers #cybersecurity
How to Detect and Mitigate SSRF Vulnerabilities in the Early Coding Cycle: A Comprehensive Guide
#BugBounty #webdeveloper #xss #bugbountytip #CyberSec #cybersecuritytips #Pentesting #hackers #CyberSecurityAwareness #redteam #infosecurity #infosec #bounty
#bugbounty #webdeveloper #xss #bugbountytip #cybersec #cybersecuritytips #pentesting #hackers #cybersecurityawareness #redteam #infosecurity #infosec #bounty
How To Windows Privilege Escalation
https://blog.devgenius.io/how-to-windows-privilege-escalation-93bf41ab259d
#bug #bugs #bugbounty #bugbountytip #bugbountytips #hacking #hacker #ethicalhacking #ethicalhacker #ethicalhackers #cybersecurity
#bug #bugs #bugbounty #bugbountytip #bugbountytips #hacking #hacker #ethicalhacking #ethicalhacker #ethicalhackers #cybersecurity
Admin Panel Bypass without the credentials
https://medium.com/@sayim0x3105/admin-panel-bypass-without-the-credentials-e867eee7c81b
#bug #bugs #bugbounty #bugbountytip #bugbountytips #hacking #hacker #ethicalhacking #ethicalhacker #ethicalhackers #cybersecurity
#bug #bugs #bugbounty #bugbountytip #bugbountytips #hacking #hacker #ethicalhacking #ethicalhacker #ethicalhackers #cybersecurity
Bug Bounty Bonanza: A Beginnerβs Guide
https://medium.com/@paritoshblogs/bug-bounty-bonanza-a-beginners-guide-f7f27fedeee6
#bug #bugs #bugbounty #bugbountytip #bugbountytips #hacking #hacker #ethicalhacking #ethicalhacker #ethicalhackers #cybersecurity
#bug #bugs #bugbounty #bugbountytip #bugbountytips #hacking #hacker #ethicalhacking #ethicalhacker #ethicalhackers #cybersecurity
GraphQL Security Flaws and Exploitation
https://infosecwriteups.com/graphql-security-flaws-and-exploitation-d3fac0831e7d
#bug #bugs #bugbounty #bugbountytip #bugbountytips #hacking #hacker #ethicalhacking #ethicalhacker #ethicalhackers #cybersecurity
#bug #bugs #bugbounty #bugbountytip #bugbountytips #hacking #hacker #ethicalhacking #ethicalhacker #ethicalhackers #cybersecurity
FROM INTERNET
1)How do I take over another user subdomain name worth $$$$
https://parkerzanta.medium.com/how-do-i-take-over-another-user-subdomain-name-worth-c66bb0c3f2f7
2)How I Used JS files inspection and Fuzzing to do admins/supports stuff
https://medium.com/@bag0zathev2/how-i-used-js-files-inspection-and-fuzzing-to-do-admins-supports-stuff-dd4f700605a
3)Bug Bounty Hunting 101: WAF Evasion
https://medium.com/@haythamkarouata/bug-bounty-101-waf-evasion-b2f4bf9cd11f
4)Jack-Of-ALL-Trades | TryHackMe
https://nihirzala.medium.com/jack-of-all-trades-tryhackme-ac043ec0c479
5)TryHackMe: Agent T Writeup
https://medium.com/@2A2U/tryhackme-agent-t-20148775384a
6)Soccer β Hack The Box Walkthrough
https://medium.com/@exit2935/soccer-hack-the-box-walkthrough-b7f9ace534e4
7)APK-Penetration-testing-Guide
https://github.com/RajQureshi/APK-Penetration-testing-Guide
#bug #bugs #bugbounty #bugbountytip #bugbountytips #hacking #hacker #ethicalhacking #ethicalhacker #ethicalhackers #cybersecurity
#bug #bugs #bugbounty #bugbountytip #bugbountytips #hacking #hacker #ethicalhacking #ethicalhacker #ethicalhackers #cybersecurity
RT @dk4trin
Splunk Info Disclosure
Shodan Dork => product:"Splunk"
Exploit like this=>
127.0.0.1:8000/en-US/splunkd/__raw/services/server/info/server-info?output_mode=json
π XSSHunter setup for blind xss via 4ways By @Dheerajydv19
π https://hacklido.com/blog/289
- - - # Tags - - -
#cybersecurity #infosec #bugbountytip
#cybersecurity #infosec #bugbountytip
RT @GodfatherOrwa
url/?f=etc/passwd ==> 403
encode etc/passwd as base64
url/?f=L2V0Yy9wYXNzd2Q= ==> 200
#note
you can use this trick in SQL , SSTI , XSS , LFI , Etc...
#note #bugbountytips #bugbountytip
In times of HttpOnly-Cookies and SPAs which make heavy use of OAuth, alert(JSON.stringify({...localStorage})) kind of feels like the modern equivalent to traditional alert(document.cookie) #XSS payloads.
Definitely worth checking to increase impact of XSS vulns.
RT @GodfatherOrwa@twitter.com
I back with new account same username handle @GodfatherOrwa@twitter.com
So all who know me you can follow me again π
And from today
A lot of
#bugbountytips #bugbountytip
And lts get back and make it rain P1sβοΈ
π¦π: https://twitter.com/GodfatherOrwa/status/1615194809194680322
RT @JayateerthaG@twitter.com
Blog about vulnerability reported to Firefox and few other browsers that could lead to code execution when browser's Save Page As feature is not implemented correctly.
Blog Link - https://lnkd.in/g8VbP3sE
#cybersecurity #infosec #hacking #bugbounty #bugbountytip #cybersecurity
π¦π: https://twitter.com/JayateerthaG/status/1614262971248824320
#cybersecurity #infosec #hacking #bugbounty #bugbountytip
RT @marcos_iaf@twitter.com
#bugbountytip π§΅π
Over the time doing bug bounties, I have learned it's okay to not know everything beforehand. I have started "learning on the fly". Stop wasting too much time learning everything beforehand and start doing.
1/n
#bugbounty #bugbountytips #cybersecutiy #infosec
π¦π: https://twitter.com/marcos_iaf/status/1614647413557592064
#bugbountytip #bugbounty #bugbountytips #cybersecutiy #infosec
Blog about vulnerability reported to Firefox and few other browsers that could lead to code execution when browser's Save Page As feature is not implemented correctly.
Blog Link - https://lnkd.in/g8VbP3sE
#cybersecurity #infosec #hacking #bugbounty #bugbountytip #cybersecurity
#cybersecurity #infosec #hacking #bugbounty #bugbountytip
RT @Aacle_@twitter.com
Local File Inclusion -{One-Liner Bash}
By: @dwisiswant0@twitter.com
π¦π: https://twitter.com/Aacle_/status/1613814601690546178
RT @Aacle_@twitter.com
Open-redirect -{One-Liner Bash}
By: @dwisiswant0@twitter.com & @N3T_hunt3r@twitter.com
π¦π: https://twitter.com/Aacle_/status/1613814604743979009
Iβm adding Jump To functionality for
@zaproxyβs history table: https://github.com/zaproxy/zaproxy/pull/7675
#OWASP #OpenSource #RedTeam #PenTest #PenetrationTesting #BugBountyTip #zaproxy
#owasp #opensource #redteam #pentest #penetrationtesting #bugbountytip #zaproxy
RT @Krevetk0Valeriy@twitter.com
I just published a new article. Are a few stories of how my XSS Payload neutralized hackers' campaigns. Enjoy readingβπ»
#TogetherWeHitHarder #BugBounty #bugbountytips #bugbountytip #bugbountywriteup
https://krevetk0.medium.com/hacking-hackers-for-fun-and-profit-784e6c7897e8
π¦π: https://twitter.com/Krevetk0Valeriy/status/1612442656478564353
#bugbountywriteup #bugbountytip #bugbountytips #bugbounty #togetherwehitharder