ForBugHunters
5.74K subscribers
67 photos
1 video
5 files
51 links
Dark Army
Bug hunting channel focused on real writeups, PoCs, and live hacking sessions, sharing practical bug bounty experience and real-world vulnerability discovery.

YouTube channel: https://youtube.com/@forbughunters
Download Telegram
You can read the subtitles in English on the YouTube video using this extension:
https://chromewebstore.google.com/detail/glot-extension/dbnjpielondlkmdjbembloegkaabfakc
❀13
Congratulations πŸ˜πŸ‘
❀31πŸ”₯12
Congratulations πŸ€©πŸ‘
1❀32
We’ve just released 6 new videos covering real-world vulnerabilities:

β€’ Exposed API Grant Unauthorized Access to Premium Option
https://www.youtube.com/watch?v=W0aCx6aaKaw

β€’ Email Verification Bypass
https://www.youtube.com/watch?v=HqH3IXYT3Ds

β€’ Business Logic Bugs: Admin Couldn’t Delete Files!
https://www.youtube.com/watch?v=w28D0_evC80

β€’ Bypassing the AI Chat Limit
https://www.youtube.com/watch?v=sPaZzk37PWA

β€’ How Pre-Account Takeover Works + Access Control Bypass
https://www.youtube.com/watch?v=ehNHpbaQrPY

β€’ Unauthorized Email Modification & Account Lockout
https://www.youtube.com/watch?v=qMa9BZ6QQ8k&t=8s
❀55πŸ”₯8πŸ₯°1πŸ‘Ύ1
Who’s next ?!πŸ˜πŸ‘
❀28
Good job πŸ‘πŸ”₯
❀36πŸ”₯3
Congratulations πŸ”₯πŸ‘
πŸ”₯21❀12
Congratulations πŸŽ‰
Bounty : 2000$

Who’s next !πŸ€·β€β™‚οΈ
πŸ”₯85❀49🀩9❀‍πŸ”₯2🀯2
Congratulations πŸŽŠπŸŽ‰
Who’s next?πŸ€·β€β™‚οΈ
❀41
Congratulations πŸŽ‰πŸŽŠ
Tell me :
Who’s next??πŸ€·β€β™‚οΈ
πŸ”₯37❀14⚑1πŸ‘1
Who’s next🀯!
❀40✍1
🚨 Critical Vulnerability

🚨 Critical Hardcoded IBM Cloud API Key in Admin JavaScript Allows Unauthorized IAM Token Generation (Cloud Account Compromise)

πŸ“ Full writeup:
https://www.facebook.com/share/p/18JAevtdRq/?mibextid=wwXIfr
❀20πŸ”₯6
Who’s next!🀩
❀34🀯1
First bountyπŸ€©πŸ‘
❀61πŸ‘1🀯1
Self hosted +Bug bounty programs⬇️

*.cleeng.com

security@cleeng.com
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
*.redsift.com

security@redsift.com
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
*.plain.com

security@plain.com
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
*.linkdm.com

support@linkdm.com
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
*.ory.com

security@ory.com
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
*. aquanow.com

bugbounty@aquanow.com
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
https://github.com/swisscom/bugbounty
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
https://www.spendesk.com/.well-known/security.txt
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
https://help.spreaker.com/en/articles/5123644-bug-bounty-program
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
https://www.fjdynamics.com/jp/bug-bounty-program
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
https://www.klook.com/bugbounty
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
https://gobright.com/responsible-disclosure-policy/
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
https://www.make.com/en/bounty
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
https://www.pubnub.com/bug-bounty-policy/
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
https://help.doit.com/docs/vendor-information/bug-bounty-program
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
https://www.lenskart.com/vulnerability-disclosure-policy
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
https://www.talentlms.com/vulnerabilitypolicy
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
https://whatbox.ca/policies/security
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
*.perlego.com

security@perlego.com
β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”β€”
https://support.playerauctions.com/hc/en-us/articles/49330305602585-PlayerAuctions-Bug-Bounty-Program
❀22
❀22πŸ”₯5πŸ‘1
Who’s next!πŸ€·β€β™‚οΈ
❀32πŸ‘2
Congratulations πŸ˜πŸ‘
❀30πŸ‘3πŸ”₯2πŸ₯°1
Congratulations πŸ˜πŸ‘
❀35