New video is out โ
Advanced Business Logic Bug in Organization Management
Watch here: https://youtu.be/Vvg7Q5Mwu-c
Advanced Business Logic Bug in Organization Management
Watch here: https://youtu.be/Vvg7Q5Mwu-c
YouTube
(21) Advanced $$$ Business Logic Vulnerability
In this video, I demonstrate an Advanced Business Logic Bug affecting organization member management.
By changing the account email to a specially encoded value, the organization admin becomes unable to remove the member from the organization. The applicationโฆ
By changing the account email to a specially encoded value, the organization admin becomes unable to remove the member from the organization. The applicationโฆ
โค47๐ฅ2๐1
ูู ุณูุฉ ูุฃูุชู
ุทูุจูู ุจู
ูุงุณุจุฉ ุนูุฏ ุงูุฃุถุญู ุงูู
ุจุงุฑู ๐
ุชูุจู ุงููู ู ูุง ูู ููู ุตุงูุญ ุงูุฃุนู ุงูุ ูุฃุนุงุฏู
ุนูููู ุจุงูุฎูุฑ ูุงูุณุนุงุฏุฉ ูุงูุจุฑูุฉ
ุชูุจู ุงููู ู ูุง ูู ููู ุตุงูุญ ุงูุฃุนู ุงูุ ูุฃุนุงุฏู
ุนูููู ุจุงูุฎูุฑ ูุงูุณุนุงุฏุฉ ูุงูุจุฑูุฉ
โค102โคโ๐ฅ8๐ฅ1
โ
Both vulnerabilities have been rewarded successfully!
linkedin :
https://www.linkedin.com/posts/ayman-amer1_bugbounty-cybersecurity-ethicalhacking-ugcPost-7466083479701721088-sS5F
๐ Broken Access Control โ $300
https://youtu.be/Vvg7Q5Mwu-c?si=twLnRfVmXotvAqcn
โก Business Logic โ $300
https://youtu.be/szRhhwB_vlE?si=7XDofnIq0INP0Led
๐ฐ Total Reward: $600 ๐ฅ
linkedin :
https://www.linkedin.com/posts/ayman-amer1_bugbounty-cybersecurity-ethicalhacking-ugcPost-7466083479701721088-sS5F
๐ Broken Access Control โ $300
https://youtu.be/Vvg7Q5Mwu-c?si=twLnRfVmXotvAqcn
โก Business Logic โ $300
https://youtu.be/szRhhwB_vlE?si=7XDofnIq0INP0Led
๐ฐ Total Reward: $600 ๐ฅ
โค83๐ฅ7
๐ฅ New Bug Bounty Reward โ
Linkedin:
https://www.linkedin.com/posts/ayman-amer1_bugbounty-xss-rxss-activity-7471511542061211648-O1JH
Simple RXSS
The application does not provide a public registration page and is intended only for approved business customers.
1. Enumerated target subdomains.
2. Found a login page on one of the discovered services.
3. Noticed that error messages were reflected through the statusMessage parameter.
4. Tested input reflection:
https://go-service.target.com/?statusMessage=test
5. Injected a simple XSS payload:
https://go-service.target.com/?statusMessage=<payload>
6. Payload executed successfully โ Reflected XSS (RXSS).
๐ฐ Reward received. $$$
Linkedin:
https://www.linkedin.com/posts/ayman-amer1_bugbounty-xss-rxss-activity-7471511542061211648-O1JH
Simple RXSS
The application does not provide a public registration page and is intended only for approved business customers.
1. Enumerated target subdomains.
2. Found a login page on one of the discovered services.
3. Noticed that error messages were reflected through the statusMessage parameter.
4. Tested input reflection:
https://go-service.target.com/?statusMessage=test
5. Injected a simple XSS payload:
https://go-service.target.com/?statusMessage=<payload>
6. Payload executed successfully โ Reflected XSS (RXSS).
๐ฐ Reward received. $$$
โค40๐ฅ4๐ซก2
Stored XSS โ $$$ ๐ฐ
Found a Stored XSS in the team creation flow.
Steps:
1. Create a new team.
2. Set the team name to:
"><script>alert(document.cookie)</script>
3. Enable the option requiring all team members to use 2FA.
4. Join the same team with another user.
Result:
The second user receives a message prompting them to enable 2FA in (Team Name). Since the team name is rendered without proper sanitization, the injected JavaScript executes, resulting in a Stored XSS.
Status: โ Fixed & Rewarded.
Linkedin : https://www.linkedin.com/posts/ayman-amer1_bugbounty-storedxss-xss-activity-7479481896792608768-NSxY
Found a Stored XSS in the team creation flow.
Steps:
1. Create a new team.
2. Set the team name to:
"><script>alert(document.cookie)</script>
3. Enable the option requiring all team members to use 2FA.
4. Join the same team with another user.
Result:
The second user receives a message prompting them to enable 2FA in (Team Name). Since the team name is rendered without proper sanitization, the injected JavaScript executes, resulting in a Stored XSS.
Status: โ Fixed & Rewarded.
Linkedin : https://www.linkedin.com/posts/ayman-amer1_bugbounty-storedxss-xss-activity-7479481896792608768-NSxY
โค46๐ฅ4๐1
Self hosted +Bug bounty programsโฌ๏ธ
*.cleeng.com
security@cleeng.com
โโโโโโโโโโโโโ
*.redsift.com
security@redsift.com
โโโโโโโโโโโโโ
*.plain.com
security@plain.com
โโโโโโโโโโโโโ
*.linkdm.com
support@linkdm.com
โโโโโโโโโโโโโ
*.ory.com
security@ory.com
โโโโโโโโโโโโโ
*. aquanow.com
bugbounty@aquanow.com
โโโโโโโโโโโโโ
https://github.com/swisscom/bugbounty
โโโโโโโโโโโโโ
https://www.spendesk.com/.well-known/security.txt
โโโโโโโโโโโโโ
https://help.spreaker.com/en/articles/5123644-bug-bounty-program
โโโโโโโโโโโโโ
https://www.fjdynamics.com/jp/bug-bounty-program
โโโโโโโโโโโโโ
https://www.klook.com/bugbounty
โโโโโโโโโโโโโ
https://gobright.com/responsible-disclosure-policy/
โโโโโโโโโโโโโ
https://www.make.com/en/bounty
โโโโโโโโโโโโโ
https://www.pubnub.com/bug-bounty-policy/
โโโโโโโโโโโโโ
https://help.doit.com/docs/vendor-information/bug-bounty-program
โโโโโโโโโโโโโ
https://www.lenskart.com/vulnerability-disclosure-policy
โโโโโโโโโโโโโ
https://www.talentlms.com/vulnerabilitypolicy
โโโโโโโโโโโโโ
https://whatbox.ca/policies/security
โโโโโโโโโโโโโ
*.perlego.com
security@perlego.com
โโโโโโโโโโโโโ
https://support.playerauctions.com/hc/en-us/articles/49330305602585-PlayerAuctions-Bug-Bounty-Program
โโโโโโโโโโโโโ
*.lithicblue.com
security@lithicblue.com
โโโโโโโโโโโโโ
*.expensify.com
security@expensify.com
*.cleeng.com
security@cleeng.com
โโโโโโโโโโโโโ
*.redsift.com
security@redsift.com
โโโโโโโโโโโโโ
*.plain.com
security@plain.com
โโโโโโโโโโโโโ
*.linkdm.com
support@linkdm.com
โโโโโโโโโโโโโ
*.ory.com
security@ory.com
โโโโโโโโโโโโโ
*. aquanow.com
bugbounty@aquanow.com
โโโโโโโโโโโโโ
https://github.com/swisscom/bugbounty
โโโโโโโโโโโโโ
https://www.spendesk.com/.well-known/security.txt
โโโโโโโโโโโโโ
https://help.spreaker.com/en/articles/5123644-bug-bounty-program
โโโโโโโโโโโโโ
https://www.fjdynamics.com/jp/bug-bounty-program
โโโโโโโโโโโโโ
https://www.klook.com/bugbounty
โโโโโโโโโโโโโ
https://gobright.com/responsible-disclosure-policy/
โโโโโโโโโโโโโ
https://www.make.com/en/bounty
โโโโโโโโโโโโโ
https://www.pubnub.com/bug-bounty-policy/
โโโโโโโโโโโโโ
https://help.doit.com/docs/vendor-information/bug-bounty-program
โโโโโโโโโโโโโ
https://www.lenskart.com/vulnerability-disclosure-policy
โโโโโโโโโโโโโ
https://www.talentlms.com/vulnerabilitypolicy
โโโโโโโโโโโโโ
https://whatbox.ca/policies/security
โโโโโโโโโโโโโ
*.perlego.com
security@perlego.com
โโโโโโโโโโโโโ
https://support.playerauctions.com/hc/en-us/articles/49330305602585-PlayerAuctions-Bug-Bounty-Program
โโโโโโโโโโโโโ
*.lithicblue.com
security@lithicblue.com
โโโโโโโโโโโโโ
*.expensify.com
security@expensify.com
โค32๐ฅ2๐1
๐ฅ Live Hacking Session Today at 4:00 PM (Egypt Time) โ Join us and bring your Bug Bounty & Pentesting questions!
โค50๐ฅ5๐5
Live Hunting #6 โ Real Bug Bounty Hunting:
https://youtu.be/tjQ_IblaMVQ?si=Bf6yhcJc6pZ5sYDt
https://youtu.be/tjQ_IblaMVQ?si=Bf6yhcJc6pZ5sYDt
YouTube
Live Hunting #6 โ Real Bug Bounty Hunting
A real-time bug bounty session focused on practical vulnerability testing and hands-on security analysis.
Follow the full workflow from target selection to testing and assessment, while breaking down the mindset behind each step. The goal is not just toโฆ
Follow the full workflow from target selection to testing and assessment, while breaking down the mindset behind each step. The goal is not just toโฆ
โค29
Congratulations โค๏ธโญ๏ธ.
The course ๐ฅท:
https://youtube.com/playlist?list=PLB12OzawmZE6Zdj6oaXy_dkMF1_uIFNWa&si=_WA9E8bMr_Z_XotO
The course ๐ฅท:
https://youtube.com/playlist?list=PLB12OzawmZE6Zdj6oaXy_dkMF1_uIFNWa&si=_WA9E8bMr_Z_XotO
โค34๐ฅฐ3โคโ๐ฅ2๐1
Authz-ExeC is a Burp Suite extension that automatically tests authorization by replaying requests with different identities to detect IDOR, BOLA, Broken Access Control, privilege escalation, and cross-tenant vulnerabilities:
https://github.com/execiq/Authz-ExeC
https://github.com/execiq/Authz-ExeC
GitHub
GitHub - execiq/Authz-ExeC: Burp Suite extension for cross-identity & cross-tenant access-control testing โ BAC, IDOR, BOLA, andโฆ
Burp Suite extension for cross-identity & cross-tenant access-control testing โ BAC, IDOR, BOLA, and privilege escalation. - execiq/Authz-ExeC
โค31โคโ๐ฅ4