ForBugHunters
6.01K subscribers
90 photos
1 video
5 files
63 links
Dark Army
Bug hunting channel focused on real writeups, PoCs, and live hacking sessions, sharing practical bug bounty experience and real-world vulnerability discovery.

YouTube channel: https://youtube.com/@forbughunters
Download Telegram
Congratulations ๐Ÿ‘โค๏ธ
โค47
Whoโ€™s next ๐Ÿคฉ?
โค62
ูƒู„ ุณู†ุฉ ูˆุฃู†ุชู… ุทูŠุจูŠู† ุจู…ู†ุงุณุจุฉ ุนูŠุฏ ุงู„ุฃุถุญู‰ ุงู„ู…ุจุงุฑูƒ ๐ŸŒ™

ุชู‚ุจู„ ุงู„ู„ู‡ ู…ู†ุง ูˆู…ู†ูƒู… ุตุงู„ุญ ุงู„ุฃุนู…ุงู„ุŒ ูˆุฃุนุงุฏู‡
ุนู„ูŠูƒู… ุจุงู„ุฎูŠุฑ ูˆุงู„ุณุนุงุฏุฉ ูˆุงู„ุจุฑูƒุฉ
โค102โคโ€๐Ÿ”ฅ8๐Ÿ”ฅ1
โœ… Both vulnerabilities have been rewarded successfully!

linkedin :
https://www.linkedin.com/posts/ayman-amer1_bugbounty-cybersecurity-ethicalhacking-ugcPost-7466083479701721088-sS5F

๐Ÿ” Broken Access Control โ€” $300
https://youtu.be/Vvg7Q5Mwu-c?si=twLnRfVmXotvAqcn

โšก Business Logic โ€” $300
https://youtu.be/szRhhwB_vlE?si=7XDofnIq0INP0Led

๐Ÿ’ฐ Total Reward: $600 ๐Ÿ”ฅ
โค83๐Ÿ”ฅ7
Congratulations ๐ŸŽŠ๐ŸŽˆ
โค49๐Ÿ‘2
๐Ÿ”ฅ New Bug Bounty Reward โœ…

Linkedin:
https://www.linkedin.com/posts/ayman-amer1_bugbounty-xss-rxss-activity-7471511542061211648-O1JH

Simple RXSS

The application does not provide a public registration page and is intended only for approved business customers.

1. Enumerated target subdomains.
2. Found a login page on one of the discovered services.
3. Noticed that error messages were reflected through the statusMessage parameter.

4. Tested input reflection:

https://go-service.target.com/?statusMessage=test

5. Injected a simple XSS payload:

https://go-service.target.com/?statusMessage=<payload>

6. Payload executed successfully โ†’ Reflected XSS (RXSS).

๐Ÿ’ฐ Reward received. $$$
โค40๐Ÿ”ฅ4๐Ÿซก2
Congratulations ๐ŸŽˆ๐ŸŽŠ
โค29๐Ÿ‘3๐Ÿ”ฅ2
Congratulations ๐Ÿ‘๐Ÿคฉ

YouTube channel:

https://youtube.com/@forbughunters
โค39๐Ÿ‘5
Stored XSS โžœ $$$ ๐Ÿ’ฐ

Found a Stored XSS in the team creation flow.

Steps:

1. Create a new team.
2. Set the team name to:

"><script>alert(document.cookie)</script>
3. Enable the option requiring all team members to use 2FA.
4. Join the same team with another user.

Result:
The second user receives a message prompting them to enable 2FA in (Team Name). Since the team name is rendered without proper sanitization, the injected JavaScript executes, resulting in a Stored XSS.

Status: โœ… Fixed & Rewarded.

Linkedin : https://www.linkedin.com/posts/ayman-amer1_bugbounty-storedxss-xss-activity-7479481896792608768-NSxY
โค46๐Ÿ”ฅ4๐Ÿ‘1
Letโ€™s start ๐Ÿคฉ๐Ÿ”ฅ!
โค52๐Ÿ”ฅ4๐Ÿ‘1
Self hosted +Bug bounty programsโฌ‡๏ธ

*.cleeng.com

security@cleeng.com
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
*.redsift.com

security@redsift.com
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
*.plain.com

security@plain.com
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
*.linkdm.com

support@linkdm.com
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
*.ory.com

security@ory.com
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
*. aquanow.com

bugbounty@aquanow.com
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
https://github.com/swisscom/bugbounty
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
https://www.spendesk.com/.well-known/security.txt
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
https://help.spreaker.com/en/articles/5123644-bug-bounty-program
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
https://www.fjdynamics.com/jp/bug-bounty-program
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
https://www.klook.com/bugbounty
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
https://gobright.com/responsible-disclosure-policy/
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
https://www.make.com/en/bounty
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
https://www.pubnub.com/bug-bounty-policy/
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
https://help.doit.com/docs/vendor-information/bug-bounty-program
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
https://www.lenskart.com/vulnerability-disclosure-policy
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
https://www.talentlms.com/vulnerabilitypolicy
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
https://whatbox.ca/policies/security
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
*.perlego.com

security@perlego.com
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
https://support.playerauctions.com/hc/en-us/articles/49330305602585-PlayerAuctions-Bug-Bounty-Program
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
*.lithicblue.com

security@lithicblue.com
โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”
*.expensify.com

security@expensify.com
โค32๐Ÿ”ฅ2๐Ÿ‘1
๐Ÿ”ฅ Live Hacking Session Today at 4:00 PM (Egypt Time) โ€” Join us and bring your Bug Bounty & Pentesting questions!
โค50๐Ÿ”ฅ5๐Ÿ‘5
Live stream started
Live stream finished (2 hours)
Congratulations ๐Ÿ”ฅ๐Ÿคฉ
โค44๐Ÿ”ฅ12๐Ÿ‘3
Congratulations โค๏ธโญ๏ธ.

The course ๐Ÿฅท:
https://youtube.com/playlist?list=PLB12OzawmZE6Zdj6oaXy_dkMF1_uIFNWa&si=_WA9E8bMr_Z_XotO
โค34๐Ÿฅฐ3โคโ€๐Ÿ”ฅ2๐Ÿ‘1
Authz-ExeC is a Burp Suite extension that automatically tests authorization by replaying requests with different identities to detect IDOR, BOLA, Broken Access Control, privilege escalation, and cross-tenant vulnerabilities:
https://github.com/execiq/Authz-ExeC
โค31โคโ€๐Ÿ”ฅ4
Congratulations๐Ÿ‘๐Ÿคฉ
โค49๐Ÿ”ฅ2