Live Hunting #6 – Real Bug Bounty Hunting:
https://youtu.be/tjQ_IblaMVQ?si=Bf6yhcJc6pZ5sYDt
https://youtu.be/tjQ_IblaMVQ?si=Bf6yhcJc6pZ5sYDt
YouTube
Live Hunting #6 – Real Bug Bounty Hunting
A real-time bug bounty session focused on practical vulnerability testing and hands-on security analysis.
Follow the full workflow from target selection to testing and assessment, while breaking down the mindset behind each step. The goal is not just to…
Follow the full workflow from target selection to testing and assessment, while breaking down the mindset behind each step. The goal is not just to…
❤29
Congratulations ❤️⭐️.
The course 🥷:
https://youtube.com/playlist?list=PLB12OzawmZE6Zdj6oaXy_dkMF1_uIFNWa&si=_WA9E8bMr_Z_XotO
The course 🥷:
https://youtube.com/playlist?list=PLB12OzawmZE6Zdj6oaXy_dkMF1_uIFNWa&si=_WA9E8bMr_Z_XotO
❤34🥰3❤🔥2👍1
Authz-ExeC is a Burp Suite extension that automatically tests authorization by replaying requests with different identities to detect IDOR, BOLA, Broken Access Control, privilege escalation, and cross-tenant vulnerabilities:
https://github.com/execiq/Authz-ExeC
https://github.com/execiq/Authz-ExeC
GitHub
GitHub - execiq/Authz-ExeC: Burp Suite extension for cross-identity & cross-tenant access-control testing — BAC, IDOR, BOLA, and…
Burp Suite extension for cross-identity & cross-tenant access-control testing — BAC, IDOR, BOLA, and privilege escalation. - execiq/Authz-ExeC
❤31❤🔥4
❤81🔥6🤩3
Found 2 vulnerabilities:
Reward: $1,500
Critical — Authentication Bypass
High — Authentication Bypass
LinkedIn Post
Reward: $1,500
Critical — Authentication Bypass
High — Authentication Bypass
LinkedIn Post
❤59🔥4
Found a valid IDOR vulnerability in Google🔥🔥
https://www.facebook.com/share/1C6BgmxdJs/?mibextid=wwXIfr
https://www.facebook.com/share/1C6BgmxdJs/?mibextid=wwXIfr
❤44🔥9👏1
❤86🔥14
🔥The 2 New Videos Are Live!
2FA Bypass — Empty OTP Accepted = Account Takeover:
Link
MFA Enforcement Bypass — Invite Team Members Without Enabling MFA
Link
2FA Bypass — Empty OTP Accepted = Account Takeover:
Link
MFA Enforcement Bypass — Invite Team Members Without Enabling MFA
Link
YouTube
Critical TOTP 2FA Bypass — Empty Token Accepted Leads to Account Takeover
In this video, I demonstrate a critical TOTP 2FA bypass vulnerability where the verification endpoint accepts an empty string ("") as a valid 2FA code.
By exploiting this flaw, an attacker who already knows the victim's password can bypass the TOTP verification…
By exploiting this flaw, an attacker who already knows the victim's password can bypass the TOTP verification…
❤44🔥5👏1