Hi everyone, The new video is out!
Learn how to chain reflected xss with cors misconfiguration to increase its impact
Video Link: https://www.youtube.com/watch?v=Rz44oTCxULs
Learn how to chain reflected xss with cors misconfiguration to increase its impact
Video Link: https://www.youtube.com/watch?v=Rz44oTCxULs
YouTube
Chaining Vulnerabilities: Reflected XSS + CORS = More Impact!! | Live Demonstration | 2024
In this video, Iβll walk you through how to chain reflected XSS with CORS misconfigurations to amplify the overall impact of your findings. By combining these vulnerabilities, we can demonstrate more severe consequences, which can often lead to higher bounties.β¦
π10β€6
I still remember the time(2020)when I had no laptop/pc so I used to run kali linux on my Android device to learn hacking & pen testing.
And now, 4 years later: I have three awesome laptop with each of them hazing unique use cases!
(The one at the top is my first laptop and it is really priceless to me)
I would really like to thank God, my parents, all of my fellow subscribers on BePractical and telegram members here for supporting me throughout my journey! β€οΈ
And now, 4 years later: I have three awesome laptop with each of them hazing unique use cases!
(The one at the top is my first laptop and it is really priceless to me)
I would really like to thank God, my parents, all of my fellow subscribers on BePractical and telegram members here for supporting me throughout my journey! β€οΈ
β€59π6π6β€βπ₯1
Found XSS by bypassing the misconfigured CSP in one of the govt website of India!
Tip: Check out this new amazing tool that will be very useful in fuzzing interesting payloads, tags & events that will be useful when bypassing waf or csp (https://github.com/Asperis-Security/xssFuzz)
Tip: Check out this new amazing tool that will be very useful in fuzzing interesting payloads, tags & events that will be useful when bypassing waf or csp (https://github.com/Asperis-Security/xssFuzz)
π22π1
#Discussion 1: How can you start in bug bounty?
(Comment down your thoughts on how can be begin the hunting journey & let's start discussion on it!)
(Comment down your thoughts on how can be begin the hunting journey & let's start discussion on it!)
π9π1
This media is not supported in your browser
VIEW IN TELEGRAM
POV: It's late at night.. Your internet pack has just expired.. So you hacked your neighbors WiFi
#hackermanπ
#hackermanπ
π19π€£6π³2π1π₯1
Discussion #2: Which is the tool that you commonly use when doing web recon?
(Comment it down below)
For me it's Ffuf
(Comment it down below)
For me it's Ffuf
β€9π1
Hi everyone! New video will be releasing tomorrow!(btw i have tried something new on this video so please let me know in the comments if this new format feels niceβοΈ)
Thanks for all your support!β€
Thanks for all your support!β€
β€11
Hi everyone, New video is out!
Check out how i was able to bypass content security policy(csp) on a live target!
Video Link: https://www.youtube.com/watch?v=Hz6zfXMdl54
Check out how i was able to bypass content security policy(csp) on a live target!
Video Link: https://www.youtube.com/watch?v=Hz6zfXMdl54
β€12π4
#Discussion 3:
You are given these two targets to find vulnerabilities
api.test.com (homepage returns 403)
test.com(returns a static web app)
What will be your methodology??
(Comment your approach below!)
You are given these two targets to find vulnerabilities
api.test.com (homepage returns 403)
test.com(returns a static web app)
What will be your methodology??
(Comment your approach below!)
β€8
#Discussion 4: What's the most underrated tool that you would recommend to bug bounty hunters?
β€3
HI everyone, New video is out! Check out how we can turn an informative report into traiged with these 3 effective ways!
https://www.youtube.com/watch?v=UEz_DKfmmCc
https://www.youtube.com/watch?v=UEz_DKfmmCc
YouTube
3 Proven Techniques to Get Your Bug Bounty Report Accepted!
Are you struggling to get your bug bounty reports accepted? Youβre not alone! In this video, Iβll share 3 proven techniques that can help you elevate your submissions from "informative" to "accepted." Whether youβre just starting out or looking to sharpenβ¦
π8β€3π₯2
While i have shared a lot of my bug bounty success story with you all, let me share story of my failures!
You know, When i was starting bug bounty hunting, I was unable to report a valid vulnerability for 6 month straight! Every report that i submitted got marked as informative, not applicable and duplicate! At that time, i was very demotivated, stressed and depressed. I was thinking, "Maybe bug bounty is not my thing" but suddenly, I started questioning myself:
1. Didn't i wanted to learn cyber security because it is my passion?
2. Am i only focusing on reporting vulnerabilities instead of improving my skills?
By asking these questions, I understand one thing: I need to switch my focus on learning, improving and hacking instead of getting demotivated because i was not getting any rewards! And eventually, I was able to get that first vulnerability and now i can easily say that i am the better version of myself than before!
You know, When i was starting bug bounty hunting, I was unable to report a valid vulnerability for 6 month straight! Every report that i submitted got marked as informative, not applicable and duplicate! At that time, i was very demotivated, stressed and depressed. I was thinking, "Maybe bug bounty is not my thing" but suddenly, I started questioning myself:
1. Didn't i wanted to learn cyber security because it is my passion?
2. Am i only focusing on reporting vulnerabilities instead of improving my skills?
By asking these questions, I understand one thing: I need to switch my focus on learning, improving and hacking instead of getting demotivated because i was not getting any rewards! And eventually, I was able to get that first vulnerability and now i can easily say that i am the better version of myself than before!
β€βπ₯32π₯8β€6π6
What are your feedbacks on the new video?
Anonymous Poll
87%
It's awesome! Make more videos like this
9%
No, stick to your old format
4%
Others(comment your feedback)