Bug Bounty
10.6K subscribers
369 photos
3 videos
46 files
426 links
Bugbounty Resources • Tips • Security Zines • Writeups • Vulnerability Update • Notes • Mindmaps • Cheatsheets • Checklists • Article / Blogs • PDFs • ebooks •
Download Telegram
image.png
429.1 KB
🌱 🔥 🌵 SMB Enumeration 🌵 🔥 🌱
2👍2
Some General Info You should Look for
before Web PenTesting 🤩🔥

See :☝🏻#bugbounty #infosec
👍3
HTTP Status Code Cheat Sheet 🔥🌵

#bugbounty #infosec
🔥3
🔥🌵😲8000+ Xss Payloads🌵😲🔥
#bugbounty #infosec

Git ripo : https://github.com/Aacle/xss_payload

#bugbounty #infosec
👌3🔥1
Web Cache Poisoning🌱🌵🔥
#bugbounty #infosec

The objective of web cache poisoning is to send a request that causes a harmful response that gets saved in the cache and served to other users.

Where to find 🧵(1/n) :👇 Complete Thread

https://twitter.com/Aacle_/status/1588199064780537856?s=20&t=G9tW-LmTpkn9SteflrprpQ
👍6
6 Bugbounty Tips 😀🤩 from @EdOverflow

#infosec #bugbountytip ☝🏻
🥰2👍1
secondary context fuzzing: 🌵#bugbounty #infosec
/..%2f
/..;/
/../
/..%00/
/..%0d/
/..%5c
/..\
/..%ff/
/%2e%2e%2f
/.%2e/
/%3f (?)
/%26 (&)
/%23 (#)

via https://samcurry.net/hacking-starbucks/

100 million😲 sbux accounts disclosure
see also: https://docs.google.com/presentation/d/1N9Ygrpg0Z-1GFDhLMiG3jJV6B_yGqBk8tuRWO1ZicV8
👍3
Introducing 20 web-application hacking tools🔥🤩🌵

1. Burp Suite - Framework.

2. ZAP Proxy - Framework.

3. Dirsearch - HTTP bruteforcing.

4. Nmap - Port scanning.

5. Sublist3r - Subdomain discovery.

6. Amass - Subdomain discovery.

7. SQLmap - SQLi exploitation.

8. Metasploit - Framework.

9. WPscan - WordPress exploitation.

10. Nikto - Webserver scanning.

11. HTTPX - HTTP probing.

12. Nuclei - YAML based template scanning.

13. FFUF - HTTP probing.

14. Subfinder - Subdomain discovery.

15. Masscan - Mass IP and port scanner.

16. Lazy Recon - Subdomain discovery.

17. XSS Hunter - Blind XSS discovery.

18. Aquatone - HTTP based recon.

19. LinkFinder - Endpoint discovery through JS files.

20. JS-Scan - Endpoint discovery through JS files.


#bugbounty #bugbountytips #cybersecurity
7👍5🌚1
This book is very helpful Beginner and Intermediate lvl bug bounty hunters
🥰3👍2🔥2
8-hour-long BurpSuite Focused Course for FREE. 👇

Don't miss it.

Will expire soon

#bugbountytips
#bugbounty
#infosec
#Pentesting

https://www.udemy.com/course/bug-bounty-hunting-with-burp-suite/?couponCode=HACKITGUYS
4
Malicious File Upload Checklist #bugbounty #infosec
by
@HolyBugx

@hunter0x7


Look : 👆🏻
8👍7
How JWT WOrks & it's attack scenario😀☝🏻
by
@sec_r0
#bugbounty #infosec #hacking

Download :
https://securityzines.com/flyers/jwt.html
👍3👏1