Bug Bounty
10.6K subscribers
369 photos
3 videos
46 files
426 links
Bugbounty Resources • Tips • Security Zines • Writeups • Vulnerability Update • Notes • Mindmaps • Cheatsheets • Checklists • Article / Blogs • PDFs • ebooks •
Download Telegram
Cookie Based Authentication Vulnerabilities🔥

Link : github.com/imran-parray/M

#bugbounty #infosec
👍5
XML EXTERNAL ENTITY (XXE) Vulnerability 🌵
by @cyph3r_asr

In More Detail :
smoggy-mozzarella-076.notion.site/XXE-9d5d3f12a5

#bugbounty #infosec
👍2😢2🍾2
I finally got ffuf to output to a text file in a decent way for automation:

ffuf -w /tmp/wordlists.txt -u URL/FUZZ -r -ac -v &>> /tmp/output.txt ; sed -i 's/\:\: Progress.*Errors.*\:\://g' /tmp/output.txt ; sed -i 's/\x1B\[[0-9;]\{1,\}[A-Za-z]//g' /tmp/output.txt

#bugbounty #infosec #SecurityEveryday #Pentesting
👍5👏4👌3
A simple bypass for XXE

To avoid XXE Injections, some web applications have custom filters that will block requests which contain "application/xml" Content-Type, to bypass these filters, we can set the Content-Type to wildcard "*/*"

#bugbounty #Infosec #securitytips
👨‍💻51
QnA : will help Beginners a lot

https://www.youtube.com/watch?v=DgsvUvt18mA
👏2
Should I add a discussion box below some Post which is discussable ?
Anonymous Poll
96%
Yes, I want to discuss
4%
No, i don't need to discuss anything
Bug Bounty pinned Deleted message
Bug List (Most Commonly Found) 🔥🌵

More Clarity : https://pbs.twimg.com/media/FhVuIKHVsAEKnpD?format=png&name=medium

#bugbounty #Infosec
👏4🔥3🕊1
Bugbounty Tips

Use round brackets to inject XSS / SQLi / RCE payloads in a valid e-mail address.

yourname${}<>'/"*-@domain.com
yourname(${}<>'/"*-)@domain.com
yourname@(${}<>'/"*-)domain.com

#bugbounty #infosec #cybersecurity
7👍3😍1
Those who wants to purchase Tryhackme voucher.

please go fast

Because I personly request to the seller for discount, for you guys

This offer valid for today { according to IST }
👍3🤬2
I've Received Screenshots From the seller, those who purchased Till now
👍2🤯1