Bug Bounty
10.5K subscribers
369 photos
3 videos
46 files
426 links
Bugbounty Resources • Tips • Security Zines • Writeups • Vulnerability Update • Notes • Mindmaps • Cheatsheets • Checklists • Article / Blogs • PDFs • ebooks •
Download Telegram
Big respect  for this Egyptian 🇪🇬 guy

Reads my website article for almost 40m 😲😧
🫡37🍌4🔥32👌2
👍9🔥3
Complete OSCP Guide With Active Directory

Amazing Article Contains :
• lots of tips
• Recommended Tools For Active Directory
• Recommended Labs To Solve For Active Directory
• Cheatsheet
• Resources

Take 👇 : Look
https://bugbountyguide.org/index.php/2022/11/29/oscp-preparation-with-active-directory/

#bugbounty #infosec #oscp
🔥7👍6👏2❤‍🔥1🏆1
Found Open Redirection Vulnerability in Google

I'll share POC with you soon
🔥49👍6👏3
email verification bypass

• After registering with email 1 you'll get verification link on email 1
• Change email to email 2 instead of verifying email 1
• Check if email verification link sended priviously on email 1 is valid for verifying email 2
👍29🔥17
secondary context fuzzing: 🌵
#bugbounty #infosec

/..%2f
/..;/
/../
/..%00/
/..%0d/
/..%5c
/..\
/..%ff/
/%2e%2e%2f
/.%2e/
/%3f (?)
/%26 (&)
/%23 (#)

via https://samcurry.net/hacking-starbucks/

100 million😲 sbux accounts disclosure
see also: https://docs.google.com/presentation/d/1N9Ygrpg0Z-1GFDhLMiG3jJV6B_yGqBk8tuRWO1ZicV8
🔥6👍4
👍8🔥7
Bug Bounty Recon Methodology For Beginners : Link
🔥9👍7
Live Hacking On Indeed with Tess 💥 | Watch
👍8🔥4
Bug Bounty 🪲 Tip:
Target had a /?back= parameter,

but payloads like javascript://alert(1) did not work.

Exploited using the following with URL-encoded ASCII tab characters:
%09Jav%09ascript:alert(document.domain)

#bugbountytips #bugbounty
👍23🔥6
XSS CHEAT SHEET 2020 edition.pdf
1.1 MB
🔰 Amazing Cheatsheet { You Must Follow This }
🔥23👍61
👍91🥰1
All Network Services & Ports with Enumeration techniques

https://bugbountyguide.org/2022/12/24/all-network-services-ports-enumeration/
🔥14👍42
An interesting trick: you can bypass a WAF during a XSS attack on ASP(dot)NET/IIS technology by using a HTTP parameter pollution attack.

#BugBounty #BugBountyTips #InfoSec

(Credit to Acunetix)
Full article: https://acunetix.com/blog/whitepaper-http-parameter-pollution/
13🔥4
👍9🔥7🤩1
Tryhackme voucher at a cheap price.

At Rs 155 / 2.2$ for a month

This guy is providing @Infosec_lover | Verified by me
9