Open Redirect To XSS
Payloads : https://book.hacktricks.xyz/pentesting-web/open-redirect#open-redirect-to-xss
#bugbounty #infosec #cybersecurity #hacking
Payloads : https://book.hacktricks.xyz/pentesting-web/open-redirect#open-redirect-to-xss
#bugbounty #infosec #cybersecurity #hacking
🔥10👍4👎1🤔1
🔰 Top 10 Mistakes & Myths Of Bug bounty hunting
https://bugbountyguide.org/2022/12/16/top-10-mistakes-myths-in-bug-bounty-hunting/
https://bugbountyguide.org/2022/12/16/top-10-mistakes-myths-in-bug-bounty-hunting/
👍9🔥3
Complete OSCP Guide With Active Directory
Amazing Article Contains :
• lots of tips
• Recommended Tools For Active Directory
• Recommended Labs To Solve For Active Directory
• Cheatsheet
• Resources
Take 👇 : Look
https://bugbountyguide.org/index.php/2022/11/29/oscp-preparation-with-active-directory/
#bugbounty #infosec #oscp
Amazing Article Contains :
• lots of tips
• Recommended Tools For Active Directory
• Recommended Labs To Solve For Active Directory
• Cheatsheet
• Resources
Take 👇 : Look
https://bugbountyguide.org/index.php/2022/11/29/oscp-preparation-with-active-directory/
#bugbounty #infosec #oscp
🔥7👍6👏2❤🔥1🏆1
Found Open Redirection Vulnerability in Google
I'll share POC with you soon
I'll share POC with you soon
🔥49👍6👏3
email verification bypass
• After registering with email 1 you'll get verification link on email 1
• Change email to email 2 instead of verifying email 1
• Check if email verification link sended priviously on email 1 is valid for verifying email 2
• After registering with email 1 you'll get verification link on email 1
• Change email to email 2 instead of verifying email 1
• Check if email verification link sended priviously on email 1 is valid for verifying email 2
👍29🔥17
secondary context fuzzing: 🌵
#bugbounty #infosec
/..%2f
/..;/
/../
/..%00/
/..%0d/
/..%5c
/..\
/..%ff/
/%2e%2e%2f
/.%2e/
/%3f (?)
/%26 (&)
/%23 (#)
via https://samcurry.net/hacking-starbucks/
100 million😲 sbux accounts disclosure
see also: https://docs.google.com/presentation/d/1N9Ygrpg0Z-1GFDhLMiG3jJV6B_yGqBk8tuRWO1ZicV8
#bugbounty #infosec
/..%2f
/..;/
/../
/..%00/
/..%0d/
/..%5c
/..\
/..%ff/
/%2e%2e%2f
/.%2e/
/%3f (?)
/%26 (&)
/%23 (#)
via https://samcurry.net/hacking-starbucks/
100 million😲 sbux accounts disclosure
see also: https://docs.google.com/presentation/d/1N9Ygrpg0Z-1GFDhLMiG3jJV6B_yGqBk8tuRWO1ZicV8
🔥6👍4
Why Security Headers are Important for websites
https://bugbountyguide.org/2022/12/19/why-security-headers-are-important-for-websites/
https://bugbountyguide.org/2022/12/19/why-security-headers-are-important-for-websites/
👍8🔥7
Bug Bounty 🪲 Tip:
Target had a /?back= parameter,
but payloads like javascript://alert(1) did not work.
Exploited using the following with URL-encoded ASCII tab characters:
%09Jav%09ascript:alert(document.domain)
#bugbountytips #bugbounty
Target had a /?back= parameter,
but payloads like javascript://alert(1) did not work.
Exploited using the following with URL-encoded ASCII tab characters:
%09Jav%09ascript:alert(document.domain)
#bugbountytips #bugbounty
👍23🔥6
The Game of HTTP Request And Response
https://bugbountyguide.org/2022/12/23/understand-the-game-of-http-request-and-response/
#bugbounty #Infosec
https://bugbountyguide.org/2022/12/23/understand-the-game-of-http-request-and-response/
#bugbounty #Infosec
👍13
All Network Services & Ports with Enumeration techniques
https://bugbountyguide.org/2022/12/24/all-network-services-ports-enumeration/
https://bugbountyguide.org/2022/12/24/all-network-services-ports-enumeration/
🔥14👍4❤2
✨ Huge Bug Bounty Mindmap
https://bugbountyguide.org/bug-bounty/mindmaps-cheatsheets#Bug-bounty-mindmap
https://bugbountyguide.org/bug-bounty/mindmaps-cheatsheets#Bug-bounty-mindmap
👍14🔥4
Web Application Security Mindmap
https://bugbountyguide.org/bug-bounty/mindmaps-cheatsheets/#Web%20Application%20Security%20Mindmap
#bugbounty #infosec
https://bugbountyguide.org/bug-bounty/mindmaps-cheatsheets/#Web%20Application%20Security%20Mindmap
#bugbounty #infosec
👍8🔥2
An interesting trick: you can bypass a WAF during a XSS attack on ASP(dot)NET/IIS technology by using a HTTP parameter pollution attack.
#BugBounty #BugBountyTips #InfoSec
(Credit to Acunetix)
Full article: https://acunetix.com/blog/whitepaper-http-parameter-pollution/
#BugBounty #BugBountyTips #InfoSec
(Credit to Acunetix)
Full article: https://acunetix.com/blog/whitepaper-http-parameter-pollution/
❤13🔥4
Tryhackme voucher at a cheap price.
At Rs 155 / 2.2$ for a month
This guy is providing @Infosec_lover | Verified by me
At Rs 155 / 2.2$ for a month
This guy is providing @Infosec_lover | Verified by me
❤9