Bug Bounty
10.5K subscribers
369 photos
3 videos
46 files
426 links
Bugbounty Resources • Tips • Security Zines • Writeups • Vulnerability Update • Notes • Mindmaps • Cheatsheets • Checklists • Article / Blogs • PDFs • ebooks •
Download Telegram
First I reported XSS trigged as medium!

I am not satisfied with that later I chained it with account takeover! Got additional. $650

Tips: - if application have feature of Api key and you can't steal session cookies!

1/n

More : 👇

https://twitter.com/bug_vs_me/status/1634090120658780162?t=X54aRAVY05Ajv0zosKda4Q&s=19
🔥7👍4👏2🍾1
Tips 🌿🌻🍂

whenever you saw any email input field!

70% bug hunters don't try XSS there as compared to name field.

always try this in email input field!

"<img/src/onerror=alert(0)"@xss.com

This don't work every time but give it a try found 2 XSS today using this!

Tips 🌿🌻🍂 👆
🔥53👍20🍌5
Audio
😄🤣
🤣30😁6🍌2
TIP:

🛡️ Admin panel access using %20 🛡️

#cybersecurity #infosec #ethicalhacking #bugbounty #bugbountytips #bugbountytip
👍14🔥4👌2
[+] Card Payment Functionality - Checklist

#bugbounty #infosec
🔥12👍3🎉3
🔥20👌1
API Hacking - RESTful API.pdf
80.9 KB
My API hacking Notes #1
👍171😁1🤔1
What I learned from reading 220* IDOR bug reports.

Credit: _nyan

https://medium.com/@nynan/what-i-learnt-from-reading-220-idor-bug-reports-6efbea44db7
8👍3
Hey 🖐 , Those Who are Interested in AI & ML learning Tips & Tricks can join This
Telegram Group : https://t.me/ai_ml_tips
👍2
Blind XSS Tips
- Create an Account
- Delete/Deactivate Account
- If the website asks for feedback, Put your payload.

#bugbountytips #BugBounty
21🔥5
Hello Team,

There is a web application security course from TCM security running in discount.

Course Name: Practical Web Application Security & Testing
Provider: TCM Security
Course Link: https://academy.tcm-sec.com/p/practical-web-application-security-and-testing
Orginal Price: $29.99
Coupon Code: HAPPYBIRTHDAYTAGGART
Discount Price: $1.18 (Inc. TAX)
🔥21👍65👏2
🤣37😁4👍3