Note: The scanning functionality is currently inactive on SPA (Single Page Application) web applications, and we have only tested it on websites developed with PHP, yielding remarkable results. In the future, we plan to incorporate these features into the tool.
Note: This tool maintains an up-to-date (https://www.kitploit.com/search/label/Up-to-date) list of file extensions that it skips during the exploration process. The default list includes common file types such as images, stylesheets, and scripts (".css",".js",".mp4",".zip","png",".svg",".jpeg",".webp",".jpg",".gif"). You can customize this list to better suit your needs by editing the setting.json file.. Installation $ git clone https://github.com/joshkar/X-Recon
$ cd X-Recon
$ python3 -m pip install -r requirements.txt
$ python3 xr.py
Target For Test: You can use this address in the Get URL section http://testphp.vulnweb.com
Download X-Recon (https://github.com/joshkar/X-Recon)
$ cd X-Recon
$ python3 -m pip install -r requirements.txt
$ python3 xr.py
Target For Test: You can use this address in the Get URL section http://testphp.vulnweb.com
Download X-Recon (https://github.com/joshkar/X-Recon)
Insecure Firebase Unauthorized Write Access on Crypto Exchange Bug Bounty
https://scr1pty.medium.com/insecure-firebase-unauthorized-write-access-on-crypto-exchange-bug-bounty-9e9187b627b1?source=rss------bug_bounty-5
https://scr1pty.medium.com/insecure-firebase-unauthorized-write-access-on-crypto-exchange-bug-bounty-9e9187b627b1?source=rss------bug_bounty-5
>Hello My Hackermen!Continue reading on Medium » (https://scr1pty.medium.com/insecure-firebase-unauthorized-write-access-on-crypto-exchange-bug-bounty-9e9187b627b1?source=rss------bug_bounty-5)
Insecure Firebase Unauthorized Write Access on Crypto Exchange Bug Bounty
>Hello My Hackermen!Continue reading on Medium »
Read more...
>Hello My Hackermen!Continue reading on Medium »
Read more...
Medium
Insecure Firebase Unauthorized Write Access on Crypto Exchange Bug Bounty
>Hello My Hackermen!
CVE-2024–4358 Critical Flaw Found in Progress Telerik Report Server
Details about this CVE can be read here. I’m starting without any time waste.Continue reading on Medium »
Read more...
Details about this CVE can be read here. I’m starting without any time waste.Continue reading on Medium »
Read more...
Medium
CVE-2024–4358 Critical Flaw Found in Progress Telerik Report Server
Details about this CVE can be read here. I’m starting without any time waste.
CVE-2024–4358 Critical Flaw Found in Progress Telerik Report Server
https://medium.com/@arafatx90n/cve-2024-4358-critical-flaw-found-in-progress-telerik-report-server-0f379f844819?source=rss------bug_bounty-5
https://medium.com/@arafatx90n/cve-2024-4358-critical-flaw-found-in-progress-telerik-report-server-0f379f844819?source=rss------bug_bounty-5
Details about this CVE can be read here. I’m starting without any time waste.Continue reading on Medium » (https://medium.com/@arafatx90n/cve-2024-4358-critical-flaw-found-in-progress-telerik-report-server-0f379f844819?source=rss------bug_bounty-5)
I just redesign the website to give a clearer purpose and improve the code to offer more functionality, here it is the result…Continue reading on Medium » (https://medium.com/@bugbountydegen/smartauditor-ai-and-new-chatgpt-bot-for-audits-a8361ec7f52d?source=rss------bug_bounty-5)
27.5 Lab: DOM-based cookie manipulation
https://cyberw1ng.medium.com/27-5-lab-dom-based-cookie-manipulation-b939af57ef06?source=rss------bug_bounty-5
https://cyberw1ng.medium.com/27-5-lab-dom-based-cookie-manipulation-b939af57ef06?source=rss------bug_bounty-5
This lab demonstrates DOM-based client-side cookie manipulation.Continue reading on Medium » (https://cyberw1ng.medium.com/27-5-lab-dom-based-cookie-manipulation-b939af57ef06?source=rss------bug_bounty-5)
SmartAuditor.AI and new ChatGPT bot for audits
I just redesign the website to give a clearer purpose and improve the code to offer more functionality, here it is the result…Continue reading on Medium »
Read more...
I just redesign the website to give a clearer purpose and improve the code to offer more functionality, here it is the result…Continue reading on Medium »
Read more...
Medium
SmartAuditor.AI and new ChatGPT bot for audits 🎉
I just redesign the website to give a clearer purpose and improve the code to offer more functionality, here it is the result…
27.5 Lab: DOM-based cookie manipulation
This lab demonstrates DOM-based client-side cookie manipulation.Continue reading on Medium »
Read more...
This lab demonstrates DOM-based client-side cookie manipulation.Continue reading on Medium »
Read more...
Medium
27.5 Lab: DOM-based cookie manipulation
This lab demonstrates DOM-based client-side cookie manipulation. To solve this lab, inject a cookie that will cause XSS on a different page…
Another Easy P4?
Hello Everyone, welcome back to another series of easy P4 vulnerabilities accepted on Platform and VDP which people aren't aware of.Continue reading on Medium »
Read more...
Hello Everyone, welcome back to another series of easy P4 vulnerabilities accepted on Platform and VDP which people aren't aware of.Continue reading on Medium »
Read more...
Medium
Another Easy P4?
Hello Everyone, welcome back to another series of easy P4 vulnerabilities accepted on Platform and VDP which people aren't aware of.