https://domain/?p=XSS - false
https://domain/?p[]=XSS - true
Yay, I was awarded a $2,000 bonus(+$1000 initial ) bounty on @Hacker0x01! https://t.co/StivK5HZA1 #TogetherWeHitHarder#bugbounty
Lineage2 все,заебало(@NCSOFT). Пофармил адену в реале.
Баги за каждым новым GET/POST запросом :
-Youtubekids-rXSS
-Azure/Dynamics365-экосистема с открытиями каждый день(Повышение привилегий)
*Снова отложил маску Анонимуса и перестал давить кавычку до нового лета*
#BugBounty
The good old google dorks still work. Maximum profit with minimum effort. Remember, this is still a powerful source for finding bugs. I advise you to get your own tool with support for bypassing google captcha.
#bugbounty#bugbountytips
Spent some time on @ATT bugbounty program.
+ huge scope
+ generic bugs everywhere
+ good training platform for beginners like me
- they will totaly ignore you with your question
- not a transparent reward system
- still did not receive my reward ¯ \ _ (ツ) _ / ¯
#bugbounty
Got 10k$(initial+final payments) for IDOR via graphql request. It was possible to change some information on all https://t.co/DfO7jgfFjB personal pages.
#BugBounty