I've been building my AI-powered offensive security harness for the past few weeks. It's successfully solved every active HTB box (minus the insane machines). To help others learn and build alongside me, I'm giving away your choice of a 1-Month Claude Pro subscription or 1-Month HTB VIP+.
Follow -> Like -> Retweet to enter
@BugBountyDEFCON@hackthebox_eu@PentesterLab I wanted to learn code review and PentesterLab has a very good resource on that and for trending AI red teaming also HTBs learning path which covers fundamentals of AI red team. Let's see, Luck matters or Hard work is the only key in infosec.
Time for another giveaway!
We will pick 6 winners to win one of the following:
1x Annual VIP @hackthebox_eu Licence
5x @PentesterLab 3 Month Licences
To enter:
1๏ธโฃ Follow us @BugBountyDefcon
2๏ธโฃ Like this post โค๏ธ
3๏ธโฃ Re-tweet this post ๐
Giveaway open until Monday June 15th! GOOD LUCK!
When a single ID fails, a pair might pass. IDOR bypasses can be that simple ๐ฅ
- Victim's ID: 5200
- Attacker's ID: 5233
GET /api/users/5200/info โ Access Denied โ
GET /api/users/5200,5233/info โ Bypassed โ
#bugbountytips#PenetrationTesting
๐จ ZERODAY: ImageMagick ๐จ
Our autonomous pentester https://t.co/zHUcIkHqvr just dropped multiple zeroday chains in ImageMagick that achieve RCE and File Leak from a single .jpg or .pdf file, bypassing EVERY security policy (Default, Limited, AND Secure). ๐คฏ
๐ฅ Affects Ubuntu, Debian, WordPress & millions of servers globally. Happy Monday and Happy Hunting! ๐ฅฐ
https://t.co/nNAvFAvPOx
I earned $xxxx for my submission on @bugcrowd https://t.co/8GBItcviHD
#ItTakesACrowd
Bug Type- 2x Reflected XSS
Tip: use DuckDuckGo dorks as same as google dorks , you will get new endpoints
Keep your eyes peeled on these endpoints. ๐
/login โก๏ธ authentication bugs
/reset-password โก๏ธATO
/upload โก๏ธ RCE
/api/v1/user/1001 โก๏ธ BOLA
/search?q=query โก๏ธ Injection bugs
/view?file= โก๏ธ SSRF
/admin โก๏ธ internal access
Which endpoint have you found the most bugs on? ๐