@binance allow everything after everyone sell thier old and new luna and when it worth $0. lost my money and found a great reason not to use binance anymore.
@binance binance is such a shit. they are enabling luna classic on 30 may till that time luna classic will be 0. and also they are listing luna 2.0 on 31 when the luna 2.0 price will be almost 0 as well. modaf**k*ng scammers. fuck you binance.
The new @Grafana CVE-2022-21703, is actually a 1 Click Authentication Bypass and full read SSRF via CSRF, all you need is XSS/TKO on Same site host and the CVSS bumps to 9.3 - Critical.
All @Grafana versions are VULNERABLE ๐
Read more at https://t.co/abqEX9oidS
#BugBounty
@Bugcrowd I remember getting invited for bugcrowd pentester certification which i was wondering coz i was new on platform and dont have much points.
the researcher success team is awesome as they told me that hackers get selected on their performance basis. for ex. bounty amount they get.
๐ 100k Giveaway ๐
Hackers walked so Bugcrowd could run. Thank you for being part of our community! ๐ ๐ฏ
To show our appreciation, we're giving away swag all day! ๐
To enter ๐๏ธ โคต๏ธ
๐ RETWEET
๐งก LIKE
โ Drop your fave Bugcrowd memory below๐
#ItTakesACrowd
@Bugcrowd@caseyjohnellis Do not underestimate manual testing. nowadays evey newcomer want to automate everything but lacking manual testing will throw more duplicates and disappointment.
finding idors and misconfigurations is the only way to stay unique in this crowd.
If you ever found ssrf & failed to access internally hosted web services then always search localhost & 127.0.0.1 in main.js or in app.js , you may end up in accessing internal web resources.
#bugbountytips#bugbounty#cybersecurity#ssrf#infosec
Alhamdolilah ..
How i was able to find it :
1- collect live subdomains using reconftw
2- run gospider -S subs -d 2 -o output (deepth of 2 is important)
3- then gf s3-buckets
#BugBounty#bugbountytip#bughuntingtips
Keep these two parameters in mind to get more invites to private programs ๐ ๐
1๏ธโฃ Proven skills that are specific to the program targets
2๏ธโฃ Dollars earned on the platform
#Hackers#BugBounty
https://t.co/SMGhyjfuoE