I managed to RCE Fortune 500 companies and made over $50,000 with this technique.
A new npm supply chain technique we just disclosed. The trick is dumb-simple.
We call it npx Confusion.
🧵
I am experiencing an issue with a withdrawal from @yeswehack . I made a withdrawal from my wallet 18 days ago, but I still have not received the funds in my bank account. Could you please help check if there is any issue with the transaction ? @yeswehack
Find the origin servers of websites protected by Cloudflare, Sucuri, or Incapsula with a misconfigured DNS. ⚔️
- https://t.co/cGWegtzlRT
#infosec#bugbountytips#Cybersecurity
PostMessage vulnerabilities can lead to all sorts of issues, from DOM-based XSS to information disclosure & application-level DoS.
In our comprehensive article, we've documented how you can identify and exploit postMessage vulnerabilities for more impact. 👇
🔗 https://t.co/EuNEZdi8fh
I am currently unable to complete the SCA verification because I do not receive the SMS OTP required to complete the process. As a result, I am unable to withdraw funds from my wallet.
Please help me @yeswehack 😟
My 4 reports on 4 different domains were marked as duplicates of a report that has already been resolved. I contacted the support team, but it seems like nothing is being resolved. I'm feeling very disappointed
@yeswehack
Some applications use protection mechanisms that rely solely on client-side input checks without validating anything on the backend. After bypassing them, some programs claim that the issue is just a UX flaw and not a security vulnerability.
#BugBounty
It has been a great month with many reports submitted, but there’s also a bit of sadness — several reports have had no updates for almost 6 months.
Hopefully everything turns out well.
Have nice day .🥰🥰🥰
#yeswehack@yeswehack