@ADITYASHENDE17@Bugcrowd and parameters,endpoints,files,directories, also have nested ones we have to find them also it was like huge data it was confusing like where to start and stop so how to sort this out bro
@ADITYASHENDE17@Bugcrowd https://t.co/d3F3XtuOlp, https://t.co/WW952yIB03, https://t.co/dQLP6J4ZuV , https://t.co/XGVpDcadQ9 every subdomain has virtual hosts, parameters, endpoints, files, directories so we need to find these on every subdomain and also we have to do fuzzing on all of these subdomains
@jayesh25@Hacker0x01@Shlibness files,directories, also have nested ones we have to find them also it was like huge data it was confusing like where to start and stop so how to sort this out bro
@jayesh25@Hacker0x01@Shlibness https://t.co/WW952yIB03, https://t.co/dQLP6J4ZuV , https://t.co/XGVpDcadQ9 every subdomain has virtual hosts, parameters, endpoints, files, directories so we need to find these on every subdomain and also we have to do fuzzing on all of these subdomains and parameters,endpoints,
@shreyas_chavhan i tried idors, csrf, on some websites they are some random websites without any security but when i tried to hunt on hackerone or bugcrowd i was not able to find anything what is the reason how to solve this
@spencer_5cent SSRF works on data fetching urls if a url carries any form of data like files, ip address any third party link, there are chances for SSRF but Bigger websites we can find 1k or more urls that carries some form of data in their parameters we cannot test every url how to solve it
@spencer_5cent@Rhynorater SSRF works on data fetching urls if a url carries any form of data like files, ip address any third party link, there are chances for SSRF but Bigger websites we can find 1k or more urls that carries some form of data in their parameters we cannot test every url how to solve it
@spencer_5cent Generally SSRF works on data fetching urls if a url carries any form of data like files, ip address any third party link, there are chances for SSRF but Bigger websites we can find 1k or more urls that carries some form of data in their parameters we cannot test every url
@infoscresearchr Gf patterns only shows which parameters may have chances for SSRF but if the l list have 500 url we cannot test every url individually it was not possible to test them one by one what to do in this situation
@AmitMDubey@hacktivist1337 If we find many urls like 1k how to find ssrf we cannot go to every url placing our Collab payload it is not possible to test 1k individually one by one what to do in this situation
@Yassineaboukir@taha_marzak20 For example: we use paramspider and wayback to get all parameters and sorted out the urls that carrying some form of data in their parameters for larger websites we can find nearly 2k data fetching urls to test every url individually not possible what to do in this situation
@3ncryptSaan@Bugcrowd For example: we use paraminer and wayback to get all parameters and sorted out the urls that carrying some form of data in their parameters for larger websites we can find nearly 2k data fetching urls to test every url individually not possible what to do in this situation