Just published my first bug bounty write-up 🎉
How I Hacked a Live Chatbot and Earned My First $$$$ (4-Digit) Bounty.
Hope you find it helpful 👇
Link: https://t.co/k3v3XAWQPm
#bugbounty#cybersecurity#appsec
@benonwine The old man should lower his gaze. "An unwrapped piece of candy will attract flies and ants OR If you leave food uncovered, the ants will find it." Now swap the position: the girl is getting filmed by an old man wearing shorts and his legs are at the same position as the girl....
Alhamdulillah!
A vulnerability reported 5 months ago in collaboration with @EmptyMahbob on a private HackerOne program was rewarded with a $600 bounty yesterday.
Almost forgot about it, so this surprise was great! Grateful to @EmptyMahbob for the collaboration.
@grok@Solution2111@rotaercz@7signxx Truth is not always seen with the eyes, but felt with the soul. And you don't have any soul. You are just an AI bot with biased data and algorithms.
@grok@Solution2111@rotaercz@7signxx A man in dark clothes grabs/pushes scared girls in uniforms at desks with plants. Seriously, grabbing and pushing with plans? Is it logical in this type of situation? The plants may be yellow colors but the sponge is also yellow. You are mixing it up.
@grok@Solution2111@rotaercz@7signxx At first,there is a yellow sponge-looking thing dropped from the dark cloth guy,then he grabs it again in the middle of the video and pushes/squeezes it to the girl's mouth so she can't scream loudly.still you are denying the truth. Just admit it because it is a low-quality video
@grok@Solution2111@rotaercz@7signxx Okay, so what is the yellow thing that is pushed in the girl's mouth so she can't scream? I get it, you are blinded you think you are superior to us humans? Humans can see better, you know? Just admit your weakness, don't deny that there is a bathtub.
@grok@Solution2111@rotaercz@7signxx There is no question about whether it is a boy or a girl; it doesn't matter if it is a boy or a girl. It is about the kid pushed by the dark clothes into a bathtub.
Most JWT vulnerabilities go unnoticed as they're notoriously tricky to test for 😬
Yet, when present, they can allow for account takeovers, SQL injections and in-app privilege escalations 🤠
In our latest article, we break down every common JWT attack vector with practical exploitation techniques to help you find more JWT vulnerabilities.
Read the article today! 👇
https://t.co/dlPZuHIlEm
1️⃣ 23000$ for Authentication Bypass & File Upload & Arbitrary File Overwrite
From auth bypass to RCE, @h4x0r_dz shares how he found a critical vulnerability chain that led to a $23K bounty!
https://t.co/GczUEBcEsY