Time-Based Blind SQL Injection in Dataapps UUID
Pro Tip: Don't just test UUIDs for IDOR, they're often unparameterized DB inputs. That makes them prime SQLi candidates.
#penetrationtesting#cybersecurity#bugbounty
Yay 🎉 I’ve hit 10K reputation on @Hacker0x01 / 0 VDPs 🙌
late to the club :)
If you’re feeling stuck and want to move from VDPs to bug bounty programs, feel free to reach out.
#bugbounty#bugbountytips#hackerone
The written version of my BSides Riga and @bsidesvilnius talks is up: exploiting git integrations in cloud services, with four bugs I found in GCP (Looker, Dataform), including the one that won me MVH.
https://t.co/HuWlK5dnfj
Duel has just paid me $30,000 for another one-click account takeover exploit which allowed me to verify any email without accessing the inbox; huge thanks to Monarch and Plank
3 events, 3 days, over $3m paid and a new bug bash industry record. If you’re not hacking on @Bugcrowd you’re missing out on the best events the industry has to offer.
Love our crowd. You are all so incredible.
@samm0uda Going to self plug here, because if you're thinking about making that leap, there's a lot more to think about than just raw bb return: https://t.co/y8lcmrt4I0
1/ We just published our first Bug Bulletin, the spot where we aim to share cool bugs we found in our own and external code, and how we found them https://t.co/prMglhDCof 🧵
@BountyOverflow dalfox file targets -o results.txt
Different places that reflect contents from the URL.
It will spend most of the time scanning the same 404 responses so make sure the targets are significantly different.
Can get targets via Manuel, spider, waybackurls (false positives)
I encourage you to watch @0xLupin talk about chatGPT and how it find security bugs in a piece of code.Also he challenged it to find a bug i found in FB (a write-up i previously published) you can check the results: (it's in french but captions work fine) https://t.co/IyKWmvDSDW
Bug write-up for Google Extensions thanks @ThomasOrlita and others for the help :) https://t.co/RK6x3ZQ4mI this writeup does include some free XSSs I got board of waiting.
Great and simple tool to follow vulns, you can see trends and also find social media posts related to one CVE, making it easier to gather additional information about the vulnerability or find PoCs.