1) Sometimes svg file upload can leads to blind xss on support desk (same as svg xss).
2) check for the redirect parameter and append javascript:alert'1' payload.
3) Bypass 2FA through IP-Rotate burp extension.
@Prathameshwarak Hi Bro, You can use below mentioned report as a reference report. Also, I will include the vulnerability discription along with step to reproduce, impact and POC video .
https://t.co/euUTlnA5UB
#bugbountytips
Sometimes when you visit a website using burp suite cloudflare stops you, but when you disable the proxy it works. here is how to bypass it using burp suite โ๏ธ
Enable match and replace with the following:
https://t.co/spxwWXf7NP
#Cloudflare#BugBounty
Two more days before our Black Friday specials!
And we just reached 90K followers! Let's celebrate!
We are going to give a 1-month voucher to 90 people who RT this tweet and follow @PentesterLab (picked randomly)!
This is how I have jumped into the web3:
Most of the Ethereum details can be learned doing CTF challenges, and in the game format it is easier to remember and learn things. But before doing the CTFs, watch this Youtube thread:
https://t.co/U2WgvtIabo
1/
Check out my blog! It's a quick read. Solving the 2022 Payment Village challenges. If you're interested in banking-specific vulnerabilities - rounding attacks, scientific notation bugs, kiosk bypasses, and simulated ATM hacking you'll enjoy it โค๏ธ
https://t.co/WPk2awOTCb
Enumerate all the subdomain's and functionalities.
Delete the csrf parameter and value.
Provide null csrf token as a bypass.
Xss payload :- <img src=x onerror=prompt(1)>
autorize burp ext for access & priv vulns.
#bugbounty
CSRF ON ACCOUNT DELETING FUNCTIONALITY
1) Always remove the csrf token parameter in the request.
After fixing the vulnerablity try to bypass the fix ๐
2) create a new user and capture the csrf token and check if that token accepting or not.
#bugbounty#bugbountytips