More than 280 million people suffer from depression worldwide.
Over 700 000 people die due to suicide every year. Suicide is the fourth leading cause of death in 15-29-year-olds. (WHO/2021)
If you feel depressed, alone, or lost, there is help to get. You are not alone.
@MantisSTS If it's e-commerce, check redemption flows especially when a default cc is stored. I had success with POST based Gift cards add to carts and redemptions.
This is @codingo_ 's first video and comprehensive written guide. His guide to ffuf is actually more comprehensive than the ffuf readme! I can see his content becoming the ultimate reference guide for hacking/bb stuff. Follow/sub to him everywhere!
@zseano Love this! I think 75 or 80% of the bugs I've found are on the main site. Recon is great for learning how the entire Enterprise deploys as well as architectures at play.
Question for #bugbounty#BugBountyTips would you submit exposed source code (.jsx files) via the browser? Only appears on a certain page and seems like the full app.
Not seeing any keys but tons of endpoints as well as custom code and full node_modules folder.
dang today became such a better day when I realized I could use _ in SED instead of /
echo '"https://t.co/ZWHeWAxArG"' | sed 's_"__g' is the same thing as echo '"https://t.co/ZWHeWAxArG"' | sed 's/"//g'
substitute all double quotes with nothing.
#linuxnoob
@fin1te Incredible post! I love the part about P0s. It's crazy when you spend some time on the "other side" prioritizing tons of security issues. Bug bounties are important and great, but don't represent all the risk to an org. Really great context to learn.
@mubix Really silly one... I suck at regex and I shouldn't. A coworker corrected a really dumb regex mistake I was making on a call and I realized how hard I was making that particular workflow. He was so matter of fact, it was super pleasant, and I learned something awesome.
Hit 2 personal goals today on @Bugcrowd
1. Top 1000!
2. Pass 2019 earnings in 2020.
set personal goals you can celebrate, the more obtainable the better!
#BugBounty
As per the vote results, here you go!
A cool XXE resulting from a SSRF found on local company website during a pentest. DMs are open, retweet and like if you love this style of PoC! 😎
#bugbounty#bugbountytip#bugbountytips#infosec
If javascript: is being filtered try some other payloads that might still work in <a href='payload'>
java%0Ascript:
java%0Dscript:
java%20script:
anything others?
#bugbounty#bugbountytips
Over the last couple of weeks I had some down time and got the itch to hit some Bug Bounty programs. Reported a couple of vulnerabilities which ultimately lead to my first payout! Thanks @Bugcrowd ! #bugbounty