A lot of you guys were requesting Gitbook for HowToHunt.
It took hell lot of work to arrange them 😓,
hope so you like it, and make some pull request, what's left.🙂
Here you go: 🔥
https://t.co/MWI5jlYnYI
#bugbountytips#bugbounty#BugBountyTips
EXCLUSIVE: 200+ Government of India websites have been hacked!
From Google, they now redirect to vc66 [dot] net, a domain registered on Dec 21, 2024. Its an online money-making scam but links to malware—an attack called SERP hijacking.
Search [site:*.gov.in fast cash] to see.
Created a small tool to retrieve archived snapshots urls of web pages from the Internet Archive. Use it in your recon and let me know your feedback!! 😄
#bugbounty#bugbountytips#infosec
Updated WayBackFetch with a new feature that removes snapshot urls with duplicate content, leaving only urls with unique content. Thank you, Sensei @dwisiswant0 👍
If you haven't already checked the project here's the GitHub link : https://t.co/898wZern0X
I found the solution using httpx itself, so the solution is that you need to find the sweet spot for threads. "-t 5" worked for me. It varies from target to target, so add this step to your recon checklist before running any tool for best results.
#bugbountytip 😅
Httpx seems to be not reliable when checking urls suggest some tool which can do better job and also has filter based on web content or title.
#BugBounty
A lot of you guys were requesting Gitbook for HowToHunt.
It took hell lot of work to arrange them 😓,
hope so you like it, and make some pull request, what's left.🙂
Here you go: 🔥
https://t.co/MWI5jlYnYI
#bugbountytips#bugbounty#BugBountyTips
HowToHunt is updated with some new resources and techniques check out: https://t.co/8xkz6rmD9B
- Reverse Engineer an API by @offensivedroid
- 2FA bypass method by @ome_mishra
- GraphQL Resource
.. and more
Sorry guys for late update lots of new things going in life. 😅
Setting up an analysis VM for reverse engineering?
Here are a few good tools (with short demos) that I recommend after running the Mandiant/FLARE script, (which installs 99% of tooling for you) 🔥
TLDR:
Garbageman, SpeakEasy, BlobRunner, Dumpulator
#Malware#RE#Analysis
Lessons:
- Context is King. THINK!
- To break you must first understand: Know your target's technologies & the services they use.
- Learn to code.
Top:
https://t.co/M1R6j67Tkh
I've made over 100k on SSRF vulnerabilities.
They aren't always as simple as pointing it at localhost or AWS Metadata service.
Here are some tricks I've picked up over the past 5 years of web app testing:
The iOS Reloader is a weaponizing tool designed for jailbroken iOS devices. It facilitates the installation of a collection of essential tools on iOS devices for penetration testing purposes.
https://t.co/qXR8A3EJPG
#HR51KDB#bugbountytip#bugbountytips#ios#vapt
Excited to kickstart my career as a Cyber Security Engineer at @Qualcomm! Joining the amazing #TeamQualcomm and ready to learn, grow, and make a difference in the world of technology. Grateful for the opportunity! 💪🔒✨ #New2Q#Qniversitygrad