@hakluke Worked with @G0LDEN_infosec to make:
https://t.co/uiHZlEZYIB
Scans SSL certs across IP ranges for domain info.
Faster than any tool out there atm.
Can scan all the clouds in 2.2hrs
All IPV4 space in 3 days
- Run all your subdomain tools
- uniq them
- Pass that list to: "amass enum -nf domains.txt" to insert them into the amass database.
Then track new findings each day via:
amass track -d https://t.co/PJOG8MCAFq | grep "Found"
#bugbountytips#bugbountytip
thanks @jeff_foley
Bug Bounty Tips by proglib_adv
👾 If you can embed <a>, <iframe>, <object>, and <embed> tags but block "javascript:" & "data:"
👉 try the following obfuscation techniques:
java%00script:
java%0Ascript:
java&tab;script:
📌Example:
<a href="java%0Ascript:al%0Aert()">click</a>
👀 Check Out Old Tweets Of @TodayCyberNews
#CyberSecurity #bugbountytips #BugBounty #infosec #Pentesting
Get CIDR ranges owned by an organisation with asnmap, extract domain names using dnsx then check for CDNs, WAFs and cloud providers with cdncheck! 💡
Install these tools:
asnmap 👉 https://t.co/EGWR8fPJ2a
dnsx 👉 https://t.co/1319t7GcEd
cdncheck 👉 https://t.co/Pc4qruBhMi
I built animal RFID scanner that shows you instantly the owner’s phone number (and a few other details) for lost dogs.
POC video - https://t.co/YY9Xk2a8o9
GitHub repo - https://t.co/OGQgMF3XJA
Writeup - https://t.co/DFLnrTFzKM
#hardware#RaspberryPi
XSS -> ATO Escalation Brain Dump:
* Change email -> password reset
* Change password
* Change phone -> SMS password reset
* Change security questions
* Add SSO login (login with GitHub, ect)
* Force logout -> Session Fixation
* Steal session token via non-HTTP only cookie
* Steal session token via insecure embed in page
* Steal API key for application
* Add admin user to organization
* Hijack oAuth flow and steal code
* Steal SSO code to adjacent app, then reverse SSO back to main app
* Add authentication method (SMS, email, etc)
* Gain access to refresh token for JWT or session
Got any more?
Delete any user account without user interaction
The database accepts string as it without convert it to lowercase string
1. Create a normal email ex. [email protected]
2. After the email created I able to bypass verify too
#bugbountytip#BugBounty#bugbountytips
👇👇
Still one of the best talks on contextual and missed vulns I've seen by @albinowax
🧩 Hunting Evasive Vulnerabilities: Finding Flaws That Others Miss
https://t.co/owilrhm0VL
You can do so much with the Burp Piper extension:
Why not send a JS file straight to the new JSluice tool using Piper extension and a small bit of bash script?...
🤘
#bugbountytips
I’ll be back at @bsidesahmedabad this year and I’ve got two spare tickets to giveaway.
Just like and retweet this post so I’m able to fairly and randomly choose someone on Sunday.