So I started a YouTube channel and started an iOS hacking series. Check it out! https://t.co/gxtgQGkYjQ
I know I sound like a mong on it but hey, just trying to share some knowledge. I want go get out a new video every couple of days!
#bugbountytips#bugbounty
Day 9 of #BugQuest! 🤠
Yesterday, we listed an overview of the primary ways to discover endpoints. Today, we're diving deep into one of the easiest and most overlooked methods: common configuration files.
Files like robots.txt and sitemap.xml were designed to help search engines, but they often leak valuable information about application structure, including endpoints not referenced anywhere else on the target.
Swipe through to see a few examples of config files to check and what they can reveal!
#BugBounty #HackWithIntigriti #BugQuest
Next.js, cache, and chains: The Stale Elixir
A nice work by @zhero___
This zero day brought web cache poisoning to the spotlight. His extensive research showed how source code analysis helped him craft a technique that resulted to CVE-2024-46982.
Blog link 👇
https://t.co/FG2PpfNngh
@hakluke@xnl_h4ck3r 4️⃣ JSAnalyzer
JSAnalyzer by @_jensec automatically extracts API endpoints, secrets, URLs, and sensitive files from JS responses, with smart noise filtering to reduce false positives! 🤠
🔗 https://t.co/MX5NCbb3zu
Built WinGraph, my new project - a BloodHound-style dependency visualizer for every binary in Windows System32 directory.
4,000+ DLLs, EXEs. Every import. Every export. One interactive graph.
Check it out now : https://t.co/sRtf2Lnmqn
🔥This is a continuously updated pentesting wiki by @Six2dez1 offering tools, techniques, cheat sheets, and guides covering recon, enumeration, web, cloud, mobile, Windows/Kerberos, and Burp Suite.
Link: https://t.co/HXDXglxU0H
Tired of hitting 403 errors during your security testing?
NoMore403 by @devploit automates bypass techniques to get past those pesky restrictions.
Try it at 👇
https://t.co/kX3a0oFGxO