I'm making a full of my methodology video ,
The actual method that i use to find privilege escalation vulnerabilities easily ๐
i have reported multiple privilege issues in hackerone using this method.
I will post the videos in *Monday* keep on eye ๐โ๐จ
#bugbounty#infosec
Reported โ Triaged โ Rewarded โ Patched
One week laterโฆ
Tried bypass with %00 โ Reported again โ Retriaged
Sometimes the patch is just the beginning.
Tips :- https://example[.]com/endpoint -> Forbidden
https://example[.]com/endpoint%00 -> bypassed
#bugbountytips