Was hunting on Apple from today morning and i did found a subdomain after some recon and the subdomain had a fileName parameter that was strong to lfi attacks but somehow after chatting with ai (not pro edition) I could bypass the waf and it now redirected me to the login page
Continueing from the post : After redirection i entered my credentials and now it shows a 500 internal server after entering the same payload that was used to bypass the waf ๐ญ๐ญ๐ญ
Teamwork makes the dream work ๐
Google Bug Hunters now supports sharing the recognition (and splitting the financial reward) for reports you have submitted, but were researched and created in collaboration with other researchers. Details ๐
https://t.co/KuN2dR4CZy
Just submitted a authentication bypass in the https://t.co/HDDMm0jFCx microsoft . And it's really critical. Finally my hard work is paying off
Never give up hackers โ
I will keep updating as the process moves ๐ธ