I was rewarded with $$$.
Bug: File upload on open S3 bucket.
1: Found a subdomain https://t.co/L8TKOtq6uF
2: Visited https://t.co/L8TKOtq6uF found a S3 bucket in source code.
3:Opened terminal type aws s3 ls s3://bucket name.
4:Enlisted contains in bucket.
BREAKING 🚨: Don’t replace your iPhone when the battery starts draining.
BREAKING 🚨: Don’t replace your iPhone when the battery starts draining.
BREAKING 🚨: Don’t replace your iPhone when the battery starts draining.
Apple won’t say this out loud…
But your settings are draining your battery faster than they should.
I tested this myself.
Same iPhone.
Same usage.
Battery jumped from 6 hours → 10 hours just by fixing a few settings.
No new phone.
No paid apps.
No tricks.
Here’s exactly what I changed 👇
A comprehensive guide for web application penetration testing and bug bounty hunting, covering methodologies, tools, and resources for identifying and exploiting vulnerabilities. https://t.co/sTpEwxtcVU
🎉 We're giving away a MILLION-DOLLAR education (literally).
The Bug Bounty Masterclass is live! 🎓
@galnagli from our research team has earned $1,000,000+ in bounties finding vulnerabilities. Now he's walking you through his *entire* methodology.
You'll learn:
→ Web security fundamentals
→ How to map attack surfaces like a pro
→ Working with proxies to intercept and analyze traffic
→ Real-world hacks, including 9 vulnerabilities Nagli personally found
The course includes tons of hands-on challenges + certification at the end.
Ready to get into the mind of a real hacker? 🧠
Start here >> https://t.co/mFfGCaWJ90
If you're in bug bounty, for the very least you should read writeups.
I dare say this can bring you the biggest bang for the buck in your skillset.
look here: https://t.co/8zTVOgK9L8
and here: https://t.co/XLYf0Hh2Cp
Big #Bugbountytip / #bugbountytips
Google Services Hunting
Google services are amazing, and for bug hunters, it's amazing as well. In some cases, you can get some P1-P2-P3 from these services, such as
Workspaces / Sheets / Groups / Drives / Etc...
In groups: you can access emails / internal data/ credentials
In Sheets, you can access PIIs / Edit access
In Drive: you can access backups/ PII / Etc...
still hard to find and
It was an issue how to make good and at the same time fresh dorks for bug bounty programs
Then I found out that a lot of links have the same path, and it was like this
All Google resources I've found
https://t.co/2SixYDAKvE
https://t.co/tbE8WaX9CX
https://t.co/5D7Clds9cH
https://t.co/OfodYVKOk0
https://t.co/ZyA0JFkax4
https://t.co/mhIbyMF03b
https://t.co/QwByRWofh8
https://t.co/vAwAEX8KxI
https://t.co/4y1UMeZdq7
https://t.co/u7mOVPnus3
https://t.co/V9ALsFoqP9
https://t.co/2eLIaEPCGm
https://t.co/VxllqvwT6n
https://t.co/c1vkp8YrBt
https://t.co/2EkMSEUpIt
UrlScan Dorking:
page.url:"https://t.co/qb3s3f8koJ*"
page.url:"https://t.co/BNLIA1rXht*"
You can replace * => the program domain
Google Dorking:
site:https://t.co/qb3s3f8koJ* "inurl:/a/"
Or for specific domain
site:https://t.co/qb3s3f8koJ* "inurl:/a/domain.com"
GitHub Dorking:
"https://t.co/qb3s3f8koJ"
Or for a specific domain
"https://t.co/FKHqr19e0o"
Shodan Dorking:
"https://t.co/3vQLeWEs54"
Web Archive
https://t.co/c8tGyvVlH7
Don't forget:
It's not just https://t.co/pbqxKC9P4s
still you have to look for docs/groups/mail/drive/spreadsheetsX
still working in Google Research and will add more and more soon ......
Happy Hunting♥
#bugbounty
I automated finding reflected XSS using Nuclei and some passive recon data and ran it against a bug bounty program. Watch it here 👉🏼 https://t.co/2XrXOVJsUD
Just released the Ultimate IDOR Testing Checklist 🧩
I combined techniques from many sources to cover IDOR scenarios.
Know a technique I missed? Drop it in the comments.
Notion:
https://t.co/Sfc0MbrTeX
GitHub:
https://t.co/WrRA6GDodC
#bugbountytips#IDOR#AppSec#InfoSec
Spent the last week reading 250+ IDOR reports on HackerOne 🕵️♂️
Now I’ve compiled 200+ easy-to-search IDOR test cases for beginners!
Want the file? Comment IDOR & I’ll send it 💾
#BugBounty#CyberSecurity#IDOR#EthicalHacking#AppSec
Javascript For bug hunters writeups, I hope you found it usefull
https://t.co/iKhGqayDce
https://t.co/NGm2rVfudF
https://t.co/hyHha32Y5B
https://t.co/0y2ZUpih4u
A few months ago, I began studying bug bounties extensively. I've made my list public, and you can submit links to help expand it!
https://t.co/ua6MLoLNbp