@M_e_z_o_23 Start from https://t.co/HSP1tkdfS7 ,next study & understand Bug topics from @PortSwigger website. Learn & apply them in bugbounty programs at same time. Read hackerone reports, writeups related to same bug type. In this way, apply this same approach for all vulnerabilities types.
When hunting for subdomain takeovers, a great trick is doing reverse CNAME lookups on known vulnerable services. Among all services I had success finding more subdomains via this great tool @profundisio
Query :
value:*.cname.xyz AND type:CNAME AND host:*.domain.com
#bugbounty
Just hit 1,500 Reputation points on @Hacker0x01 !
Looks like I've also made history as the first hacker with two clear verified accounts on HackerOne. ๐
https://t.co/NWI5TnT9bh & abd_4fg
#BugBounty