🔥Bounty arrived
I earned $2000 for my submission on #bugcrowd
it was a priviledge escalation of user roles
Tip: if you see role based access control, try to manipulate the username value to check if backend can differentiate between usernames
#bugbounty#bugcrowd#bounty
@MiniMjStar na in nabood, backend bein username haye moshabeh ba encoding mokhtalef nemitonest tafavot bezare vase hamin user sathe paeen role user sathe bala ro migereft
Writeup minevisam barash
🔥 New Video is up 🔥
a nice vulnhub CTF called CewlKid.
it begins by getting access through making a creative wordlist and then
a reverse shell by file upload.
then we see multiple privilege escalation (horizontal and vertical) to get to root account.
Link 👇
#ctf#vulnhub
تو این ویدیو میریم سراغ یه ماشین دیگه از vulnhub به اسم PwnOS که سعی میکنیم با بررسی آسیب پذیری های سیستم دسترسی بگیریم و اون رو از طریق kernel exploit ارتقا بدیم
In this video we solve PwnOS machine from Vulnhub and try to find a way to gain access to system and escalate our privileges through kernel exploit
Video Here : https://t.co/U7S7zvAL8u
#redteam#Hacking#webapplication#penetration_testing#vulnhub