If you're struggling to setup Genymotion + BurpSuite + Frida, then spare some minutes to read about my writeup about it.
https://t.co/yGsEBS4y15
#bugbounty#bugbountytips#MobileSecurity
I discovered a Server-Side Request Forgery (SSRF) vulnerability in InvoiceNinja, which allowed unauthorized access to local files on the server. For a more detailed explanation, you can refer to the following link:
https://t.co/K7TN1KDu7a
#CVE-2024-53353 #bugbounty#pentest
A few months ago, we successfully utilized a Blind Cross-Site Scripting (XSS) vulnerability that was impacting two major companies.
In this blog post, we explained in detail on how we were able to achieve this.
#bugbounty#pentesting
https://t.co/1lcXwR83E3
In this blog post published by @preterallc, I share a review of the Burp Suite Certified Practitioner exam that I recently passed.
#bugbounty#burpsuitecertified
https://t.co/ir5R3qC7iI
I'm thrilled to announce that I've recently become a Burp Suite Certified Practitioner!
I highly recommend PortSwigger Academy's labs to anyone looking to improve their skills in this area.
#burpsuitecertified
Tip: Don't waste your time hacking on bb programs where the researcher's work is not valued. I reported these vulnerabilities 2 months ago, when the bounty table had a greater a reward; the client updated the bounty table every week and paid me with the current version.
In this blog post, we explained on how we were able to remotely exploit a misconfigured and vulnerable biometric device, in order to bypass physical security measures.
Read how recently our team managed to compromise a #biometric device by chaining a couple of #vulnerabilities, from default #credentials to abusing a vulnerable web service used by the biometric device.
@arbennsh details all this into a blog post:
https://t.co/HLFw04su7w
In this blog post I will explain how I turned a Self-XSS (cross-site scripting) vulnerability into a Stored-XSS by chaining it with an IDOR (insecure direct object reference) vulnerability.
https://t.co/FDNYNkpvbO
Our hearts go out to the victims of the devastating earthquakes in Türkiye and Syria earlier this week. HackerOne’s #hackforgood donation program will now support the @ifrc and their humanitarian efforts in the region. For more information, visit https://t.co/VnFN8eld4g
Kinda crazy to think that 2 years ago we were a startup, and today we're enabling ASM for all Google Cloud customers. Intrigue became a good story to tell.
https://t.co/6drl4swOCc
@_0x999 Sure, I always leave it running on the background. Make sure to check Logger++ or the Logger tab of Burp to see if the requests are repeating through Femida extension, if you don't see output in the extension console.