Built another milestone today:
I just completed TryHackMe’s Web Application Pentesting Path and earned the certificate.
Still learning, still improving, still chasing real skill in web security and bug bounty🔥
#TryHackMe#WebPentesting#CyberSecurity
Day 10 Bug Bounty💻
Tested user account settings page and validated some potential xss bug
also read alot of writeups
Total reports= 0
Hunted= 5hrs
Earning: 0$
@WebSecAcademy true to some extent... there's slight nuance on it, nowadays those "classic" ever lasting vulnerabilities are more obfuscated and harder to find
Day 9 Bug Bounty💻
Tested profile settings and oauth signup implementation for bugs, but still didn't found any impactful vulnerability
wish me luck🤞
Total reports= 0
Hunted= 6hrs
Earning: 0$
Day 7-8 Bug Bounty💻
Hunted for a potential reflected xss on one of the subdomains, but no succcess till now
Mapped the entire oauth workflow of target for finding vulnerabilities in it
Lets see what happens in future😗
Total reports= 0
Hunted= 5hrs
Earning: 0$
Day 5-6 Bug Bounty
Hunted on random urls from katana and waybackurls
Found some interesting subdomains, but got hit by a 403😑
Currently working on bypassing that😗
Wish me luck🤞
Total reports= 0
Hunted= 5hrs
Earning: 0$