Pro tip for hackers who accidentally get IP banned by Akamai or Cloudflare on their home IP:
Many ISPs will requisition a new public IP if they detect new network hardware installed in a house. If you get banned, unplug your cable or DSL modem.
Then go into your router settings and change the MAC address of your router. Most routers allow you to either change or clone to a different MAC address.
Then plug in your cable modem and enjoy your new IP!
Universal MXSS. Works in all browsers and is likely to bypass lots of filters because title is both an SVG and HTML tag. Briefly checked DOM Purify and it looked okay.
🧵 1/9
I'm often asked about my initial steps in game hacking engagements, whether for penetration testing or bug bounty hunting. My answer surprises some: "Tutorial." That's right. Let's dive into why this is the go-to for me. #BugBounty#PenTesting#GameHacking#bugbountytips
🐞💰 100+ Reports, $150k+ Bounties: The Collaborative Bug Bounty Journey
🚀 Used to believe solo was the way, but that all changed after attending @Hacker0x01's live hacking event in London. 💡Collaboration is KEY in bug bounties! Since then, I've connected with amazing folks, partnering up and making over $150k in the last 3 months with 100+ submissions to multiple programs. Big shoutout to my collab partners: @monkehack, @H4cktus, @bendtheory, @Shlibness, @soiaxx, and many more. 💪#BugBounty #PowerOfCollaboration #HackerOne, #Bugcrowd, #bugbountytips, @securitytips
If you ever find yourself stuck, don't hesitate to reach out. You'd be amazed at the talented people around you ready to help! 💼💡
A new day, A new blog!
Note: This SSO login option was there for around a few months and I never bothered to test for such a bug thinking it would be duplicate or 90% wouldn't work
https://t.co/HPQMPfWUCZ
#bugbountytips#bugbounty
Java/Spring application property injection to leak sensitive information. I've seen code where something like this was possible, but there was no access to sensitive information.
/home?appid=secretkey
⬇️
appid = env.getProperty("demoapp.config."+appid);
Do you have any theoretical bugs that you wish you could find in the wild? I have a few.
• Request CRLF injection in an SSRF to inject request headers.
• Sitewide DoS via WAF by sending malicious payloads from an SSRF to a firewall.
• SQLi via an Irish name like “O’Brien” 😆
@monkehack the guys at bleeping computer paypal'd like 50 bucks for an XSS I sent via twitter DM and then a $30 bonus for finding a bypass to their first fix... so technically think my lowest was $30 lol
Interruption aside... 30 days of bug bounty is over!
📨 Reports: 30
♊️ Duplicates: 3
ℹ️ Informatives: 3
✅ Validated: 24
⚠️ 1 L / 22 M / 3 H / 4 C
⌛️Unpaid so far: 3
💰 Total Bounties: $4,518
Thanks again to @_jayesh25 and @bendtheory! Great collab :)
I'm releasing a subdomain permutation tool, Typewriter ⌨️.
https://t.co/Mu8FWzkn6K
This is my first project in Rust (with the aid of ChatGPT, of course). It was a great experience!
Typewriter is effectively a Rust-based partial rewrite of Gotator. Enjoy!🇮🇪
Giveaway! 🎉
I'm going to buy someone a new MacBook Pro M2 13".
To enter, retweet this tweet, then follow: @hakluke, @hacker_content & @haksecio.
If you're a cybersecurity org looking for high quality content and social media management, check out https://t.co/FfJsZ2HZYU 👇
@shaunau <a href=“javascript:fun(‘reflection’)”></a>
not sure what the actual term is but other people call it that ¯\_(ツ)_/¯
https://t.co/x36cLW0RCw
I'm probably not the first to suggest this, but it feels like every bounty program wants hackers to self-identify with a different custom HTTP header. Seems like a great opportunity to standardise?
@Hacker0x01@Bugcrowd@intigriti