Just released v21.1.0 of the Wappalyzer technology detection add-on. Update includes the latest patterns/icons from upstream and support for DOM patterns courtesy of @bettercalln1ck
Get it via zap marketplace.
#owasp#zaproxy#cybersec#appsec#redteam#purpleteam
Explore Scope Based Recon Methodology in a new blog post by Core pentester, @harshbothra_. Harsh will look at how to perform recon and examine what methods are best to use based on scope. Check it out: https://t.co/4DbxjwqFUm
If you are tired of googling for #BugBounty writeups, I made a little tool that lets you search writeups easily. You can also pull the search data in JSON format if you need it.
https://t.co/r7JhrBuHLr
#cybersecurity#bugbountytips#infosec#100DaysOfCode
#learn365 Day-30: Common Business Logic Issues (Wrap)
(Cont'd...)
9. Parameter Tampering
- Tamper Payment or Critical Fields to manipulate their values
- Add multiple fields or unexpected fields by abusing HTTP Parameter Pollution & Mass Assignment
#bugbountytips#appsec
(1/n)
I just published leaky-paths on Github, it's a collection of special paths linked to major web CVEs, known juicy APIs, known misconfigurations.. etc.
They could be used for web-content discovery as a way to find quick-wins.
Please feel free to contribute
https://t.co/6vhUjXMOfV
It generates an email address and then prints any OTPs or confirmation links sent to it.
Just enter 'ote' in your terminal and get your OTP.
Github: https://t.co/SmYvpfXI8I
b00t2root CTF ended! Hearty congratulations to team @ByteForc3, @Zh3r00 and @0x90r00t for bagging the top three positions! We would also like to thank our esteemed sponsors @offsectraining@vector35 for sponsoring the prizes. Adieu guys! See you all next year :)
15+ hrs into the CTF and we are seeing some intense competition here :P
If you havent registered yet shoot here: https://t.co/91rNoi2tIt
#boot2r00tctf2020
We are very happy to have @offsectraining as our esteemed sponsor!!
Registers yourselves at https://t.co/91rNoi2tIt Hope you are as excited as we are :)
@tryhackme My favorite thing about TryHackMe is the weekly release of new boxes and they give enough time to solve the boxes. After few days hints are released. It has helped me greatly to increase my skills.
go-stare: A fast & light web screenshot without headless browser but Chrome DevTools Protocol!
https://t.co/UXUTWu28OK
#infosec#bugbounty#golang#chromedp
Here's a solid bug bounty tip. If you are going to focus on one vulnerability class, make it logic bugs. Most of the P1 bugs I see pop up are logic errors that developers have made. They often have high impact and they can't be discovered through automation.
To find them ...
Burp Extensions that I use: (1/n)
1. Autorize - To Test BACs
2. Burp Bounty - Profile-based Scanner
3. Active Scan++ - Add more power to Burp's Active Scanner
4. AuthMatrix - Authorization/PrivEsc Checks
5. Broken Link Hijacking - For BLH
#bugbountytips#bugbounty