Let's start looking for this vulnerability. To do so, you can:
Google dork 🔎
1. Go to https://t.co/NaxXzvUnVo
2. Search for - intitle:"index of" "parameters.yml.test"
OR "parameters.yml.dist" - More information at
https://t.co/heXxFYxo9U
Shodan dork 🔍
1. Go to https://t.co/y7uIln2ekj
2. Search for - html:"parameters.yml"
3/5
I haven't played CTF for a while cause I am busy with other stuff like new job and moving to a new place(I am in Tokyo now!).
But I still see some interesting challenges on twitter from time to time and really want to take a note, so here is it
https://t.co/X4NegjtlBb
@HusseiN98D Most of the time while testing Apis I , after looking your tweet can confirmt that uuid/../uuid or id/../id shows same respone but what would be exploitation of this specific scenario ?
I did found PII critical by myid/../victimId but no idea about traversing that you mentioned
Google Dorks - File Storage:
site:https://t.co/57Cb6NtQy3 "example[.]com"
site:https://t.co/7duufTkL52 "example[.]com"
site:https://t.co/lkAF61gwEb inurl:"/d/" "example[.]com"
Find sensitive data and company accounts
#recon#bugbountytips#infosec#seo