On SSRF (Server-Side Request Forgery) or Simple Stuff Rodolfo Found (Part I) by Rodolfo Assis https://t.co/meyzIUo99q #bugbounty#bugbountytips#bugbountytip
Exposing a Critical PII Leak on Durex India: How a Simple Misconfiguration Put Customer Privacy at Risk https://t.co/xt5817748M #bugbounty#bugbountytips#bugbountytip
Based on platform fees. I think the better approach will be to submit only reports when the user is fully Kyc-verified. Then, he can submit a report. since a user on the platform is KYC verified. He cannot easily make a fake identity. This will be a helpful newcomer.(1/n)
I Found My First Bug in 3 Hours, Then Nothing for 2 Weeks: Here’s What I Changed by Userwithheart https://t.co/NGyjgTXl80 #bugbounty#bugbountytips#bugbountytip
Business Logic Vulnerabilities: From Price Tampering to Expert-Level Parser Attacks by Nilanjan https://t.co/shwRWpM09e #bugbounty#bugbountytips#bugbountytip
Rejected but Rewarded: What a GraphQL Misconfiguration Taught Me About Bug Bounty Triage by Aaryan https://t.co/tEG9ztSXpB #bugbounty#bugbountytips#bugbountytip
Deleting Any User's Account From the Platform via Exposed Admin "Manage User" by xploiterr https://t.co/lekf7LHQFW #bugbounty#bugbountytips#bugbountytip