IRIS (Intent Runtime Inspection System) is my attempt at building a Burp Suite for Android intents :) . Give it a spin and let me know what breaks, what’s missing, and what you’d like to see next: https://t.co/u5sUlvHBpB
Demo here: https://t.co/IdAZDIq3qU
🚨 180+ vulnerabilities found.
🌍 763 hackers. 38 countries.
🏆 4 elite teams.
Adobe brought serious energy to the 2024 #AmbassadorWorldCup, working side-by-side with ethical hackers to secure products like Firefly & Lightroom.
We were proud to host → https://t.co/ImyONO7B6j
#HackForGood #TogetherWeHitHarder
Ambassador World Cup Final Results 🏆
🥇 Spain — back‑to‑back #AWC champions! CONGRATULATIONS!
🥈 Egypt — an impressive run to 2nd place.
🥉 Greece — securing 3rd place after a hard‑fought battle.
🇳🇱 Netherlands — props for keeping the pressure on, right to the final minute.
Huge applause to every security researcher who competed, collaborated, and proved the power of crowdsourced security on the global stage. 🌏
Learn more about the tournament → https://t.co/xa2xtC4Tj0
#AmbassadorWorldCup #HackerOne #SecurityResearchers #BugBounty #Cybersecurity #AWC2024 #teamspain #teamegypt #teamgreece #teamnetherlands
Congrats Team Greece for a great battle until the last minute. Thanks @Troll_13 for all the hard work as an ambassador and leading your team to the podium. Appreciate all the hard work, well deserved 3rd place and congrats to all of you!
The finals for the #AmbassadorWorldCup in Dubai are over.
We managed to get 3rd spot in a tough and competitive round against team Nederlands 🇳🇱
Thanks to @Hacker0x01 for organizing this.
It was an honor to lead team 🇬🇷
Well done to all teams and hopefully see you all next year
Give it up for the four teams headed to the next round of the #AmbassadorWorldCup! 🏆 👏
The teams from Greece 🇬🇷, Egypt 🇪🇬, Spain 🇪🇸 and The Netherlands 🇳🇱 dominated the Elite 8 round and will move on to go head-to-head as the final four.
Who do you think will make it to the #1 spot and take home the gold?🥇
Graphql can have serious CSRF vulnerabilities (that pay well) under the following conditions (that aren't uncommon):
1. GET-based querying is enabled
2. There's at least 1 sensitive mutation
3. There's no special auth header or CSRF token beyond the cookies of the app
If you discover a Slim App, you should definitely try [email protected]&Password=test123. You can disclose a lot of information in Debug Error Mode !
Just scored a reward @intigriti, check my profile: https://t.co/gWptipqmz8 #HackWithIntigriti
Hacking tip of today:
‘“`><img src=x>gud${{85*64}}
XSS in different contexts
SQLi
SSTI
CSTI
All while being minimal as to not trigger filters and bypass the most common things known like {{7*7}} which is taught everywhere and thus a little more likely to trigger a filter
Need to bypass the JWT signature? Kid param injection + directory traversal = signature bypass
Vulnerable apps using 'kid' for key retrieval might allow attackers to force a predictable key file (e.g. static file or /dev/null)🔓 Crafted malicious tokens signed w/ known key
when you are looking for bugs like SSRF & Open Redirect.
and there is a blacklisted character.
try to bypassed using other Unicode characters.
I found Open Redirect Bypass Using (。) Chinese dot "%E3%80%82".
poc: redirect_to=////evil%E3%80%82com
credit:@h4x0r_dz#bugbountytip
Time-based SQLi with two payloads injected in the following headers: ⚔️
1. User-Agent: "XOR(if(now()=sysdate(),sleep(5),0))XOR"
2. X-Forwarded-For: 0'XOR(if(now()=sysdate(),sleep(10),0))XOR'Z Both
payloads were executed and the server responded after 15s. Very interesting.
For first time i found a SQL Injection On **sitemap.xml** endpoint 😎😎
#bugbountytips#bugbountytip
target[.]com/sitemap.xml?offset=1;SELECT IF((8303>8302),SLEEP(9),2356)#
sleep payload
[1;SELECT IF((8303>8302),SLEEP(9),2356)#] = 9s
Happy Hunting
#BugBounty
Don't give up too fast if all your standard XXE payloads don't work 😭@nullenc0de has you covered with another way to extract juicy information!
😎#bugbountytips
org:YOUR_TARGET http.favicon.hash:116323821
Use this query on Shodan to find Spring Boot servers. Then check for exposed actuators. If /env is available you can probably achieve RCE. If /heapdump is accessible you may find private keys and tokens.
credit:@sw33tLie#bugbountytips
LFI & Path Traversal & SSRF & Open Redirect:
Gi to your Burp Search > Regex
\?.*=(\/\/?\w+|\w+\/|\w+(%3A|:)(\/|%2F)|%2F|[\.\w]+\.\w{2,4}[^\w])
#infosec#cybersec#bugbountytips