It's hard to believe, but after a long time I got my FIRST BOUNTY... and yeah: it was a P1 Critical $3.000 !!!!
#bugbountytips don't try to automate everything, use Burp Suite and dedicate at least 1-2 weeks to understand the whole application and do manual hacking ;) #bugbounty
Yes! P3 Triaged on Bugcrowd! π―π€.
Another bug in mobile scope, I'm still waiting for the customer response in this new week! πͺπ.
π§ Tip: Always try bypass client-side restrictions/blocks via backend API through Caido/Burp proxy interceptions.
#bugbounty#bugbountytips#hacking
So, do you want to do Bug Bounty in Mobile Apps? π°π±
π€ Frida maybe a headache with actual modern RASP protections, so I published my personal method to Bypass SSL Pinning on Play Store Android Emulators WITHOUT Frida!π
#bugbountytips#bugbounty#hacking
https://t.co/K1oScHDD6j
Yes! P3 Triaged on Bugcrowd! π―π€.
Another bug in mobile scope, I'm still waiting for the customer response in this new week! πͺπ.
π§ Tip: Always try bypass client-side restrictions/blocks via backend API through Caido/Burp proxy interceptions.
#bugbounty#bugbountytips#hacking
I've been using Caido since (sadly) my Burp Pro license expired a week agoπ... and WOW! " I l o v e Caido β€οΈ. " Never have used it before and it's a really game changer π₯.
#bugbounty#bugbountytips@CaidoIO#appsec
@CyberRacheal if the OTP is never stored in the server, then just intercept the response and check it and also the client-side: is a mobile app? then debug with Frida and check logcat. is a web app? use devtools.
Exciting news: we have teamed up with @intigriti
Bug hunters can now earn a FREE 6-month Burp Suite Professional license by hitting 400 reputation points on Intigriti.
More power. Deeper testing. Bigger impact.
Happy hunting π
#BugBounty#Intigriti#BurpSuite
Is this for real? Yeah it is!! ππ₯
π DumpDork has a new version, v1.2.0 and this is huge!!
This release now supports GitHub Code Search using Dorks.
Hack using dumpdork from your TERMINAL without CAPTCHA limits right now!
β GitHub repo: https://t.co/zItp4tbpuK
@CyberRacheal That is the case when you're inside an internal network, not the common LAN network, and this could be part of the configuration of the Router or in the worst scenario, you are under almost total network control by someone else!!π π..