Want to make bug hunting your career, but hitting some blocks and unsure what to do?
Take some tips and tricks from @ninad_mathpati in todays researcher spotlight! #ItTakesACrowd#BugBountyTips 💻 https://t.co/2Ny5ZVuWts
Recently I have found an RCE via file upload thorough path traversal in tomcat server. Found that tomcat automatically deploys war when uploaded in webapps folder.
https://t.co/RiMIwEpIHd
Gear up for the most awaited course API Penetration Testing live on HackersEra app. Begin the new year by adding a new skill set.
If you are already subscribed Hunter 2.0 course you will get an awesome offer, for discount email - [email protected]
Download HackersEra APP
I've just added an API routes wordlist containing 953011 possible API paths from the HTTPArchive dataset. Download it at https://t.co/Y04dyFY5q1 - all paths which start with "/api/", "/v1/", "/v2", or "/rest/". Good luck hacking! Thanks for requesting this, hope it helps.
Instead of writing continous blogs, thought of writing down my points and merging all the pentesting tips by awesome community here, still in progress not completed, will be updating it regularly. Hope you like it.
Maintainers me and @chaskar_shubham
https://t.co/YDkZLO2YFd
Learn how I've streamlined my bug bounty reporting in this video, using a recent release from my toolkit, BBR. Video: https://t.co/u6t0wGU52d Tool: https://t.co/dYWNoJ6IEV #bugbountytips
Sat down with @iamnoooob and worked on the recent Mobileiron MDM RCE by @orange_8361 and what a great find, Here's an RCE PoC using JNDI Injection via local classloading reference triggered using Hessian deserialization as stated in the blog.
https://t.co/dRNP5HW1L4
Incredible mindmap about hacking iOS applications by @hd_421
Pay attention, we have prepared two versions:
1. Full Security Assessments
2. Shorter BugBounty version
XMind source:
https://t.co/52We9OSiFI
#CyberSecurity#BugBountyTip#BugBounty#iOS
Simple but impactful tip for content discovery. Always use the subdomain as a path. Often it is the root of the application #bugbountytips#bugbountytip :
https://t.co/qNVu3F3T3T
try:
https://t.co/Bo3FeyarqM
and then do content discovery
https://t.co/w3VvpdcBe4