Hello everyone ♥
a little bit write-up of #bugbountytip#bugbountytips I am going to write here .....
Title:
getting unauthorized access on 3rd party's/workspaces & and building your checklist for quickly locating bugs there via massive recon
we know that its helpful to look for google
groups/docs/etc..
Slack as well just like when the amazing @h4x0r_dz shared days ago ..
Use google dork "site:https://t.co/ravW2tHHcP"
so I was not in a good mode the last months to doing Google Dorks, so what I did was build a checklist ready for me & very huge one
for EX:
https://t.co/wPxAHXvC18
https://t.co/hs3VHvhT92
https://t.co/ravW2tHHcP
and here is just an example you can add more similar workspaces for your checklist
thin I extracted all internet endpoints and as example here join[.]slack[.]com
https://t.co/OlHQSEQ6Qz
https://t.co/e8jB8H6nMS
https://t.co/w5h4VkESyQ
you can use the ready tools to do it such as waymore
important note: you have to keep your checklist updated every week
and from here I just keep looking for the company name or domain name to see if there's anything connected
and mostly the company name or domain name in the URL it self EX: tesla
https://t.co/QesyI4MHu2
Ex For Bugs found:
1 unauthorized access to the workspaces
(PII | Information disclose)
2 account takeover as Ex: valid signup employee link
3 account takeover as Ex: valid reset password employee link
now about Slack, as an example if you found an invitation link for tesla
Tesla https://t.co/QesyI4MHu2 and that link was not valid, don't stop here
it will redirect for Ex:
tesla-internal[.]slack[.]com
here back and start looking manually for endpoints of this subdomain as well EX:
https://t.co/w2dhvfdBhL
now there are a lot of 3rd party's/workspaces I just shared here
slack & Google Docs/groups
What I wrote is a bit long and annoying to some, so I apologize. I hope, as usual, that this will be useful to all who follow me here.
#Bugounty
don't forget to retweet if you like it ♥♥♥
Big #Bugbountytip / #bugbountytips
Google Services Hunting
Google services are amazing, and for bug hunters, it's amazing as well. In some cases, you can get some P1-P2-P3 from these services, such as
Workspaces / Sheets / Groups / Drives / Etc...
In groups: you can access emails / internal data/ credentials
In Sheets, you can access PIIs / Edit access
In Drive: you can access backups/ PII / Etc...
still hard to find and
It was an issue how to make good and at the same time fresh dorks for bug bounty programs
Then I found out that a lot of links have the same path, and it was like this
All Google resources I've found
https://t.co/2SixYDAKvE
https://t.co/tbE8WaX9CX
https://t.co/5D7Clds9cH
https://t.co/OfodYVKOk0
https://t.co/ZyA0JFkax4
https://t.co/mhIbyMF03b
https://t.co/QwByRWofh8
https://t.co/vAwAEX8KxI
https://t.co/4y1UMeZdq7
https://t.co/u7mOVPnus3
https://t.co/V9ALsFoqP9
https://t.co/2eLIaEPCGm
https://t.co/VxllqvwT6n
https://t.co/c1vkp8YrBt
https://t.co/2EkMSEUpIt
UrlScan Dorking:
page.url:"https://t.co/qb3s3f8koJ*"
page.url:"https://t.co/BNLIA1rXht*"
You can replace * => the program domain
Google Dorking:
site:https://t.co/qb3s3f8koJ* "inurl:/a/"
Or for specific domain
site:https://t.co/qb3s3f8koJ* "inurl:/a/domain.com"
GitHub Dorking:
"https://t.co/qb3s3f8koJ"
Or for a specific domain
"https://t.co/FKHqr19e0o"
Shodan Dorking:
"https://t.co/3vQLeWEs54"
Web Archive
https://t.co/c8tGyvVlH7
Don't forget:
It's not just https://t.co/pbqxKC9P4s
still you have to look for docs/groups/mail/drive/spreadsheetsX
still working in Google Research and will add more and more soon ......
Happy Hunting♥
#bugbounty
@_jensec Exactly seems to me everyone is riding the wave of ai bounty hunting without being responsible about it's affects on the industry the fact that there are limitations to what It can do and serious drawbacks to both parties is often neglected! You can hunt with ai but be smart
@Rishurana2867 AI lowers the barrier, not the knowledge requirement.
It can find signals, but you still need to know what to ask, validate findings, understand impact, respect scope, and report responsibly.
“AI says critical” can get you rejected.
Zero-knowledge hunting is selling a dream.
🚨 CRITICAL: CVE-2026-15826 (CVSS 9.8) allows unauthenticated attackers to bypass authentication and take over WordPress administrator accounts.
The flaw affects User Profile Builder ≤ 3.16.4, putting 40,000+ sites at risk.
The issue is fixed in 3.16.5. Update immediately.
#WordPress #CVE #CyberSecurity #WebSecurity #Infosec
‼️ Microsoft's July patch for the RoguePlanet local privilege escalation Defender flaw (CVE-2026-50656) has been bypassed.
Nightmare Eclipse published exploit code called ShieldBreak on GitHub, hours after August Patch Tuesday. The researcher claims a 100% success rate on fully patched Windows 11 25H2 and Server 2025, where RoguePlanet's race condition was hit-or-miss.
The vulnerability makes it possible for any local user to get SYSTEM. No fix yet.
Instead of Subfinder, try Subfaster.
It’s faster than Subfinder and uses keyless sources like thc, submd, crt, shodanct, rapiddns, hackertarget, and sitedossier.
It also has an option to resolve subdomains and keep only the live ones, so you don’t need to run httpx separately just for resolving. ⚡
https://t.co/RO1QFcLD5L
We got new research from @cybershaykh!
A single unclaimed npm package name is all it takes for client-side RCE... Read more about it below! (=
https://t.co/boz5xNq9ry
I am #1 on many bug bounty programs in crypto.
Including Binance, Bybit, Upbit, Kucoin, OKX and more.
Occasionally we have had several clients who use a 3rd party app within their main tools.
We found several RCEs in something that is being used by several top crypto projects, including our clients.
I registered on @immunefi just for the sake of reporting that and because some people wanted me to join the club.
I am not gonna tell the details at the moment, but I honestly don't trust either immunefy or the program itself.
Found an IDOR + SSRF.
Validated both, wrote the reports, then checked the scope.
The wildcard was in scope.
The subdomain had a specific exclusion.
Pain.
Last three days I been cooking
It's a never ending game
Always more to learn to catch and hunt
One of my two submissions so far were a duplicate on a critical RCE XD the other one
.. let's say I'm hoping it's not a dupe
#bugbounty
Bugs are found by reading code, right?
Reading is just the part you notice.
Ask Mike Tyson how to get good at boxing and he says "hit the bag more". Right, and completely useless.
"Just read the code" is the same answer. Reading is only what your top level notices. Underneath you are:
- forming a hypothesis and reading to DISPROVE it
- looking for what's missing, not what's there
- comparing what the dev meant vs what he wrote
- tracking one variable across every function that touches it
- mirroring paired functions side by side
- testing the boundaries
- reversing flows
- and a lot more
Hey Hunters,
just released: Burp Unrestricted MCP
Free and open source, for hunters running AI agents against Burp on
long engagements.
A fork of @PortSwigger's Burp MCP Server that adds the 8 tools an agent
actually needs to work a target end to end.
https://t.co/4CbKF3rIJB
#Bugbounty
I love hacking IIS servers. It feels like you're hacking on easy mode. I've released the second video. Be sure to also follow @Assetnote for more content from the wider team.
Are you into web hacking?
If so, you must have technology-specific wordlists
If not, you're missing obvious vulnerabilities.
Don't believe me?
Let's look at an information disclosure in an ASP[.]NET Core site: