When HTTP/1.1 Must Die lands at DEFCON we’ll publish a @WebSecAcademy lab with a new class of desync attack. One week later, I’ll livestream the solution on air with @offby1security! You’re invited :)
https://t.co/BPt0h0YiN2
Alhamdulillah, focus on one program and get another vulnerability again :
1 high
1 medium
1 low
bounty : $$$$
Tips : check every endpoint on admin and try in low level user
⏰ Time for a #GIVEAWAY!
💬 We want to hear from you.
How to win swag?
📣 Retweet
📣 Like
📣 Complete the survey
📣 Drop an emoji once completed
Click here to get started: ⤵
https://t.co/2d0aKaCH6z
Alhamdulillah, finally I found a security vulnerability in Apple, one of my goal is finally achieved, seeing this push me to try more harder and keep learning!
#bugbounty
Thread about hunting on the main application 🧵
1. Check the login process
- Do they allow signup with email or Google etc
- Do they allow you to signup with the @company email
- what is the content-type of the signup/login page
- when you enter valid cred, on which page you