Exciting News: My Second Write-Up is Now Available!
https://t.co/boOuuOMs63
Dive into the details of the bounty that ranks as the 3rd highest I’ve received on @Bugcrowd
"A Journey of Limited Path Traversal To RCE With $40,000 Bounty!"
Collaborated with @GodfatherOrwa ,
This Write-Up is not just informative but also a fun read.
Enjoy reading and happy hunting!
#BugBounty #BugBountyTip #BugBountyTips #Bugcrowd #HackerOne #SOC #CyberSecurity #infosec
All my current bug bounty knowledge is gone.
Here's how I get it back and make $100k in the first year:
First, I've got to learn the basics. For this, I will make sure I understand at a high level how the components I'm working with function.
I'll need to understand...
I'm happy to say that the DOMLogger++ workshop created for @GrehackConf is now available 😁
I've written it in a way that it can serve as documentation. I hope it helps you understand how to use it properly!
Website: https://t.co/HG9oi1o4tG
GitHub: https://t.co/LQWeuLNEXt
This HTML parsing behavior is absolutely wtf...
It can be abused to completely bypass any server-side HTML sanitizer when a second user input is present earlier in the document within a script string...
So happy to had the chance to present for second time at #BlackHat USA!
I’m already receiving a lot of messages from people using these techniques to get some nice bounties!
If you want to learn more about cache exploitation, the research is available at https://t.co/A3DoIdBZ6N
I've made over 100k on SSRF vulnerabilities.
They aren't always as simple as pointing it at localhost or AWS Metadata service.
Here are some tricks I've picked up over the past 5 years of web app testing:
📖 Monke's Guide to Bug Bounty Methodology
An exhaustive article answering pretty much everything you ever wanted to know about methodology. Enjoy :)
#bugbounty
https://t.co/f3ylJkepcu
Stop🛑reporting XSS in boring traditional manner, and start escalating them to a high issue instead. How? It is possible to chain XSS via a Browser based Password Manager Account takeover issue.
I see a lot of times, I get duplicated to XSS being reported as a medium severity issues. But you can use this script and chain XSS to a high (Depending on the program owners if they are willing to accept it as a high.)
The proof of concept for password manager script works regardless if you have XSS on https://t.co/VsgjCqDLrm you can save the password in Browser Password Manager for *.acme.com and the exploit will steal the credentials for whatever subdomain the password is saved for via your XSS on https://t.co/VsgjCqDLrm
#bugbountytips #BugBounty #infosec