Not reinventing the wheel — but something more practical than generic lists.
focused on:-
• OAuth
• MFA/OTP bypass
• ATO chains
• IDOR
• session/auth flaws
• real implementation mistakes
https://t.co/yhLICB9G0e
#BugBounty#AppSec#hacking#CyberSecurity#KnowledgeIsFree
Not reinventing the wheel — but something more practical than generic lists.
focused on:-
• OAuth
• MFA/OTP bypass
• ATO chains
• IDOR
• session/auth flaws
• real implementation mistakes
https://t.co/yhLICB9G0e
#BugBounty#AppSec#hacking#CyberSecurity#KnowledgeIsFree
@krishnsec@yeswehack Who is supposed to act and defend hacker's rights here?
Or is it a one way entitlement for companies only?
One might think to dump all DB and then report sqli lol
@h4x0r_dz Starting to realize that it's happening with other platforms as well. I dont know anymore if its cuz of lack of documentation passed to the bb platform or not.
Just reported OAuth flaw high vuln on bugcrowd, and got NA, so I contacted company's sec team.