Just got another CRLF injection, and exploiting it to #XSS but Server is returning 302 status code with location param which is preventing my javascript to return XSS promot
Any tips to bypass this thing and get xss prompt?
#bugbountytips#cybersecuritytips
Just found my first SQL injection on a bug bounty platform. Tip: postgreSQL has a lot of tricks to escalate from SQLi to RCE. Don't stop at the SQLi itself. #bugbountytips#bugbounty#rce#sqli#postgresql#hacking#hacken
https://t.co/lvWcGSovWf
Just released @securinti "RTFR (Read The Bleeping RFC)" from #NahamConEU2022! These attack vectors are incredible creative and worth implementing them in your day to day testing!
https://t.co/RJAHzhBgtu
We let ChatGPT write today's #BugBytes tweet and this is what it wrote 👇
I'm sorry, but I am not able to write about anything related to Bug Bytes or chatGPT, as I am a large language model trained by OpenAI and do not have access to curren-
oh nvm lets bring the human back
1. remove disk from target laptop
2. virtualize system (VBoxManage convertfromraw)
3. abuse local admin (chntpw using alt booted system)
4. run mimikatz by reflective loading (bypass ESET :) )
5. extract machine cert / secrets
NEVER deploy company laptop without BitLocker.
[1️⃣] Spot The Vulnerability 📜
Hackers love spotting vulnerabilities! Spot the vulnerability in this code snippet and get your first flag!
🔗 https://t.co/pMan4O85Rb
Yay, I was awarded a $x,xxx bounty on @Hacker0x01!
I found Critical bug Time-based SQL injection on JSON parameter
Payload: (select*from(select(sleep(20)))a)
#TogetherWeHitHarder
⏰ DOJO Challenge - DOM XSS (Butters Adventure)
🎁 Top 3 reports win a swag pack!
🗓️ Submit your solution before 05/01/2023
Check out it out here 😼👇
https://t.co/0qaya5PJJT
#BugBounty#YesWeRHackers#YWHDOJO