Hunting for secrets? Try scanning live subs for config.js it often contains API keys,tokens, and other sensitive data
httpx -l live-subs.txt -path "config.js" -mc 200 -sc -cl -title
- This screenshot is from my current scanning of 3,304 live subdomains
#bugbountytips#Recon
If your target uses Rails, look for Action View CVE-2019-5418 - File Content Disclosure vuln. Although this is an old bug, it can still be found.
Intercept the request in Burp and replace the Accept header with: `Accept: ../../../../../../../../../../etc/passwd{{` #bugbountytips
An automated recon tool for asset discovery and vulnerability scanning using open-source tools. Supports XSS, SQLi, LFI, RCE, IIS, Open Redirect, Swagger UI, .git exposures and more.
https://t.co/NxJqeMV52L
#bugbounty#bugbountytips#bugbountytip
Hey everyone! sorry for the late. The new video is now out.. must-watch for anyone working on mastering recon techniques this will help u. This is just the first part of the checklist. More powerful techniques will be added and published soon on medium..
https://t.co/ny7cSMfS96