Bug bounty can be a cruel mistress sometimes.
Dupes, downgrades, mass closes and misunderstandings get us all down.
Solid tips were dropped on the pod last week to help in these times.
Here are 14 of them.
🔔 New topic alert: Web LLM attacks 🔔
Stay ahead in application security - dive into the world of LLMs to discover their weaknesses and understand how to exploit them.
Read our latest learning materials and try your hand at the new interactive labs.
https://t.co/Trvc0x2Wj0
Interested in #appsec and/or #graphql and contributing to an #opensource project? We're announcing a call for contributors for #inql! InQL is our #BurpSuite extension for GraphQL security testing - check it out today!
#doyensec
https://t.co/N7rfebmFB2
Great news! Our Proxy Enriched Sequence Diagrams (PSED) Exporter tool is fully integrated in #Burpsuite & in the BApp Store. You'll love how it creates professional diagrams & helps communicate complicated traffic flows. Install today!
#doyensec#appsec
https://t.co/WosH6VrGuJ
= Infosec super-thread =
A big part of my presos is tools/resources I like for offensive security & bug hunting.
Here's a thread of "PRINT" resources cited in the Bug Hunter's Methodology Application Analysis v1
https://t.co/Qt6H4VOSd7
a 🧵
#bugbountytips#Pentesting
1/x
You can now trigger file-upload XSS with no user-interaction using a technique spotted by @kkotowicz. We've just added it to our XSS cheat sheet:
https://t.co/AxgyDnZHLK
We've launched the long-awaited @WebSecAcademy HTTP/2 topic! Learn about and practice HTTP/2 request smuggling, request tunnelling, and response queue poisoning! https://t.co/ggrpBCHKJv
H2C Smuggling is a seriously cool HTTP/2 attack technique. It won't directly feature in my upcoming presentation, but you should still check it out:
https://t.co/b0LjuF6ljp
https://t.co/g8yyIpWIGi