🚨 I convinced my team to do one last giveaway!
Options: https://t.co/60rsOCKTnO
🏆 Full Access: $199
💻 Lifetime Course: $39 (includes updates)
🎯 1-Month trial (no updates): $19
TWO WINNERS (1 each):
- Full cert bundle
- Lifetime access
Enter: ↪️ RT + Reply with 🎯
🚀Bug Bounty Tips: Act quickly to report issues related to CVE-2020-27838, as many vulnerable instances are still out there. I've identified over 100+ instances vulnerable to CVE-2020-27838 so far.
A flaw was found in Keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information about PUBLIC clients (like client secret) without authentication.
Below is the PoC:
https://yourtarget[.]com/auth/realms/master/clients-registrations/default/security-admin-console
Scan your targets using the following command and ethically report any quick wins:
nuclei -l targets.txt -t CVE-2020-27838.yaml
Here's the link to the template - https://t.co/4jnMnBZ61g
Enjoy! #CybersecurityTips #BugBountyTips #SecurityTips #HackerOne #BugCrowd #Bounty #Tips
An automation tool for enumerating subdomains, filtering out XSS, SQLI, Open Redirect, LFI, SSRF, and RCE parameters, and scanning for vulnerabilities.
https://t.co/N5ahXgLwl2
THREAD
How did I find 2 DOM XSS by hacking Swagger-UI?
1-Do a subdomain enum to find subs that use Swagger Ui
2-Get the live subs
3-Run Nuclei in all the live subs using the (-tags swagger)
4-Find Swagger Ui endpoints
#BugBounty#bugbountytip#bugbountytips#Cybersecurity
Thanks to Allah always and forever ♥️
First Triage in 2024, HTML Injection on Login Page
#Tips :-
1- site:*[.]redacted[.]com login.php
2- arjun -u .../login.php -> parameters with body length reflection (username)
3- Test for :- SQLi, LFI, XSS, HTML inj,..etc
#bugbountytips
- Simple tip for port scan
1) after enumerat your subdomains save in subs.txt
2) run this command
"cat subs.txt | dnsx -a -ro | naabu -silent -top-ports 1000 -exclude-ports 80,443,21,22,25 -o ports.txt"
#bugbountytips#bugbounty#infosec#cybersec
شكرًا لعبدالرحمن ذكي، لخص فيديو الرود ماب ف تكست ❤️
للي مش حيقدر يتفرج عالفيديو او معندهوش وقت، دقيقه اقرا الاتي:
———————————
1. html | https://t.co/M2oo6LDS7k
2. css ازاي تعمل تزيين بس كدا وخلاص | https://t.co/M2oo6LDS7k
3. js | https://t.co/M2oo6LDS7k
4. php | https://t.co/M2oo6LDS7k
5. mysql | https://t.co/M2oo6LDS7k
6. scripting => bash & python
مش لازم تبقى تنين في js, php, bash, python بس لازم تفهمهم وتعرف لما تشوف كود تفهمه وتعدل عليه
7. network basics
8. network pentest (eg. nessus, metasploit)
9. linux
10 كورس إبراهيم حجازي:
https://t.co/e0iSb0rqd6
11. كورسين يوديمي:
Ethical hacking and penetration testing and bugbounty hunting V1 (rohit):
https://t.co/qaxn9aENrW
Ethical hacking and penetration testing and bugbounty hunting V2 (rohit):
https://t.co/Oa5qrtFExS
- Advanced
1. NakerahNetwork OSCP:
https://t.co/LyTolzBc0b
2. eJPT by NetRidersAcademy (Ahmed Sultan):
https://t.co/4wvm2DL05p
لحد هنا هتكون وصلت لحصيلة معرفية كويسة.. تقدر تبدأ تهانت بقى
التطبيق هو اللي هيعلمك، مش مجرد النظري
تطبيقات عملي للتدريب
- PortSwigger labs (كل فترة خدلك توبيك حله، ومعارف معاه، متشوفش الإجابة على طول)
- https://t.co/YengwXzGad ( كنز.. 30 دولار ل 3 شهور بالأكونت الجامعي)
- Hack The Box (نقطة متقدمة شوية عن مجرد البج هانتنج)
- https://t.co/CuGkFRdS9o (موقع لل source code review مهم فتابعه)
Books:
1- Real-World BugBounty
2- The web application hacker's handbook
3- BugBounty Bootcamp
4- Hacking APIs
5- Black Hat GraphQL
حاليا بقيت تقدر تجيب Bounties بالفعل -إن شاء الله-
- دخل نفسك في الكوميونتي بتاع السكيورتي لذيذ
- تابع منشئي محتوى في السيكيورتي ( مثال nahamsec, bugbounty report explain, john hammond, cyberBugs... باقي أمثلة اتذكرت في الفيديو)
- تابع هاشتاج #bugbountytips واقرأ رايت ابس من Medium ب 1 $ في الشهر لرايت ابس لانهائية.. لكن احذر من الهاشتاج والرايت ابس عشان ساعات بتبقى حاجات Fake، هتاخد بالك منها أكتر مع الخبرة
- اعرف أكتر عن التكنولوجيز زي wordpress ومثال تاني مسمعتوش
- اتفرج على سيشنز بلاك هات اللي فاتت (مش بتاع السعودية بس)
- في البنتست هتقابل حاجات مش هتقابلها في البج باونتي.. فممكن تثقف نفسك في حاجات زي:
point of sale pentesting
large language machine pentesting
drone pentesting
active directory pentesting (مهم جدا)
configuration
hsm reviews
voip pentesting
segment pentesting
عدد ثغرات البج هانت اللي هتطلعها ملهاش علاقة بكونك كويس أو لأ في البنتست.. كتير شاطرين في البنتست بس مش بيهانتوا أصلا
الناس اللي بتشوفها مشيرة عدد الثغرات والجمدان دا يا هو برنامج لسة جديدة يا برنامج برايفت، أنت لسة وقتك مجاش بس.. وكلها أرزاق.. ركز مع نفسك وبس
I'm thrilled to introduce Recon88r, a Python script designed to streamline and automate the reconnaissance process
# Features:
Subdomain Enumeration
Live Results in Discord
Perform XSS scans
JS Exposures
Port scanning
Full nuclei scanning
Panels
#bugbounty
https://t.co/QERKUMSukb
"Don't ignore 403 subdomains"
Try to bypass or fuzz more.
Also, always check Symfony targets for these directories: /_profiler.
You might find phpinfo containing Symfony secrets, which can lead to RCE.
Great tip by @GodfatherOrwa! ❤️❤️
#BugBounty#SecurityTips
Wanna know How I prevented a Mass Data Breach?
Go Read: https://t.co/QE6bqK1VKo
Wanna know How a Bank offer led to PII Leak?
Go Read: https://t.co/LYJnGtDEXl
More writeups coming soon 🖤