⚠️⚠️ NGINX 0-Day (nginx-poolslip): RCE reported on NGINX 1.31.0; no upstream patch yet
🔗FOFA Link: https://t.co/baLc49KQmv
🎯493.1M+ Results are found on https://t.co/HSOBZfCA2r in the past year.
FOFA Query: app="NGINX"
🔖Refer: https://t.co/MjnLU0NWP6
#OSINT#FOFA #CyberSecurity #Vulnerability
I Found IDOR in a chat AI system:
Normal: `/chats/7b9fa258-b4d8-40e4-8560-9f7d4b82ee46/messages` → 403 Forbidden
Change one letter to UPPERCASE: `/chats/7B9fa258-b4d8-40e4-8560-9f7d4b82ee46/messages` → 200 OK + full chat history of another user!
#bugbountytips#BugBounty
Find bug bounty programs that running on @zerocopter via waybackurls and google dorks:-
waybackurls https://t.co/Ygyq1PwXea |grep /cvd/ |sort
waybackurls https://t.co/Ygyq1PwXea |grep /rd/ |sort
Google dorks:-
intext:"https://t.co/Ygyq1PwXea"
intext:"https://t.co/RJXdSEUnym"
Working with my brothers @0xmagdy & @h_hussein11, we turned a Stored XSS into a full Account Takeover by bypassing a WAF.
Tip: window.location.href can bypass some WAFs 😉
Thanks @intigriti for the platform.
story :https://t.co/1AePVR0VUd
#BugBounty#bugbountytips
Tip:
In organizations, always test by sending requests to access sensitive data from all roles. Check if roles without permissions can still retrieve the data—you might just find a hidden goldmine of vulnerabilities!
#BugBounty#CyberSecurity#EthicalHacking#PrivilegeEscalation
The Slides of (The Art Of Authentication Bypass) on
@bsidesahmedabad
You will find a lot of useful tips and tricks that will help you bypass some admin panels😉
https://t.co/ORwf8nNNQ7
Thanks to @bsidesahmedabad for giving this topic chance
#bugbounty#bugbountytips#infosec
الحلقة الرابعه مع Souhaib Naceri @h4x0r_dz واتكلمنا فيها عن حاجات كتير وتجربتة في الوصول لـ LHE بتاع هاكرون وفيه نصايح جداً مهمة لتطوير مستواك، وحاجات تانية كتير تقدر تشوفها من هنا :
https://t.co/cqJwGZLvY8
#BugBounty