☝️did you know: if you have CRLF injection on a 302 redirect, you can still trigger XSS by providing an empty value for the "Location:" header #bugbountytip#hackerone
Burp Suite Secret Finder - Burp Suite Extension To Discover Apikeys/Tokens From HTTP Response⚡️
> https://t.co/z7qG9eZXTk
#bugbounty#cybersec#bugbountytips
👿👿After a long time, finally got a Pwn again! 💀💻
This time it’s a Windows WebApp RCE 🧠⚡
Feels great to get that exploit adrenaline back!
🚀 #BugBounty#RCE#HackerVibes#HackTrainingHackers TrainingHack Training
Use NextJS? Recon ✨
A quick way to find "all" paths for Next.js websites:
DevTools->Console
console.log(__BUILD_MANIFEST.sortedPages)
javascript:console.log(__BUILD_MANIFEST.sortedPages.join('\n'));
Cred = https://t.co/4hiJXDNlmU
#infosec#cybersec#bugbountytips
Welcome to XSS Under Siege — an advanced-level XSS challenge designed to push your skills to the limit.
📷Challange Link := > https://t.co/N1NqrhRvDq
@sudhanshur705@Assass1nmarcos
الحمد لله♥️
I got my first 2 bounty rewards from Standoff365 (1 public, 1 private).
Still got accepted reports pending, including a High severity in the platform itself! Great experience with their professional and respectful teams.
🔗 https://t.co/wm0n4fcAO6
#infosecurity