Everyone uses httpx to see what's live. Few use the signal it already gives you.
-title -tech-detect -status-code -cdn in one pass tells you what it is, what's behind a CDN (Content Delivery Network), and what's worth a closer look.
Filter, don't scroll.
#BugBountyTips #ReconTips #ProjectDiscovery
Most people run subfinder and stop. The passive default misses a lot.
subfinder -all hits every source, including the slower ones others skip.
Then -recursive to enumerate subdomains of subdomains. That layer is where forgotten assets hide.
#BugBounty#Recon#Subfinder
For first time i found a SQL Injection On **sitemap.xml** endpoint ๐๐
#bugbountytips#bugbountytip
target[.]com/sitemap.xml?offset=1;SELECT IF((8303>8302),SLEEP(9),2356)#
sleep payload
[1;SELECT IF((8303>8302),SLEEP(9),2356)#] = 9s
Happy Hunting
#BugBounty
We're launching the OpenAI Bug Bounty Program โ earn cash awards for finding & responsibly reporting security vulnerabilities. https://t.co/p1I3ONzFJK
I have created a simple yet useful tool to detect misconfigured S3 buckets. With this tool, one can easily check a list of subdomains for misconfigured S3 buckets using the AWS CLI.
Check it out : https://t.co/MUoGCcrh2i
And let me know your feedback.
#cybersecurity#bugbounty
Web Cache Poisoning๐ฑ๐ต๐ฅ
#bugbounty#infosec
The objective of web cache poisoning is to send a request that causes a harmful response that gets saved in the cache and served to other users.
Where to find ๐งต(1/n) :๐
We are so excited to be holding our first UX study! Help us shape the future of cybersecurity and get some awesome swag while doing it!
Are you interested, or do you know people who may be? here is the survey link to share/follow โโ
https://t.co/eJlJOIMZ68
@aadesh_namdevv Information Security: Secure the Data/Information from Different Attack Vectors
Cyber Security: Secure the Cyber World From different Types of Attacks
Any other Opinion ? Please free to Add.