Local files for Linux :
/etc/passwd
/etc/shadow
/etc/shells
/etc/group
/etc/profile
/etc/hosts
/proc/self/environ
/proc/self/status
/proc/mounts
#bugbountytips#BugBounty
Chiasmodon:It's a handy tool for finding info about a website. You can search for emails, credentials, and more, even Google Play app IDs
https://t.co/9IqOOQPCE6
#BugBounty#bugbountytips
BurpGPT
Explore unique vulnerabilities with Burp Suite extension, integrating OpenAI's GPT for a better passive scan.
https://t.co/ashW0G9Rqk
#bugbountytips#bugbounty
1. Identify a URL param allowing a potential LFI
2. FUZZ the param value (GPT can help to create a custom list)
3. Find a new file/page via LFI
4. FUZZ looking for URL params reflected on this newly discovered file
(...) ⬇️
#bugbountytips#Hacking
'All-In-One Regex' by @h4x0r_dz for searching leaked keys and secrets is a must-have. Here is how I was able to find a P1 recently using BurpSuite, The leaked secrets allowed me to see some employee related juicy info. Link: https://t.co/U7At9SmlzT #BugBounty
Google Dork - Unlisted Bug Bounty Programs 🐛
"submit vulnerability report" | "powered by bugcrowd" | "powered by hackerone" reward -site:hackerone[.]com
Some programs don't want to be listed in the directory; you can only access them directly via their site.