Looking for bugs is like looking for love. You don't know whether you'll find anything or not, but you believe in the process and keep looking.
Eventually, the universe is by your side as you find something real.
#bugbounty#philosophy#braindump
Today we are releasing our FREE educational course: "Intro to Exploit Dev"!
This course is perfect for those trying to start exploit dev and covers:
- Tooling
- Fuzzing
- Exploitation techniques
- And more!
You can take the course here: https://t.co/kejXkinsGR
Good resources on #BugBounty for you to bookmark!🌟
1. https://t.co/hdFRamEyc5
2. https://t.co/RiV3ukxQhS
3. https://t.co/6uxHvZ0BAK
4. https://t.co/7YoEUOQK4N
5. https://t.co/cSAii723GF
#dorking#vulnerability#bugbountytip
OSINT TIP #248🔐
Telerecon - a comprehensive OSINT reconnaissance framework for researching, investigating, and scraping Telegram.
🔗https://t.co/dxmVvEXYaf
#OSINT#recon#telegram
AI helps greatly translating JavaScript to "Human Readable Language", here's how I found a very straight forward DOM Based XSS in 2 minutes.
#BugBounty
Announcing ProtoBurp++ a #burpsuite extension to encode/decode & fuzz custom Protobuf messages! Fuzz using Repeater, Intruder & Active Scanner & proxy traffic from other tools (e.g., sqlmap). Check it out!
#doyensec#appsec#websecurity#bugbountytips
https://t.co/mjrnpdjC0N
About @Burp_Suite and your RAM...
Over time, Java deliberately uses all the RAM you feed it, in order to minimise CPU cycles spent freeing memory. To feed it less memory, you can use the -XX:MaxRAMPercentage argument. For other RAM tips see:
https://t.co/CorkyyFjQm
Just popped another crazy XSS. Check this one out 👀
So a CRLF was passed to me by a podcast listener. The CRLF was in the path, so it couldn't contain a /.
We could do response splitting, but couldnt change the content-type to text/html because we couldn't use a /.
So we...
1- create 2 accounts (A , B )
2- reset password for account A
3- follow the regular flow and study the link sent to your email
I noticed that it had mail param https://t.co/Ng1Ls99Wpc
4- change the mail value to account B
happy hunting
#BugBounty#bugbountytips
Here's a #bugbountytip I've used a couple times to find some really interesting functionality - if you're doing recon, check out this endpoint:
<targetdomain>/.well-known/apple-app-site-association
This endpoint is used for Apple's associated domains feature - you would really
I've made over 100k on SSRF vulnerabilities.
They aren't always as simple as pointing it at localhost or AWS Metadata service.
Here are some tricks I've picked up over the past 5 years of web app testing: