Everyone just sees the payout in bug bounties, but they never see the long road that was necessarily needed to arrive at those rewards
#bugbounty#ethicalhacking
We tell people all the time... you wanna be a better hack? then just hack. learn as you do. you will nevr know everything about hacking. you will never think you know enough. so dive in and start doing it. the best teachers are success and failure. (and trial & error lol)
I maintain that adding a trailing slash to random pages and APIs remains the stupidest albeit perhaps most effective and prevalent authorization and/or WAF bypass there is. Go slay #bugbounty, the world depends on your proper insertion of the slash.
When you get your first bounty doing this, go on a vacation and when your wife says "No no, it's too expensive."
You say: "Its OK, the slash is paying for it."
Because in what other field can you add a backslash somewhere and make enough money to take the family on a vacation 🤣
/place/thing/page.aspx --> /place/thing/page.aspx/
some/v1/api/users --> some/v1/api/users/
Other common wins are: /, //, %2f, %3f, #, and so forth. Just tack stuff lack that on the end. Maybe combine it with method changes.
OK BYE