Tip: Open Redirect ⚠️
- Use invalid URL-encoded bytes (%96 , %97) to bypass validation; they decode to (?)
evil[.]com?@ target[.]com ❌
evil[.]com%97@target[.]com ✅
#bugbountytips#bugbounty
1/2
Has the old login page been removed?
No worries, go a step further and try the login form endpoint:
https://t.co/0VTnYBwQRf => 404 => copy/send the login form from https://t.co/BFHvqZZGBf => https://t.co/jBk1kBaPse => 200
Pro tip: 2FA Bypass 🔥
1/1
- Look for old login pages in https://t.co/47K6QCeQMS , Sometimes they are not protected.
- This can also lead to finding some XSS, Open Redirects.
#bugbountytips#bugbounty