“Uber closed your report #123456 Social engineering in uber./com as N/A. Want to improve your reporting and hacking skills? Download your free copy of the book Web Hacking 101”
🤣
Attacker: okay here is the POC 🤣
#uber#uberhack#infosec#hackerone
KARGIL VIJAY DIVAS
Salute the grit, determination & steely nerves of the Soldiers of Indian Army @adgpi
With Prayers on Lips & Pride in Hearts, Remember the Bravehearts Who Made the Supreme Sacrifice
Jai Hind 🇮🇳
People drop 0dayz every day.
What they don’t know is how to responsibly disclose them...
Here are 13 ways to responsibly disclose your 0dayz you won’t be able to live without 👇
@mukund_natvar@IncomeTaxIndia No way for me to find out on this domain as I do not have an employee account to test on. Atleast in all the domains of the Indian gov I’ve seen, HttpOnly is false. Even if it was enabled, it wouldn’t be able to completely mitigate XSS.
XSS in @IncomeTaxIndia
Payload: lookhere');});</script><img src=x onerror=alert('XSS')>
1)the keyword “lookhere” was used to detect all the places the input was reflected
2)The rest is responsible for balancing the payload
#infosec#bugbountytips#xss