After working for a long time, finally got my first Hall of Fame🏆 and bounty💸...Thank you everyone for love, support and guidance ❤️🙏
#bugbountytips#bugbounty#hacking
How to test your apps for #log4shell vulnerability
1. Generate a DNS token https://t.co/vCzVG0O03i
2. Wrap that token in
Prefix: ${jndi:ldap://
Suffix: /a}
3. Use that value in search forms, profile data, settings etc. of your apps
4. Get notified when you triggered a reaction
Recon Methods:-
Part 1:-
https://t.co/sdiC7pP9TS
Part 2:-
https://t.co/IFMHHcFoGP
Part 3:-
https://t.co/uD6WFcpTLe
Part 4:-
https://t.co/Eco2jqdKyY
Part 5:-
https://t.co/l2xyKMin7w
I have checked every single page of this repo
Real world scenarios with proper reference
Must give it a look and support author @daffainfo for his excellent work
#bugbountytips#infosec#cybersecurity
https://t.co/paF6LAn7Th