@TataPlayin i found couple of vulnerabilities in your product i tried to report on your bug hunter platform but it throwing some errors. Can i get an email to report the vulnerabilities?
GooFuzz - A tool to perform fuzzing with an #OSINT approach, managing to enumerate directories, files, subdomains, or parameters without leaving evidence on the target's server and by means of advanced Google searches (Google Dorking)
» https://t.co/vKpNpEi8aY
#cybersecurity
Bypass Url Parser by @TheLaluka
Checking the source, I can confirm many of these methods have worked for me in the past. Including a string of auth bypasses for $30k on a bounty platform.
Excited to test tool instead of doing it all manually 🤩
https://t.co/COzbIunwbK
My tweets are filled with web3 🚀
If anyone learning smart contact and web3 security drop your resources below🙏
Here are some amazing resources I found to learn Solidity 👇
== Trademark and Copyright Recon ==
How to find assets no other bug hunters have found.
One of my simple "secrets" for years.
Little automation exists for it.
💸💸💸
a thread🧵
🚨follow, retweet, & like for more hacker tips!🚨
1/x
🚨XSS Polyglots🚨
Test multiple XSS scenarios with ONE payload.
jaVasCript:/*-/*`/*\`/*'/*"/**/(/* */oNcliCk=alert() )//%0D%0A%0d%0a//</stYle/</titLe/</teXtarEa/</scRipt/--!>\x3csVg/<sVg/oNloAd=alert()//>\x3e
#BugBounty#bugbountytips#XSS