When you look up your target's ASN you'll find their ipv4 & ipv6 ranges.
Here's a one-liner to request all the webserver's SSL certificates and parse them for NEW TLD's, domains, and subdomains.
#bugbountytips
This year (2022), I have worked on creating educational resources in various forms, such as blogs, Twitter series, mindmaps and others. In case you missed them, here are all of them:
# SecurityExplained Twitter Series:
- https://t.co/JqwwUom4eI
🧵 - 1/5
Disclosed last 10 days (17.12.22-27.12.22)
Always try to break JWTs https://t.co/uQ6Pw38VsZ
Always check js files to get juicy stuffs https://t.co/QlMAXJnZ2H
IDORs everywhere
https://t.co/7310ZU23VJ
Business logic error based email verification bypass https://t.co/m0TSQh2lKR
10 types of web vulnerabilities that are often missed
🐞 HTTP/2 Smuggling
🐛 XXE via Office Open XML Parsers
🐜 SSRF via XSS in PDF Generators
🕷 XSS via SVG Files
🦟 Blind XSS
#bugbounty#pentest#hacking
Thread 🧵👇
https://t.co/c2AIi8ev8Q
Hi hackers,😁
You can use the below tool, one of the amazing tool when it comes to source code review assessment it’s going to save your time, It’s contain a huge databases with updated signatures for critical function in different programming languages.
https://t.co/vXAXXglN0t
Much like Amass, a lot of people don't use Nmap to its full potential. Here's a bunch of tips on how I use actually use Nmap.
If you get something out of this article, share it!
https://t.co/QzobV6hYhe