Looks like Truffle Security has been digging through hackers' XSS Hunter data. Trusting a free service with your data works most of the time, but not every time.
https://t.co/YOGNR5ahHu
New XSS platform released.
Support using your own domain name.
Support webhook.
Mates with the burpsuite extension to log the full request that triggers xss.
For more, please visit.
https://t.co/WtUhwVFo0j
#xsshunter#xss#hackerone#bugbounty#bugcrowd#bugbountytip#burpsuite
Just when you thought JSON was the one thing you could trust. My latest research on JSON interoperability vulnerabilities highlights the risks of inconsistent parser behavior (40+ parsers) and attacks to bypass business logic in microservice architectures. https://t.co/A3MQkLpAXe
Top 25 Vulnerability Parameters based on frequency
Vulnerable parameters including ๐ฆ๐ค๐๐ถ, ๐ซ๐ฆ๐ฆ, ๐ฆ๐ฆ๐ฅ๐, ๐ฅ๐๐, ๐ซ๐ฆ๐ฆ, ๐ข๐ฝ๐ฒ๐ป ๐ฅ๐ฒ๐ฑ๐ถ๐ฟ๐ฒ๐ฐ๐ that can be used in automation tools or manual recon. ๐ก๏ธ๐งโโ๏ธ
https://t.co/D7j9jXfinM
#bugbounty#bugbountytips#cybersecurity