I earned $6,000 for an SSO bypass in @Hacker0x01 !
💡Tip:
Always test authentication endpoints with encoded whitespace. A simple %20 (trailing space) bypassed SSO completely and fell back to the legacy login flow.
The Issue:👇
The application normalized input after checking for SSO eligibility. By appending an encoded space to the email parameter, the check failed and the request was routed to the standard auth flow.
#bugbountytips #hackerone
No jailbreak. No problem. 🔓
I built a tool that bypasses iOS SSL Pinning using OpenVPN + iptables — works with Burp Suite & mitmproxy out of the box.
👇 GitHub
https://t.co/N4QyCDaXvR
#CyberSecurity#BugBounty#iOS#Pentesting
Hi All -.‑
we always talk about security issues
today I’ll share how I exploited a feature used to protect the website and turned it into a critical issue
hope you like it waiting for your opinions -.-
https://t.co/IiQX96dkYp
#BugBounty#bugbountytips#infosec#bugbountytip
🔥 Fuzzing and Bypassing the AWS WAF
Interesting writeup by the @sysdig team on building an automated fuzzing tool to trigger XSS by bypassing the AWS WAF
https://t.co/elPGc4p3M0
Fuzzer: https://t.co/X1YJJJzM6f
#bugbountytips#bugbounty#infosec#cybersecurity
@OctagonNetworks In this code lies in the getBalance and setBalance functions (not shown in the provided code). If these functions don't properly validate the user's authentication or authorization, an attacker might be able to manipulate the balance and perform unauthorized withdrawals.
Found a GraphQL endpoint that you want to test? InQL is just for you!
InQL is an awesome BurpSuite extension for advanced GraphQL pentesting!! 😎
Check it out 👇
https://t.co/zWdmDGETtb
I've found HTTP Verb Tampering can often be used to bypass 403 (and 401) too.
Also fuzzing HTTP proxy headers and setting values to localhost often works like a charm. I use this tool to speed up the process
credit: @0dayWizard
https://t.co/SmuPKCrf3K
Successfully bypassed a SSRF WAF by using a combination of IPV6 + Unicode. Payload for Metadata instances:
http://[::ⓕⓕⓕⓕ:①⑥⑨。②⑤④。⑯⑨。②⑤④]:80
Check images for response difference between 169.254.169.254 and the above payload I shared 🔥
#bugbounty#infosec#waf
@fattselimi Same thing happend to me earlier the triager closed my report as N/A then I submitted all possible proofs including the poc video of exploitation and the company fixed the bug but still the triager didn't change report status then I requested a mediation.