Ashish Rao (@ashishraosahab6) 's Twitter Profile
Ashish Rao

@ashishraosahab6

| Cyber Security |
Bug Hunter | #blackbox | #greybox | #whitebox |
github.com/Ashish-bot |

ID: 2897697889

calendar_today12-11-2014 15:23:23

4,4K Tweet

111 Followers

284 Following

Nicolas Krassas (@dinosn) 's Twitter Profile Photo

CVE-2024-40725 & CVE-2024-40898: Apache HTTP Server Flaws Put Millions of Websites at Risk securityonline.info/cve-2024-40725โ€ฆ

RootMoksha Labs (@rootmoksha) 's Twitter Profile Photo

๐—ซ๐—ฆ๐—ฆ ๐—•๐˜†๐—ฝ๐—ฎ๐˜€๐˜€ ๐—ฃ๐—ฎ๐˜†๐—น๐—ผ๐—ฎ๐—ฑ: javascriptโ€‹:var a="ale";var b="rt";var c="()";decodeURI("<button popovertarget=x>Click me</button><cybertix onbeforetoggleโ€‹="+a+b+c+" popover id=x>CYBERTIX</cybertix>") #bugbountytips by Cybertix

๐—ซ๐—ฆ๐—ฆ ๐—•๐˜†๐—ฝ๐—ฎ๐˜€๐˜€ ๐—ฃ๐—ฎ๐˜†๐—น๐—ผ๐—ฎ๐—ฑ:
                                        
javascriptโ€‹:var a="ale";var b="rt";var c="()";decodeURI("&lt;button popovertarget=x&gt;Click me&lt;/button&gt;&lt;cybertix onbeforetoggleโ€‹="+a+b+c+" popover id=x&gt;CYBERTIX&lt;/cybertix&gt;")

#bugbountytips by <a href="/thecybertix/">Cybertix</a>
๐• Bug Bounty Writeups ๐• (@bountywriteups) 's Twitter Profile Photo

๐Ÿš€๐Ÿš€ How to find RXSS in 5 minutes ๐Ÿš€๐Ÿš€ ๐Ÿงพ Credit - Ahmad Marzouk 1) subfinder -d target.com -all -o targets.txt *use subfinder with API Keys to extract a lot subdomains* 2) paramspider -lย targets.txt 3) cat *.txt | kxss 4) Use this Payload to Bypass case

Today Cyber News (@todaycybernews) 's Twitter Profile Photo

A major security vulnerability in the most recent version of WhatsApp for Windows lets hackers send attachments that contain PHP and Python scripts that execute quietly when the person who received them opens them. Read More - hackingblogs.com/indepth-guide-โ€ฆ #bugbounty #cybersecurity

A major security vulnerability in the most recent version of <a href="/WhatsApp/">WhatsApp</a> for Windows lets hackers send attachments that contain PHP and Python scripts that execute quietly when the person who received them opens them.

Read More - hackingblogs.com/indepth-guide-โ€ฆ

#bugbounty #cybersecurity
Intigriti (@intigriti) 's Twitter Profile Photo

Want a comprehensive guide on how to exploit SQL injections? ๐Ÿค‘ Check out Advanced SQL Injection Techniques by N$! ๐Ÿ˜Ž A Gitbook covering some of the most common and advanced SQL injections that may be present on your target! ๐Ÿ‘‡ buff.ly/3AfzUUz

H1 Disclosed - Public Disclosures (@h1disclosed) 's Twitter Profile Photo

โšก Content-Security Policy bypass with File Uploads ๐Ÿ‘จ๐Ÿปโ€๐Ÿ’ป gronke โžŸ Rocket.Chat ๐ŸŸฅ High ๐Ÿ’ฐ None ๐Ÿ”— hackerone.com/reports/1380157 #bugbounty #bugbountytips #cybersecurity #infosec

โšก Content-Security Policy bypass with File Uploads 
๐Ÿ‘จ๐Ÿปโ€๐Ÿ’ป gronke โžŸ Rocket.Chat 
๐ŸŸฅ High
๐Ÿ’ฐ None
๐Ÿ”— hackerone.com/reports/1380157
#bugbounty #bugbountytips #cybersecurity #infosec
H1 Disclosed - Public Disclosures (@h1disclosed) 's Twitter Profile Photo

โšก moderate: Apache HTTP Server: mod_rewrite proxy handler substitution (CVE-2024-39573) CWE-20 Impr... ๐Ÿ‘จ๐Ÿปโ€๐Ÿ’ป orange โžŸ Internet Bug Bounty ๐ŸŸง Medium ๐Ÿ’ฐ $2,600 ๐Ÿ”— hackerone.com/reports/2585374 #bugbounty #bugbountytips #cybersecurity #infosec

โšก moderate: Apache HTTP Server: mod_rewrite proxy handler substitution (CVE-2024-39573) CWE-20 Impr... 
๐Ÿ‘จ๐Ÿปโ€๐Ÿ’ป orange โžŸ Internet Bug Bounty 
๐ŸŸง Medium
๐Ÿ’ฐ $2,600
๐Ÿ”— hackerone.com/reports/2585374
#bugbounty #bugbountytips #cybersecurity #infosec
H1 Disclosed - Public Disclosures (@h1disclosed) 's Twitter Profile Photo

โšก Course Registration Form Allowing an attacker to dump all the candidate name who had enrolled for... ๐Ÿ‘จ๐Ÿปโ€๐Ÿ’ป steveflex โžŸ U.S. Dept Of Defense ๐ŸŸฅ High ๐Ÿ’ฐ None ๐Ÿ”— hackerone.com/reports/1100383 #bugbounty #bugbountytips #cybersecurity #infosec

โšก Course Registration Form Allowing an attacker to dump all the candidate name who had enrolled for... 
๐Ÿ‘จ๐Ÿปโ€๐Ÿ’ป steveflex โžŸ U.S. Dept Of Defense 
๐ŸŸฅ High
๐Ÿ’ฐ None
๐Ÿ”— hackerone.com/reports/1100383
#bugbounty #bugbountytips #cybersecurity #infosec
H1 Disclosed - Public Disclosures (@h1disclosed) 's Twitter Profile Photo

โšก Blind Stored XSS on the internal host - โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ ๐Ÿ‘จ๐Ÿปโ€๐Ÿ’ป Eugene Yakovchuk โžŸ U.S. Dept Of Defense ๐ŸŸฅ High ๐Ÿ’ฐ None ๐Ÿ”— hackerone.com/reports/923912 #bugbounty #bugbountytips #cybersecurity #infosec

โšก Blind Stored XSS on the internal host - โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ 
๐Ÿ‘จ๐Ÿปโ€๐Ÿ’ป <a href="/h1_sp1d3r/">Eugene Yakovchuk</a> โžŸ U.S. Dept Of Defense 
๐ŸŸฅ High
๐Ÿ’ฐ None
๐Ÿ”— hackerone.com/reports/923912
#bugbounty #bugbountytips #cybersecurity #infosec
H1 Disclosed - Public Disclosures (@h1disclosed) 's Twitter Profile Photo

โšก Unauthenticated arbitrary file upload on the https://โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ/ (โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ) ๐Ÿ‘จ๐Ÿปโ€๐Ÿ’ป Eugene Yakovchuk โžŸ U.S. Dept Of Defense ๐ŸŸฅ High ๐Ÿ’ฐ None ๐Ÿ”— hackerone.com/reports/698789 #bugbounty #bugbountytips #cybersecurity #infosec

โšก Unauthenticated arbitrary file upload on the https://โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ/ (โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ) 
๐Ÿ‘จ๐Ÿปโ€๐Ÿ’ป <a href="/h1_sp1d3r/">Eugene Yakovchuk</a> โžŸ U.S. Dept Of Defense 
๐ŸŸฅ High
๐Ÿ’ฐ None
๐Ÿ”— hackerone.com/reports/698789
#bugbounty #bugbountytips #cybersecurity #infosec
Nikhil Mittal (@nikhil_mitt) 's Twitter Profile Photo

We had a blast at DEF CON ! Met 2000+ visitors on our booth. Met many of our existing students and customers and met many new ones. We sponsored the Adversary Village and the RedTeamVillage. We also had the largest collection of mugs at DEF CON 32 :) After the conference, we

We had a blast at <a href="/defcon/">DEF CON</a> ! Met 2000+ visitors on our booth. Met many of our existing students and customers and met many new ones.

We sponsored the <a href="/AdversaryVillag/">Adversary Village</a>  and the <a href="/RedTeamVillage_/">RedTeamVillage</a>. We also had the largest collection of mugs at DEF CON 32 :)

After the conference, we
H1 Disclosed - Public Disclosures (@h1disclosed) 's Twitter Profile Photo

โšก Local Privilege Escalation via DLL Search-Order Hijacking with Cyber Protection Agent - tibxread.... ๐Ÿ‘จ๐Ÿปโ€๐Ÿ’ป mmg โžŸ Acronis ๐ŸŸง Medium ๐Ÿ’ฐ None ๐Ÿ”— hackerone.com/reports/963103 #bugbounty #bugbountytips #cybersecurity #infosec

โšก Local Privilege Escalation via DLL Search-Order Hijacking with Cyber Protection Agent - tibxread.... 
๐Ÿ‘จ๐Ÿปโ€๐Ÿ’ป mmg โžŸ Acronis 
๐ŸŸง Medium
๐Ÿ’ฐ None
๐Ÿ”— hackerone.com/reports/963103
#bugbounty #bugbountytips #cybersecurity #infosec