Mr. Crit0x (@mrcrit0x) 's Twitter Profile
Mr. Crit0x

@mrcrit0x

Bug Hunter

ID: 1472621064052101122

calendar_today19-12-2021 17:33:34

210 Tweet

29 Followers

611 Following

Syed Mushfik Hasan Tahsin (@smhtahsin33) 's Twitter Profile Photo

Hello, If you are just getting started into bug bounties and can't find enough resources, this thread might help you to find a way πŸ‘‡

Abhishek Meena - {πŸ”₯} (@aacle_) 's Twitter Profile Photo

========= Master XSS ========= Share this with your friends πŸ˜€ Tags: #cybersecurity #hacking #bugbounty #xss #masterXSS #infosec #offsec #labs Check :🧡0/n πŸ‘‡

0xRAYAN πŸ‡ΈπŸ‡¦ (@0xrayan7) 's Twitter Profile Photo

I hate recon but here a good tip : 1 - Get the company IPs range X.X.X.X/24 2 - Run nmap -p 80,448,8080 IP/24 -oN file.txt 3 - Use any IP extractor or API in case of automation or bash then save it on IPs.txt 4- run httpx -l IPs.txt -o final.txt 5 - run nuclei -l final.txt

Jayesh Madnani (@jayesh25_) 's Twitter Profile Photo

Bug Bounty Tips: πŸ›πŸ’° Here's a simple bug bounty tip for shopping site targets that can earn you some serious $$$$. I've stumbled upon 10+ similar issues on shopping sites that allow guest checkouts πŸ›’. Many overlook these issues because they require placing an order πŸ“¦.

Bug Bounty Tips: πŸ›πŸ’° Here's a simple bug bounty tip for shopping site targets that can earn you some serious $$$$. 

I've stumbled upon 10+ similar issues on shopping sites that allow guest checkouts πŸ›’. 

Many overlook these issues because they require placing an order πŸ“¦.
Will Gates (@wllgates) 's Twitter Profile Photo

GitHub - KingOfBugbounty/Bugbounty-Checklist: Tips and Tutorials for Bug Bounty and also Penetration Tests.πŸ”₯πŸ”₯ credit: Clandestine #bugbountytips #hacking #recon #bugcrowd #hackerone #infose github.com/KingOfBugbount…

Rishika Desai (@ich_rish99) 's Twitter Profile Photo

Good resources on #BugBounty for you to bookmark!🌟 1. kongsec.medium.com/how-to-js-for-… 2. medium.com/@investigator5… 3. medium.com/@ar_hawk/from-… 4. asdqw3.medium.com/xss-in-gmail-d… 5. medium.com/@deadoverflow/… #dorking #vulnerability #bugbountytip

Hunter (@huntermapping) 's Twitter Profile Photo

🚨Alert🚨CVE-2023-41056: Redis Remote Code Execution Vulnerability Redis may incorrectly handle resizing of memory buffers which can result in incorrect accounting of buffer sizes and lead to heap overflow and potential remote code execution. πŸ“Š 1.4M+ services are found on the

🚨Alert🚨CVE-2023-41056: Redis Remote Code Execution Vulnerability
Redis may incorrectly handle resizing of memory buffers which can result in incorrect accounting of buffer sizes and lead to heap overflow and potential remote code execution.

πŸ“Š 1.4M+ services are found on the
Sirat Sami (analyz3r) (@siratsami71) 's Twitter Profile Photo

Do your target using WordPress? If so, then you should check if they have rate limit on their WordPress login "wp-login.php" or not. Note, WordPress doesn't use rate limit on its login by default. #BugBounty #bugbountytips #bugbountytip

VAIDIK PANDYA (@h4x0r_fr34k) 's Twitter Profile Photo

Cloudflare Bypasses Here are 10 Writeups about Cloudflare bypasses 1. medium.com/@the_harvester… (XSS) 2. cyberweapons.medium.com/reflected-xss-… (RXSS) 3. medium.com/@amitdutta6026… (SQLi) 4. medium.com/@mayankchoubey… (SID from XSS) 5. royzsec.medium.com/cloudflare-byp… (In Microsoft) 6.

Bug Bounty Village (@bugbountydefcon) 's Twitter Profile Photo

Don't miss "A Zero to Hero Crash Course to Server-Side Request Forgery (SSRF)" by Ben Sadeghipour (@nahamsec)! πŸ“… Friday, Aug 9 ⏰ 12:15 PM πŸ“ Bug Bounty Village Classroom, Room W215 #BugBounty #DEFCON

Don't miss "A Zero to Hero Crash Course to Server-Side Request Forgery (SSRF)" by Ben Sadeghipour (@nahamsec)!  πŸ“… Friday, Aug 9 ⏰ 12:15 PM πŸ“ Bug Bounty Village Classroom, Room W215 #BugBounty #DEFCON
Het Mehta (@hetmehtaa) 's Twitter Profile Photo

GitHub Repos of Bug Bounty One Liners #bugbounty github.com/dwisiswant0/aw… github.com/twseptian/onel… github.com/0xPugal/One-Li… github.com/0xPugal/One-Li… github.com/daffainfo/Onel…

Pratik Dabhi (@impratikdabhi) 's Twitter Profile Photo

πŸ—οΈ Top Checks for IDOR Bugs β€’ Change IDs in URLs & APIs (e.g. /user?id=123) β€’ Test DELETE & PUT requests, not just GET/POST β€’ Swap numeric ↔ alphanumeric IDs β€’ Hunt for ID references in JavaScript files β€’ Inspect nested JSON objects for hidden IDs πŸ’° IDORs are easy to