noobSecurity (@noobsec_org) 's Twitter Profile
noobSecurity

@noobsec_org

One mistake can make you crazy! mailto:[email protected]

ID: 992204330391371776

linkhttps://noobsec.org calendar_today04-05-2018 00:48:41

1,1K Tweet

1,1K Followers

215 Following

Faizal Abroni (@faizalabroni) 's Twitter Profile Photo

1. ./dirsearch.py -u target -e php,html,js,xml -x 500,403 2. found url.com/.svn/ 3. clone & use github.com/anantshri/svn-… 4. ./svn-extractor.py --url url.com --match database.php 5. result in output dir and just open it #bugbounty #bugbountytips

1. ./dirsearch.py -u target -e php,html,js,xml -x 500,403
2. found url.com/.svn/
3.  clone & use github.com/anantshri/svn-…
4. ./svn-extractor.py --url url.com --match database.php
5. result in output dir and just open it
#bugbounty #bugbountytips
Faizal Abroni (@faizalabroni) 's Twitter Profile Photo

1. found blind sql injection 2. use simple payload ./sqlmap -r req -p vuln --dbs 3. the backend db is Firebird 4. cant retrieve dbname or table 5. change payload to -r req -p vuln--level 3 --risk 3 --thread 8 --dbms Firebird --tables 6. puf! *image below #bugbountytips #bugbounty

1. found blind sql injection
2. use simple payload ./sqlmap -r req -p vuln --dbs
3. the backend db is Firebird
4. cant retrieve dbname or table
5. change payload to -r req -p vuln--level 3 --risk 3 --thread 8 --dbms Firebird --tables
6. puf! *image below
#bugbountytips #bugbounty
dw1 (@dwisiswant0) 's Twitter Profile Photo

Been learned for ~2 weeks, this is my first #Rust program: a fast tool to scan prototype pollution vulnerability. github.com/dwisiswant0/pp… Thanks to ईशान सिंह for the tip! #infosec #bugbounty #bugbountytips

dw1 (@dwisiswant0) 's Twitter Profile Photo

ppfuzz v1 released! Now, if it's indeed vulnerable: it'll fingerprinting the script gadgets used and then display additional payload info that could potentially escalate its impact to XSS, bypass/cookie injection. Bump now! — github.com/dwisiswant0/pp… #bugbountytips

dw1 (@dwisiswant0) 's Twitter Profile Photo

Now #apkleaks v2.6.0 released! - GitHub Access Token - Discord BOT Token - JSON Web Token - MAC Address - CTF Flags: — DEF CON — HackerOne — TryHackMe — HackTheBox

IDSECCONF (@idsecconf) 's Twitter Profile Photo

Dear ID-Hackers, pendaftaran ditutup hari ini jadi masih bisa registrasi di 2021.idsecconf.org/p/registrasi.h…, bagi yang sudah daftar, sudah bayar dan belum terima link zoom segera kontak @azisaz 🍉 atau email ke viska[at]idsecconf.org atau WA ke: +62-851-6253-1337, see you \o/

Dear ID-Hackers,  pendaftaran ditutup hari ini jadi masih bisa registrasi di 2021.idsecconf.org/p/registrasi.h…, bagi yang sudah daftar, sudah bayar dan belum terima link zoom segera kontak <a href="/azisaz/">@azisaz 🍉</a> atau email ke viska[at]idsecconf.org atau WA ke: +62-851-6253-1337, see you \o/
Nuclei by ProjectDiscovery (@pdnuclei) 's Twitter Profile Photo

New - Grafana unauthorized arbitrary file read Template: github.com/projectdiscove… by z0ne, dhiyaneshDk Reference: nosec.org/home/detail/49… #bugbounty #pentest #appsec

New - Grafana unauthorized arbitrary file read 

Template: github.com/projectdiscove… by z0ne, dhiyaneshDk

Reference: nosec.org/home/detail/49…

#bugbounty #pentest #appsec
YoKo Kho (@yokoacc) 's Twitter Profile Photo

The Prophet (ﷺ) said, "A believer to another believer is like a building whose different parts enforce each other." The Prophet (ﷺ) then clasped his hands with the fingers interlaced. (Shohih Al-Bukhari No. 6026).

The Prophet (ﷺ) said, "A believer to another believer is like a building whose different parts enforce each other." 

The Prophet (ﷺ) then clasped his hands with the fingers interlaced.

(Shohih Al-Bukhari No. 6026).
dw1 (@dwisiswant0) 's Twitter Profile Photo

Did you know that you can use ngrok for detecting out-of-band requests? I just built ngocok, yet another Burp Collaborator for free. It effortlessly wraps ngrok tunnels and captures incoming requests seamlessly. 👉 github.com/dwisiswant0/ng… #bugbounty #bugbountytip #bugbountytips

IDSECCONF (@idsecconf) 's Twitter Profile Photo

Innalillahi wa inna ilaihi rojiun telah berpulang ke-Rahmatullah salah satu aktivis cyber security indonesia yang merupakan salah satu komite #IDSECCONF, Randi Malikul Mulki (Cybertank) hari ini. Semoga diampuni segala dosanya dan diterima amal ibadahnya, Aamiin 🤲🏻