LudvY πŸ‡©πŸ‡ΏπŸ‘Ύ(@lud_vy) 's Twitter Profile Photo

Shodan InternetDB feature for Scanning Host CVEs & Ports using IP :

curl -X 'GET' 'internetdb.shodan.io/ip_here' -H 'accept: application/json' | jq

tips

Shodan InternetDB feature for Scanning Host CVEs & Ports using IP :

curl -X 'GET' 'internetdb.shodan.io/ip_here' -H 'accept: application/json' | jq

#bugbountytips #bugbounty
account_circle
Ashraf Abdelrazik(@ashabdelrazik) 's Twitter Profile Photo

CRLF injection with a 302 response will not succeed because browsers will ignore the body. However, adding a NULL byte (%00) will prevent the redirection, and the body will be executed, meaning that you will be able to inject XSS payloads.

tips

CRLF injection with a 302 response will not succeed because browsers will ignore the body. However, adding a NULL byte (%00) will prevent the redirection, and the body will be executed, meaning that you will be able to inject XSS payloads.

#crlf #bugbounty #bugbountytips
account_circle
Rahul Sirvi(@rahul0x01) 's Twitter Profile Photo

I earned $50 for my submission on bugcrowd

Tip: Fuzzing deeper is the key πŸ”‘
If you think you find a file sensitive, load up a huge wordlist and fuzz on every endpoint.

s

I earned $50 for my submission on @Bugcrowd 

Tip: Fuzzing deeper is the key πŸ”‘ 
If you think you find a file sensitive, load up a huge wordlist and fuzz on every endpoint.

#BugBounty #bugbountytips #bugbountytip #ItTakesACrowd
account_circle
badcracker(@badcrack3r) 's Twitter Profile Photo

Excited to announce that I've hit the milestone of 15k+ reputation HackerOne, placing me at an impressive rank 60 All time! πŸŽ‰ Grateful to have achieved this at the age of 20!

tip tips

Excited to announce that I've hit the milestone of 15k+ reputation @Hacker0x01, placing me at an impressive rank 60 All time! πŸŽ‰ Grateful to have achieved this at the age of 20!

#bugbounty #bugbountytip #bugbountytips #ethicalhacking #hacking #infosec #pentesting  #hackforgood
account_circle
4rmand.exe(@_Zer0Sec_) 's Twitter Profile Photo

Good old Forced Browsing πŸ’―

1. Noticed 403 for β€œ/.git”
2. Kept knocking at different doors
3. Door # β€œ.git/config” & β€œ.git/index” were unlocked
4. Dumped repo locally
5. Analyzed all items and located β€œconfig.php” containing secrets, prod credentials

Good old Forced Browsing πŸ’―

1. Noticed 403 for β€œ/.git”
2. Kept knocking at different doors
3. Door # β€œ.git/config” & β€œ.git/index” were unlocked
4. Dumped repo locally
5. Analyzed all items and located β€œconfig.php” containing secrets, prod credentials
#bugbountytips #BugBounty
account_circle
Travala.com(@travalacom) 's Twitter Profile Photo

This one's for the Crypto Whales πŸ“£

NEW exclusive & luxurious experiences have been added to Concierge.io. Apply today & with your favorite cryptocurrency.

account_circle
Public Void πŸ‡©πŸ‡Ώ(@_public_void) 's Twitter Profile Photo

Hello Community,

I found this JS file 'env-config.js' and my question is :
Should i report it immediately as [sensitive infos disclosure] or i need to perform other actions to prove the impacts ?



Hello Community,

I found this JS file 'env-config.js' and my question is :
Should i report it immediately as [sensitive infos disclosure] or i need to perform other actions to prove the impacts ?

#bugbountytips 
#BugBounty 
#CyberSecurity
account_circle