bugbountygroup | Unsorted

Telegram-канал bugbountygroup - Bug bounty chat

3264

Talk and help about bugbounty

Subscribe to a channel

Bug bounty chat

i think it depends on company, i would recommend to check if there was similar reports or if company actually paid for out of scope issues before.

Читать полностью…

Bug bounty chat

Guys i found a severe vulnerable but it's out of scope should i report it the vuln is opening admin panel and full control of the subdomain and server's files

Читать полностью…

Bug bounty chat

well that’s sad but still gives no right to actually exploit it 😔

Читать полностью…

Bug bounty chat

nah it’s type of playing stupid games winning stupid prizes if you really order something off of them. The consequences might be really dire. If I were in your shoes, I’d rather go report it again 😌

Читать полностью…

Bug bounty chat

yes do you want to try?

Читать полностью…

Bug bounty chat

they did not fix it😆 its almost 2 years since i found this

Читать полностью…

Bug bounty chat

You can. Owasp zap shows you the vulnerability. All you have to do is replicate it on your end which should be pretty easy

Читать полностью…

Bug bounty chat

do you have youtube video explain how i use owasp.zap tool to give it to hackerone soory my english too bad

Читать полностью…

Bug bounty chat

and a poc if it require

Читать полностью…

Bug bounty chat

I found store account takeover

Читать полностью…

Bug bounty chat

It was in my checkout page no one can see it so yeh no point

Читать полностью…

Bug bounty chat

i can able to alert any user who visit the shop

Читать полностью…

Bug bounty chat

i found POST based XSS and only me i can see it they didn't give me nothing

Читать полностью…

Bug bounty chat

Hi guys what would you recommend me to do to get into bug bounty, I've done some pentesting (TryHackMe, HackTheBox) but I'm open to any suggestions or advices

Читать полностью…

Bug bounty chat

does stored xss can be rejected?

Читать полностью…

Bug bounty chat

Nope. If in bb programm it is out-of-scope, high risk that your vuln will be unpaid

Читать полностью…

Bug bounty chat

yes. otherwise its a valid bug

Читать полностью…

Bug bounty chat

i reported it 5 times they did not response

Читать полностью…

Bug bounty chat

quantity tampering easy to find

Читать полностью…

Bug bounty chat

it’s just 50% off from their boss 😅

Читать полностью…

Bug bounty chat

For Any one who want to share a payload or find one 🤗 : @wildpayloads

Читать полностью…

Bug bounty chat

Is It possibile ti use owasp zap in hackerone bug bounty?

Читать полностью…

Bug bounty chat

screen recordign or screenshot

Читать полностью…

Bug bounty chat

hi guys if i found a bug with owasp.zap tool how can i give it to hackerone

Читать полностью…

Bug bounty chat

Is It possibile to do a subdomain takeover? Who can help me?

Читать полностью…

Bug bounty chat

https://youtu.be/Esq3S7HFLeg

Читать полностью…

Bug bounty chat

Pass CBBH exam on htb, first you have to complete relevant path, then you can shoot for an exam

Читать полностью…

Bug bounty chat

if it's self XSS it's not eligible for bounty

Читать полностью…

Bug bounty chat

i found stored xss in template and bypassing there filtration.. does self xss happen when the attacket cant send the link and cant make an alert to a victim

Читать полностью…

Bug bounty chat

Anyone know about price tempering?

Читать полностью…
Subscribe to a channel