bugbountygroup | Unsorted

Telegram-канал bugbountygroup - Bug bounty chat

3186

Talk and help about bugbounty

Subscribe to a channel

Bug bounty chat

I am novice also friend

Читать полностью…

Bug bounty chat

Hey friends. I am new in Cybersecurity. I have 0 knowledge. I am learning. I hope everyone will guide me.
Thanks & take love.

Читать полностью…

Bug bounty chat

you will need to use frida along side burp
there are videos on youtube that would give you a detailed explanation
hit me up if you have issues setting it up

Читать полностью…

Bug bounty chat

Is emulators a name of program like burp suite or not ?

Читать полностью…

Bug bounty chat

I found this in android application is it important?

{"param500":1,"param501":0,"param502":"YKBYM15","prm2":"SP6mUG6uWQ3oCZPSJzwIoyIPAtgrLGlC6BP22afaLBo0jE5EvM2r7KdCXew8KBpS","prm3":"35420909103999","prm4":"967779080460","timeStp":"17-09-2023 19:26:45.557","check":1,"hash":"A2628833FDD5B6963FBAEA1080B3ECE78DC1F70D9D59E793818E07A2F24DD449","param18":"35420909103999","param1":"4486544324","param2":0.0,"param3":0,"param5":0}

The app to send money to the wallet of number 4486544324

But i can't catch the request becuase it's in android apps

Is there a tool like burpsuite to edit the requests of the android apps?

Читать полностью…

Bug bounty chat

Hello friends, my name is Lucky or I want to start my career in bug bounty. Can anyone tell me that after finding the target, I do recon that like subdomain finding, directory brute forcing, subdomain take over all those things. what to do later? 🙂

Читать полностью…

Bug bounty chat

ohh
sorry about that

Читать полностью…

Bug bounty chat

yeah
i found it once before in the /.well-knowm/jwks endpoint

Читать полностью…

Bug bounty chat

so its possible to find the hs256 key from endpoint or js?

Читать полностью…

Bug bounty chat

i won't really call it algorithm confusion attack/bug.
i had the key so i just signed the token.
i think algorithm confusion involves signing an RS256 with a public key and changing the algorithm to HS256....But i maybe wrong

Читать полностью…

Bug bounty chat

Should i report one by one or all.j. one report؟

Читать полностью…

Bug bounty chat

this is p4 bug. i dont know if bugcrowd accept this type of bug😅

Читать полностью…

Bug bounty chat

Yea sure lemme try coz I have jeard its been used for apple payment or smthn

Читать полностью…

Bug bounty chat

Yeah
Dig deeper and know what the key is used for...

Читать полностью…

Bug bounty chat

And am seein it for first time. I havent seen a report or writeup on it

Читать полностью…

Bug bounty chat

lots to read and learn brother, enjoy and have fun!

Читать полностью…

Bug bounty chat

Ok thank you , i will search.

Читать полностью…

Bug bounty chat

Nope
Emulator is used to run Android apps on windows

Читать полностью…

Bug bounty chat

Use emulator and intercept requests

Читать полностью…

Bug bounty chat

is this valid? and can you describe as step to reproduce? like 1. 2. 3. like this?

Читать полностью…

Bug bounty chat

What are these?
Hs256
RS256

Читать полностью…

Bug bounty chat

i see. i always found rs256 in that endpoint and i try algorithm confusion but not work😅

Читать полностью…

Bug bounty chat

oh no
it was HS256

Читать полностью…

Bug bounty chat

yes its correct sorry i miss the HS256😅 i thought you found it in RS256

Читать полностью…

Bug bounty chat

yeah algorithm confusion bug

Читать полностью…

Bug bounty chat

Assume i have a bug in a program and it is on multi subdomains and also other domains which all in Scope

Читать полностью…

Bug bounty chat

Sorry new in the game i need a guide

Читать полностью…

Bug bounty chat

Really coz this name was put like 3 year back havent changed it lol

Читать полностью…

Bug bounty chat

why did u steal my nickname

Читать полностью…

Bug bounty chat

Well they asked for more information about the vulnerability

Читать полностью…
Subscribe to a channel