bugbountygroup | Unsorted

Telegram-канал bugbountygroup - Bug bounty chat

3186

Talk and help about bugbounty

Subscribe to a channel

Bug bounty chat

That's a medium at best yeah

Читать полностью…

Bug bounty chat

It was containing a lot of PII

Читать полностью…

Bug bounty chat

The report is still open in Traiged state. What is likely to happen?

Читать полностью…

Bug bounty chat

Can someone share methodology please

Читать полностью…

Bug bounty chat

i can upload file to s3 for guest section to file like shell.php it worked but when trying to open it downloads the file directly

Читать полностью…

Bug bounty chat

Rebyata, davaite uchit ruckiy yazik

Читать полностью…

Bug bounty chat

Has anyone came across this?

Читать полностью…

Bug bounty chat

You're right bro.
Thanks 😊

Читать полностью…

Bug bounty chat

If you can then try to escalate it more because the company needs to know how knowing all these credentials can affect them.

Читать полностью…

Bug bounty chat

Hello Hunters, I got NREUM loader account id, trustkey, agentid, license key and application id in a hardcoded source code. Should I report?

Читать полностью…

Bug bounty chat

Yo does anyone know any bug bounty platforms that pay through crypto, I'm new to this

Читать полностью…

Bug bounty chat

This blog might help you for the Role Based Access Control Bypass
Link 🔗: https://www.google.com/url?sa=t&source=web&rct=j&opi=89978449&url=https://www.bugbountyhunter.com/hackevents/report%3Fid%3D885&ved=2ahUKEwiEuLWqwdaFAxUhzzgGHaOdB-EQFnoECCAQAQ&usg=AOvVaw1_Sbdrsv1Awf3jzfgsz34V

Читать полностью…

Bug bounty chat

Thanks for the response.

I actually reported it and it was changed from critical to medium (Traiged) but I'm not okay with it being a medium.
The js file reveals a lot of endpoints too but whenever I try accessing the endpoints, it shows authentication token missing.

Читать полностью…

Bug bounty chat

Try escalating it more or else it will go in Informative vulnerabilities or very minimal bounty or points depending on the platform you are reporting.

Читать полностью…

Bug bounty chat

Hello hunters, while inspecting a js file, I found Names, Email addresses and Role : Admin, Signup date. Should I report it?

Читать полностью…

Bug bounty chat

Name and email addresses

Читать полностью…

Bug bounty chat

Why would that be critical

Читать полностью…

Bug bounty chat

Got a response that's it's actually a retool dummy data.
💔😣

Читать полностью…

Bug bounty chat

its exutes its code also

Читать полностью…

Bug bounty chat

Hi all, does anyone have an external peneteation testing checklist? If you have pls share it.

Читать полностью…

Bug bounty chat

https://infosecwriteups.com/hack-stories-hacking-hackers-ep-3-11b1f0e002e8

Читать полностью…

Bug bounty chat

https://book.cipherops.tech/bug-bounty-notes/readme/cipherops

Читать полностью…

Bug bounty chat

You may report It but I'm 90% sure they will say the same!
And remaining 10% they might give you bounty or points or mark it as informative if it does not effect them.

Читать полностью…

Bug bounty chat

Treat as urgent please 🙏

Читать полностью…

Bug bounty chat

xss.is / exploit.in 😂
——
it's a joke btw

Читать полностью…

Bug bounty chat

new writeups !!!

View billing information using IP Rotation!

Read - https://rhymeus.blog/2024/04/view-billing-information-using-ip.html

Читать полностью…

Bug bounty chat

I also came across a RBAC. Any idea on how to bypass? I don't think fuzzing would help

Читать полностью…

Bug bounty chat

Just search wordlist for the purpose you want there are many GitHub pages with great wordlists or you can use Chatgpt to create one for you ✌🏻🌚

Читать полностью…

Bug bounty chat

Instead of 404, fuzz 403 try to bypass it.
403 has more credibility if bypassed than 404.
For 404, you can try fuzzing but just inspect first which type of pages the website is using that can narrow down your approach for wordlists.
For Example: While scrolling a website and traversing it's different pages you get to know that website is using .aspx or .php or some extensions like that for about us and sitemap.xml too.

Читать полностью…

Bug bounty chat

Best wordlists for fuzzing 404 ?
Anyone please

Читать полностью…
Subscribe to a channel