Hello,
If anyone has come across a program with extensive functionalities or varying user permission levels, kindly share the program name with me, whether it's on HackerOne, Bugcrowd, or YesWeHack. Thanks!
Can anyone share their experience with VAPT/pentesting interview.What are the key topics and questions should focus on for an entry-level role?
Читать полностью…I'm looking for a "bug hunter," especially someone specialized in WordPress and capable of producing PoCs DM me! High payment offered.
Читать полностью…You are an angel! Heard a lot of good things about Shodan. I will try it out from your repo then. 😁
Читать полностью…Wix(.)com Reflected Xss | Bug Bounty #bugbountytip #bugbounty #hacking
https://youtu.be/is0cGl3TXkQ
Common xss types (especially dom), authentication vulns (like what is authentication vs authorization), basic client side vulns, and server side ones
Читать полностью…I have a lot of private invites on bugcrowd. Lmk if u wanna hunt together.
I also have access to paid tools like osintleak, knoxss, etc
Sure, I will try it out. Not much of a tool guy though, I hunt manually because of the types of bugs I hunt, they are very difficult to hunt with automation tools. But I am planning to learn tools for injection related vulnerabilities
Читать полностью…You might like sXtract if you do shodan dorking.
I completely automated shodan/google/dark web dorking in my automation workflow
Yeah, but it's true that I have encountered some dumb developers in the journey too. One site implemented only client side JS event blocker to block any unwanted intruder to access a particular resource. Just because of not knowing js enough, I couldn’t exploit it.
Читать полностью…