bugbountygroup | Unsorted

Telegram-канал bugbountygroup - Bug bounty chat

3186

Talk and help about bugbounty

Subscribe to a channel

Bug bounty chat

You find dups regardless of the tool or manual test you do if someone came first 🤷‍♂

Читать полностью…

Bug bounty chat

What about Duplicates?

Читать полностью…

Bug bounty chat

I agree. There is nothing better than manual when it comes this. The only way I’d ever use a manual process is when trying different payloads for a specific function like xss or path traversal with intruder

Читать полностью…

Bug bounty chat

A 6yo old kid will find less false positive than automated tool 🔧

Читать полностью…

Bug bounty chat

to HELP ME not HUNT FOR ME

Читать полностью…

Bug bounty chat

U cannot achive more than xss or some flase positive or maybe some intentional bugs which aren't eligible for a bounty

Читать полностью…

Bug bounty chat

Nuclei with custom templates is insanely good

Читать полностью…

Bug bounty chat

Does it do the same with https?

Читать полностью…

Bug bounty chat

Hello all please help me, I just bought a vps and running nuclei but I found information like this on nuclei Templates clustered: 1194 (Reduced 1133 Requests) Is yours also like that?

Читать полностью…

Bug bounty chat

In admin page on a specific directory fuzz as much as you can headers params cookies... chance of 80% u will get somewhere ro analyze more

Читать полностью…

Bug bounty chat

Possible ways to bypass WAF specifically for SSRF

Читать полностью…

Bug bounty chat

I will teach free Hacking for newbie

Читать полностью…

Bug bounty chat

Как же мы все любим Битрикс, обожаем просто , рай для хакеров

Читать полностью…

Bug bounty chat

Thanks for answering

Читать полностью…

Bug bounty chat

Vulnerabilities. You would obviously need to show how it’s vulnerable though. So for example, you stumble across a reflected xss, just do a recording of a non damaging tag like the alert. Don’t actually inject a damaging payload

Читать полностью…

Bug bounty chat

Teh that's fuzzing which is essential

Читать полностью…

Bug bounty chat

You arent testing thousands of hosts manually tho, nuclei is one of the best tools out there to scale big numbers

Читать полностью…

Bug bounty chat

Nuclei has basically no false positives

Читать полностью…

Bug bounty chat

Manual bug hunt > automated

Читать полностью…

Bug bounty chat

I made lots of scripts to help me and save time

Читать полностью…

Bug bounty chat

There are a lot of paid template u can not imagine how they work and still useless

Читать полностью…

Bug bounty chat

Nuclei is the biggest wast of time

Читать полностью…

Bug bounty chat

Can you send whole screenshot

Читать полностью…

Bug bounty chat

Do you think I can report that I can inject code into HTTP headers and reflect them because the TRACE method is enabled? Does anyone know if I can achieve an impact from this? I have seen reports that justify the impact because it can be stored in logs or cause some XSS at another point in the application.

Читать полностью…

Bug bounty chat

Try injecting internal port on Host: header like Host:x.com:1024 or Host:localhost

Читать полностью…

Bug bounty chat

Ideas to bypass Django panel admin authentication?

Читать полностью…

Bug bounty chat

During the testing of a domain, i accidently found its subdomain which was the server page. Where it was mentioning:

Welc9me to nginx!
If you see this page the nginx server is successfully installefld and working.

Now when i try to acces example.com/.htaccess
It gives 403. Even i tried for /%2ehtaccess but still it is blocking. Now what should i try?

Читать полностью…

Bug bounty chat

#bitrix 🚨🚨🚨

Уязвимость модуля landing системы управления содержимым сайтов (CMS) 1С-Битрикс: Управление, позволяющая нарушителю выполнить команды ОС на уязвимом узле, получить контроль над ресурсами и проникнуть во внутреннюю сеть.

Bitrix > 23.850.0
RCE, CVSS 10/10

Удаляем модуль landing, если не используется. Обновляем до версии 23.850.0 и выше, если используется.

BDU:2023-05857

Че, пацаны, анимэ?

Читать полностью…

Bug bounty chat

And in this jason admin directory i get some email ph.no transaction id and bcrypt hashed password but the password can't cracked so can i report that information disclosure or broken access control and another question does it high vulnerability

Читать полностью…

Bug bounty chat

hello guys i am studying bug bounty and networking for 1 year so does hacker1 pay me by finding vulnerabilities or it need exploitation

Читать полностью…
Subscribe to a channel