One more question please, how can I use Burpsuite to detect if my target is vulnerable to sqli?
Читать полностью…Thanks. I was able to use waybackurls.
My question: Any tools to check for sqli and XSS from the urls Please?
nuclei, wfuzz or ffuf for automation content discover. https://github.com/tomnomnom/waybackurls for endpoints from waybackmachine
Читать полностью…also you can try to search endpoints from other subdomains or look in js files in other subdomains
Читать полностью…Hello hunters, how can I get endpoints for a third level domain?
Waymore and gau aren't working
bug.dev.bounty.com
hello hackerone hackers
if you are "Clear/ID verified" can u share how much ((BBP)) invites u have for each category ?
i want to know if it's really worth applying!
u can check from this links:
"ID verified" https://hackerone.com/opportunities/all/search?bbp=true&idv=true
"Clear verified" https://hackerone.com/opportunities/all/search?bbp=true&h1_clear=true
I remembered running sqlmap on request form and it shows that a particular is likely vulnerable to reflective xss
Читать полностью…waybackmachine, google, github (dont forget for gist.github.com), content discovery
Читать полностью…New XSS Bypass Cloudflare WAF 🧱
Payload : %3CSVG/oNlY=1%20ONlOAD=confirm(document.domain)%3E
who wants to befriend and teach me how to find website vulnerabilities and plant backdoor shells
Читать полностью…I'm looking for someone who can hack a website like planting a backdoor shell or shell finder
Читать полностью…