Sn1per is also good option as it does all the work on its own!
You just have to have all the tools required for it
One more question please, how can I use Burpsuite to detect if my target is vulnerable to sqli?
Читать полностью…Thanks. I was able to use waybackurls.
My question: Any tools to check for sqli and XSS from the urls Please?
nuclei, wfuzz or ffuf for automation content discover. https://github.com/tomnomnom/waybackurls for endpoints from waybackmachine
Читать полностью…also you can try to search endpoints from other subdomains or look in js files in other subdomains
Читать полностью…Hello hunters, how can I get endpoints for a third level domain?
Waymore and gau aren't working
bug.dev.bounty.com
hello hackerone hackers
if you are "Clear/ID verified" can u share how much ((BBP)) invites u have for each category ?
i want to know if it's really worth applying!
u can check from this links:
"ID verified" https://hackerone.com/opportunities/all/search?bbp=true&idv=true
"Clear verified" https://hackerone.com/opportunities/all/search?bbp=true&h1_clear=true
I remembered running sqlmap on request form and it shows that a particular is likely vulnerable to reflective xss
Читать полностью…waybackmachine, google, github (dont forget for gist.github.com), content discovery
Читать полностью…New XSS Bypass Cloudflare WAF 🧱
Payload : %3CSVG/oNlY=1%20ONlOAD=confirm(document.domain)%3E
who wants to befriend and teach me how to find website vulnerabilities and plant backdoor shells
Читать полностью…I'm looking for someone who can hack a website like planting a backdoor shell or shell finder
Читать полностью…