bugbountygroup | Unsorted

Telegram-канал bugbountygroup - Bug bounty chat

3186

Talk and help about bugbounty

Subscribe to a channel

Bug bounty chat

I can send thousands of emails using a password reset endpoint of a private bug bounty program. There's also authentication bypass (I can register with any email I do not own e.g. elon@tesla.com).
It is usually a p2 since I wrote an exploit, I can use it as a mass scale attack. But they give it a p5 lol I really hate this

Читать полностью…

Bug bounty chat

👾Mastering Exploit Development & Metasploit – A Step-by-Step Guide👾

Читать полностью…

Bug bounty chat

Hello hello,

I published new bug bounty writeup. Have a read. Please share and clap.

https://vijetareigns.medium.com/email-and-home-address-disclosure-using-unauthenticated-api-endpoint-worth-500-4a497ff0678c

Читать полностью…

Bug bounty chat

Hey, so I have found a vulnerability on a website from HackerOne. The webapp basically helps its users to transfer crypto currency from one place to another.
The vulnerability allows a low level user on the team to view the crypto wallet addresses which were added by the admin of the team. Also, the vulnerability leaks billing details(PII-full name, street address, zip code, city etc.) of the admin in the same http response.

I reported the bug with a clear PoC. But the H1 triager closed this as an informative saying that there is no significant security impact of this bug.

It just went over my head that how exposing wallet addresses along with PII of an admin does not pose security impact. I am really stunned.

Can someone suggest me what should I do in this situation?

Читать полностью…

Bug bounty chat

Can someone help me?

Читать полностью…

Bug bounty chat

https://mega.nz/folder/96AhRazA#Qci5-I29JIQobl4btJ7w0g

Читать полностью…

Bug bounty chat

https://www.pluralsight.com/courses/advanced-web-application-penetration-testing-burp-suite

Читать полностью…

Bug bounty chat

With cracked burp suite

Читать полностью…

Bug bounty chat

Nahamsec course are not bad in udmey

Читать полностью…

Bug bounty chat

anyone know sitecore api key exploit?

Читать полностью…

Bug bounty chat

https://vijetareigns.medium.com/pii-disclosure-worth-750-758b72e7e8ca

Читать полностью…

Bug bounty chat

My mind is overcooked 😅

Читать полностью…

Bug bounty chat

Good book for starting bug bounty
I have experience in development

Читать полностью…

Bug bounty chat

https://www.linkedin.com/posts/abdullah-parvez-95a8a926b_qoumi30dayschallange-linux-cybersecurity-activity-7269160563073531904-7KKH?utm_source=share&utm_medium=member_android

Читать полностью…

Bug bounty chat

Please clap and share.

Читать полностью…

Bug bounty chat

Well this is privacy violation 😅
I also found similar things but they closed it as informative and they fixed it after closing it 😆 toxicity of bug bounty

Читать полностью…

Bug bounty chat

https://www.linkedin.com/posts/abdullah-parvez-95a8a926b_exploit-development-and-metasploit-activity-7272499074627461121-cLry?utm_source=share&utm_medium=member_android

Читать полностью…

Bug bounty chat

P.S. the wallet addresses and the PII are hidden from the low level users on the frontend.

Читать полностью…

Bug bounty chat

Dm me for free bug site

Читать полностью…

Bug bounty chat

Thank you brother ❤️

Читать полностью…

Bug bounty chat

https://mega.nz/folder/96AhRazA#Qci5-I29JIQobl4btJ7w0g

Читать полностью…

Bug bounty chat

Anyone using hackerone please message me.

Читать полностью…

Bug bounty chat

I have 3 bug bounty course

Читать полностью…

Bug bounty chat

I want bug bounty course

Читать полностью…

Bug bounty chat

https://www.linkedin.com/posts/abdullah-parvez-95a8a926b_qoumi30dayschallange-cybersecurity-wireshark-activity-7270658949559787521-QV8o?utm_source=share&utm_medium=member_android

Читать полностью…

Bug bounty chat

https://www.linkedin.com/posts/abdullah-parvez-95a8a926b_qoumi30dayschallange-networkingbasics-tcpvsudp-activity-7270274879935905794-qrz6?utm_source=share&utm_medium=member_android

Читать полностью…

Bug bounty chat

Burp suite academy, it's a website

Читать полностью…

Bug bounty chat

https://vijetareigns.medium.com/how-automation-detected-default-admin-credential-worth-500-d6c09719d307

Читать полностью…

Bug bounty chat

Dm to get free sureship tampering site

Читать полностью…

Bug bounty chat

Hello guys,
I just released a new Bugbounty writeup.

https://vijetareigns.medium.com/delete-account-functionality-helped-me-earn-250-21baa23c4034

Читать полностью…
Subscribe to a channel