bugbountygroup | Unsorted

Telegram-канал bugbountygroup - Bug bounty chat

3269

Talk and help about bugbounty

Subscribe to a channel

Bug bounty chat

Yeah it was subdomain takeover but got duplicate someone had already reported before me

Читать полностью…

Bug bounty chat

Capture site TCP request

Читать полностью…

Bug bounty chat

Hello
Thank you for accepting the group

Читать полностью…

Bug bounty chat

Who have private program go collabaration

Читать полностью…

Bug bounty chat

The email enum vulnerability is not valid according to their rules stated on the program rules

Читать полностью…

Bug bounty chat

Hey everyone, so I have stumbled upon a kind of a logic bug a while back. Basically, to change the password the app requires a two step verification via email. And the user needs to solve captcha on the front end to submit their email while requesting for a password change to get a reset link on the email.

However, in the backend through burp, I can insert the email without solving the captcha about 20-25 times before getting locked out. Mind you, the app has an email enumeration bug which lets you identify if an email is registered on the app or not.

So, I can insert any user's email as many times as I want to request reset password links and lock the actual user out from resetting their passwords.

Do you think it is a valid security bug?

I'm a bit confused and scared to report because I don't wanna lose reputation by getting flagged as N/A.

Читать полностью…

Bug bounty chat

https://exploit.linuxsec.org/uptimerobot-com-custom-domain-subdomain-takeover/

Читать полностью…

Bug bounty chat

Sendgrid isn’t vulnerable

Читать полностью…

Bug bounty chat

I sell db with 200k rows

Читать полностью…

Bug bounty chat

hey i've found 2 subdomains that are reflecting subdomain takeover vulnerablity can anyone help me to confirm this vulnerability

Читать полностью…

Bug bounty chat

is anyone good with cookies/jwt?

Читать полностью…

Bug bounty chat

AMAZING bookmark trick

Читать полностью…

Bug bounty chat

I'm looking for the apk that are used by scammers to hack people and steal otp.. wana reverse engineer it.. does someone have a latest app that a scammer sent them

Читать полностью…

Bug bounty chat

https://level-level.com/wp-login.php?redirect_to=https%3A%2F%2Flevel-level.com%2Fwp-admin%2F&reauth=1

Читать полностью…

Bug bounty chat

Start from basics of network and its concepts. There are few fundamentals to learn

Читать полностью…

Bug bounty chat

https://www.youtube.com/watch?v=hHLCfTm8TN8

Читать полностью…

Bug bounty chat

How to capture the https username and password using wireshark tool

Читать полностью…

Bug bounty chat

fuzzing ke liye wordlists send karo koi plz

Читать полностью…

Bug bounty chat

https://github.com/Vulnpire/Reclaim

Читать полностью…

Bug bounty chat

yeah report the username enum vulnerability

Читать полностью…

Bug bounty chat

ok bro now verifying it

Читать полностью…

Bug bounty chat

uptimerbot is vulnerable

Читать полностью…

Bug bounty chat

and other one is uptimerobot

Читать полностью…

Bug bounty chat

share poc to check and confirm

Читать полностью…

Bug bounty chat

Yes I can help with jwt

Читать полностью…

Bug bounty chat

hello, can anyone help me with a bug on a site?

Читать полностью…

Bug bounty chat

https://www.youtube.com/watch?v=X64c_-dh3rs

Читать полностью…

Bug bounty chat

Is there any way I can bypass this admin login by SQL injection or any other methods?

Читать полностью…

Bug bounty chat

https://pauljerimy.com/security-certification-roadmap/

Читать полностью…

Bug bounty chat

Hi everyone, I’m an 18 year old, just got into computer science, and I’m really passionate about finding loopholes, bugs in websites and applications, software systems, jailbreaking. I’ve got knowledge in coding. I was hoping you guys could suggest material to learn as a start, pdfs, books, YouTube videos white hacker 101, stuff like that, everything much appreciated.

Читать полностью…
Subscribe to a channel