Talk and help about bugbounty
I found a Zendesk api key and applicationID can anyone sugguest me what should i do further escalation to a bounty
Читать полностью…i found the keys of a target i'm walking through with google dorking how can i escalate this a get a bounty.....
Читать полностью…Yep. Considering that’s what you’re doing first. Not sure if that was done. Just basing it off of the fact of running zap
Читать полностью…See if you can pivot or use it to affect domains in scope
Читать полностью…Ya if you done with your Manual testing you can run automated tool
Читать полностью…Automated testing and tools are not preferable because they show false positive and are not capable of finding business logic bug or any critical bug in most of the case
Читать полностью…And like other said. It will be unpaid. There’s a reason they probably don’t pay it. The reason, who knows. That’s their fault.
Читать полностью…Anyone interested in OSCP , GPEN , OSWE , OSCE , Pentest+ , CEH certification ?
Читать полностью…Nope. If in bb programm it is out-of-scope, high risk that your vuln will be unpaid
Читать полностью…Can anyone explain me this bug Insecure OS/Firmware > Hardcoded Password > Non-Privileged User
Читать полностью…True that’s why I mentioned replicating the issue. Owasp is known to show % of false positive in its report, but obviously, always preferable to run a replication as part of your QA
Читать полностью…You can report it if it's directly or indirectly linking to in scope domain or server
Читать полностью…I say don’t do it. If it’s out of scope they are going to ask how you even found it and sometimes they get sensitive about it.
Читать полностью…i think it depends on company, i would recommend to check if there was similar reports or if company actually paid for out of scope issues before.
Читать полностью…Guys i found a severe vulnerable but it's out of scope should i report it the vuln is opening admin panel and full control of the subdomain and server's files
Читать полностью…well that’s sad but still gives no right to actually exploit it 😔
Читать полностью…nah it’s type of playing stupid games winning stupid prizes if you really order something off of them. The consequences might be really dire. If I were in your shoes, I’d rather go report it again 😌
Читать полностью…