bugbountygroup | Unsorted

Telegram-канал bugbountygroup - Bug bounty chat

3264

Talk and help about bugbounty

Subscribe to a channel

Bug bounty chat

I found a Zendesk api key and applicationID can anyone sugguest me what should i do further escalation to a bounty

Читать полностью…

Bug bounty chat

the public root keys and the encryption algo

Читать полностью…

Bug bounty chat

i found the keys of a target i'm walking through with google dorking how can i escalate this a get a bounty.....

Читать полностью…

Bug bounty chat

I use burp ofcourse but i also use Fiddler

Читать полностью…

Bug bounty chat

It feels like it's out of date

Читать полностью…

Bug bounty chat

Yep. Considering that’s what you’re doing first. Not sure if that was done. Just basing it off of the fact of running zap

Читать полностью…

Bug bounty chat

See if you can pivot or use it to affect domains in scope

Читать полностью…

Bug bounty chat

Ya if you done with your Manual testing you can run automated tool

Читать полностью…

Bug bounty chat

Automated testing and tools are not preferable because they show false positive and are not capable of finding business logic bug or any critical bug in most of the case

Читать полностью…

Bug bounty chat

And like other said. It will be unpaid. There’s a reason they probably don’t pay it. The reason, who knows. That’s their fault.

Читать полностью…

Bug bounty chat

Anyone interested in OSCP , GPEN , OSWE , OSCE , Pentest+ , CEH certification ?

Читать полностью…

Bug bounty chat

Nope. If in bb programm it is out-of-scope, high risk that your vuln will be unpaid

Читать полностью…

Bug bounty chat

yes. otherwise its a valid bug

Читать полностью…

Bug bounty chat

i reported it 5 times they did not response

Читать полностью…

Bug bounty chat

quantity tampering easy to find

Читать полностью…

Bug bounty chat

also the signature keys

Читать полностью…

Bug bounty chat

lie password of admin panel or user ?

Читать полностью…

Bug bounty chat

hey guys im a noob here

Читать полностью…

Bug bounty chat

Can anyone explain me this bug Insecure OS/Firmware > Hardcoded Password > Non-Privileged User

Читать полностью…

Bug bounty chat

But zap is a noisy tool

Читать полностью…

Bug bounty chat

Especially IDOR and SDE

Читать полностью…

Bug bounty chat

Nice idea bro i will test it

Читать полностью…

Bug bounty chat

True that’s why I mentioned replicating the issue. Owasp is known to show % of false positive in its report, but obviously, always preferable to run a replication as part of your QA

Читать полностью…

Bug bounty chat

You can report it if it's directly or indirectly linking to in scope domain or server

Читать полностью…

Bug bounty chat

I say don’t do it. If it’s out of scope they are going to ask how you even found it and sometimes they get sensitive about it.

Читать полностью…

Bug bounty chat

i think it depends on company, i would recommend to check if there was similar reports or if company actually paid for out of scope issues before.

Читать полностью…

Bug bounty chat

Guys i found a severe vulnerable but it's out of scope should i report it the vuln is opening admin panel and full control of the subdomain and server's files

Читать полностью…

Bug bounty chat

well that’s sad but still gives no right to actually exploit it 😔

Читать полностью…

Bug bounty chat

nah it’s type of playing stupid games winning stupid prizes if you really order something off of them. The consequences might be really dire. If I were in your shoes, I’d rather go report it again 😌

Читать полностью…

Bug bounty chat

yes do you want to try?

Читать полностью…
Subscribe to a channel