bugbountygroup | Unsorted

Telegram-канал bugbountygroup - Bug bounty chat

3264

Talk and help about bugbounty

Subscribe to a channel

Bug bounty chat

Hloo... anyone there here...???

Читать полностью…

Bug bounty chat

😝 now days bg. 1st trigger then N/A 😅

Читать полностью…

Bug bounty chat

Deep recon means finding the subdomains of subdomains like finding 5 th level subdomains or finding deeper level endpoints ,parameters, files and directories ?

Читать полностью…

Bug bounty chat

Bonjour
Merci pour l’acceptation
Qui parle Français dans ce groupe ?
J’ai besoin d’aide

Читать полностью…

Bug bounty chat

Keep enhancing yourself and knowledge

Читать полностью…

Bug bounty chat

What did you learned

Читать полностью…

Bug bounty chat

What's your plan for today?

Читать полностью…

Bug bounty chat

https://youtu.be/RuTadZiYn1U

Читать полностью…

Bug bounty chat

Better luck next time

Читать полностью…

Bug bounty chat

Yeah it was subdomain takeover but got duplicate someone had already reported before me

Читать полностью…

Bug bounty chat

Capture site TCP request

Читать полностью…

Bug bounty chat

Hello
Thank you for accepting the group

Читать полностью…

Bug bounty chat

Who have private program go collabaration

Читать полностью…

Bug bounty chat

The email enum vulnerability is not valid according to their rules stated on the program rules

Читать полностью…

Bug bounty chat

Hey everyone, so I have stumbled upon a kind of a logic bug a while back. Basically, to change the password the app requires a two step verification via email. And the user needs to solve captcha on the front end to submit their email while requesting for a password change to get a reset link on the email.

However, in the backend through burp, I can insert the email without solving the captcha about 20-25 times before getting locked out. Mind you, the app has an email enumeration bug which lets you identify if an email is registered on the app or not.

So, I can insert any user's email as many times as I want to request reset password links and lock the actual user out from resetting their passwords.

Do you think it is a valid security bug?

I'm a bit confused and scared to report because I don't wanna lose reputation by getting flagged as N/A.

Читать полностью…

Bug bounty chat

Any advice to get my first bug?

Читать полностью…

Bug bounty chat

endpoints,parameters all those are right but idk whats 5th level subdomains, . . . new to me

Читать полностью…

Bug bounty chat

Success begins with the decision to try.

Читать полностью…

Bug bounty chat

Hey does anyone here know how to escalate csrf vulnerability on logout endpoint to any other impact

Читать полностью…

Bug bounty chat

Hunting and learning

Читать полностью…

Bug bounty chat

I'm glad I learned a lot here!

Читать полностью…

Bug bounty chat

https://infosecwriteups.com/stored-xss-to-admin-in-unauthenticated-wordpress-cb76bae66623

Читать полностью…

Bug bounty chat

Hello, it would be a pleasure, could you help me solve the following laboratory?
thanks --> https://xss-labs.abay.sh/xss/6.php

Читать полностью…

Bug bounty chat

Actually it was hosted amazon elb

Читать полностью…

Bug bounty chat

https://www.youtube.com/watch?v=hHLCfTm8TN8

Читать полностью…

Bug bounty chat

How to capture the https username and password using wireshark tool

Читать полностью…

Bug bounty chat

fuzzing ke liye wordlists send karo koi plz

Читать полностью…

Bug bounty chat

https://github.com/Vulnpire/Reclaim

Читать полностью…

Bug bounty chat

yeah report the username enum vulnerability

Читать полностью…

Bug bounty chat

ok bro now verifying it

Читать полностью…
Subscribe to a channel