Talk and help about bugbounty
I already show tham but ...then do not reply on that
Читать полностью…This is not a bug we tunneling the dns to another domain I'm reported atleast 5 websites for these bug but everyone says it's not a bug 😂😂😂
Читать полностью…It is not as easy as you think, you will have to study the subject well since it depends on many things, the Portwigger JWT labs are very complete 100% recommended https://portswigger.net/web-security/jwt
Читать полностью…If the base url is at the website then u add the evil.com and takes u there then yes
Читать полностью…Can anyone help me with a bug bounty? I know there is a bug in the site
Читать полностью…Hello guys I found password reset token not expired after changing email leads to account take over but when I report this vulnerability in bugcrowd they give me response p5???
Читать полностью…hello i found an api key on github in jenkinsfile but its internal i can't able to validate it so should i report it or not
Читать полностью…Hi everyone, please who can help with dorks that I need in hunting,
To aid my bug bounty hunting journey 🥹
It not redirecting any meaningful data, and there are not individual session token attached to it, so it does nothing
Читать полностью…If the url ue testing directs u ti evil.com and u see evil.com then yes
Читать полностью…Hi guys, I'm new to this field of bug bounty.
Please I have a question,
Adding "@another URL" at the end of a URL to redirect it, can we regard this as a vulnerability
e.g. https://example.com@evil.com
Can this be report as open URL redirection?
What a joke bro , if anyone have private key then, they can easily account takeover of anybody .
Читать полностью…