thebugbountyhunter | Unsorted

Telegram-канал thebugbountyhunter - The Bug Bounty Hunter

43961

Happy hunting! thebugbountyhunter.com hello@thebugbountyhunter.com

Subscribe to a channel

The Bug Bounty Hunter

Cursed tapes: Exploiting the EvilVideo vulnerability on Telegram for Android

https://www.welivesecurity.com/en/eset-research/cursed-tapes-exploiting-evilvideo-vulnerability-telegram-android/

Читать полностью…

The Bug Bounty Hunter

3 ways to get Remote Code Execution in Kafka UI

https://github.blog/2024-07-22-3-ways-to-get-remote-code-execution-in-kafka-ui/

Читать полностью…

The Bug Bounty Hunter

WhatsUp Gold Pre-Auth RCE GetFileWithoutZip Primitive

https://summoning.team/blog/progress-whatsup-gold-rce-cve-2024-4885

Читать полностью…

The Bug Bounty Hunter

Exploiting the EvilVideo vulnerability on Telegram
Discovered a 0-day Telegram for Android exploit that allows sending malicious apps disguised as videos
https://www.welivesecurity.com/en/eset-research/cursed-tapes-exploiting-evilvideo-vulnerability-telegram-android/

Читать полностью…

The Bug Bounty Hunter

Discovering an XML File Upload Vulnerability Lead to SSRF: My Bug Hunting Journey

javroot/discovering-an-xml-file-upload-vulnerability-lead-to-ssrf-my-bug-hunting-journey-8e1bac89f60f" rel="nofollow">https://medium.com/@javroot/discovering-an-xml-file-upload-vulnerability-lead-to-ssrf-my-bug-hunting-journey-8e1bac89f60f

Читать полностью…

The Bug Bounty Hunter

I Created a Burp Suite Extension from SCRATCH

https://www.youtube.com/watch?v=9yXQ2UXfH4E

Читать полностью…

The Bug Bounty Hunter

Live Recon: Hacking A Real Company

https://www.youtube.com/watch?v=qlSAaqsBbY8

Читать полностью…

The Bug Bounty Hunter

Bug Bounty Mental - Practical Tips for Staying Sharp & Motivated (Ep.77)

https://www.youtube.com/watch?v=9s0mX1KB-90

Читать полностью…

The Bug Bounty Hunter

L'Oréal x YesWeHack: Live Bug Bounty event at LeHack 2024

https://www.youtube.com/watch?v=wVSZ5lCDyr4

Читать полностью…

The Bug Bounty Hunter

APKscan: Scan for secrets, endpoints, API keys, tokens, credentials in Android apps
https://github.com/LucasFaudman/apkscan

Читать полностью…

The Bug Bounty Hunter

Community-driven PTaaS vs. Automated Pentesting

https://www.hackerone.com/penetration-testing/ptaas-vs-automated-pentesting

Читать полностью…

The Bug Bounty Hunter

XenForo <= 2.2.15 (Widget::actionSave) Cross-Site Request Forgery Vulnerability | Karma(In)Security


https://karmainsecurity.com/KIS-2024-05

Читать полностью…

The Bug Bounty Hunter

Indirect Prompt Injection

https://www.youtube.com/watch?v=sHs8OZEFrAc

Читать полностью…

The Bug Bounty Hunter

GitHub - exploits-forsale/collateral-damage: Kernel exploit for Xbox SystemOS using CVE-2024-30088

https://github.com/exploits-forsale/collateral-damage

Читать полностью…

The Bug Bounty Hunter

What Is a Vulnerability Disclosure Program and Do You Need One?

https://www.hackerone.com/vulnerability-disclosure/what-vulnerability-disclosure-program-and-do-you-need-one

Читать полностью…

The Bug Bounty Hunter

You Can't Spell WebRTC without RCE - Part 1

https://margin.re/2024/07/you-cant-spell-webrtc-without-rce-part-1/

Читать полностью…

The Bug Bounty Hunter

SAPwned: SAP AI vulnerabilities expose customers’ cloud environments and private AI artifacts | Wiz Blog

https://www.wiz.io/blog/sapwned-sap-ai-vulnerabilities-ai-security

Читать полностью…

The Bug Bounty Hunter

Hacking a 2014 tablet... in 2024!
https://blog.r0rt1z2.com/hacking-a-2014-tablet-in-2024.html

Читать полностью…

The Bug Bounty Hunter

How Hackers Help Jedox Secure Cloud Assets and Stay One Step Ahead

https://www.hackerone.com/customer-stories/how-hackers-help-jedox-secure-cloud-assets-and-stay-one-step-ahead

Читать полностью…

The Bug Bounty Hunter

1000$ IDOR : Unauthorized Project Inclusion in Expense

a13h1/1000-idor-unauthorized-project-inclusion-in-expense-b9ce08b28c71" rel="nofollow">https://medium.com/@a13h1/1000-idor-unauthorized-project-inclusion-in-expense-b9ce08b28c71

Читать полностью…

The Bug Bounty Hunter

Electron JS ASAR Integrity Bypass

https://blog.souravkalal.tech/electron-js-asar-integrity-bypass-431ac4269ed5

Читать полностью…

The Bug Bounty Hunter

Winning Together Through Synergy and Vulnerabilities

https://www.hackerone.com/engineering/winning-together-synergy-vulnerabilities

Читать полностью…

The Bug Bounty Hunter

How I Hacked the Dutch Government: Exploiting an Innocent Image for Remote Code Execution

mukundbhuva/how-i-hacked-the-dutch-government-exploiting-an-innocent-image-for-remote-code-execution-df1fa936e46a" rel="nofollow">https://medium.com/@mukundbhuva/how-i-hacked-the-dutch-government-exploiting-an-innocent-image-for-remote-code-execution-df1fa936e46a

Читать полностью…

The Bug Bounty Hunter

Latest Nuclei Release v3.3.0!

https://github.com/projectdiscovery/nuclei/releases/tag/v3.3.0

Читать полностью…

The Bug Bounty Hunter

How to Bypass Golang SSL Verification

https://www.cyberark.com/resources/threat-research-blog/how-to-bypass-golang-ssl-verification

Читать полностью…

The Bug Bounty Hunter

Find XSS on the Fly 🔥( Full guide )

zack0x01_/find-xss-on-the-fly-full-guide-300f07fb86ae" rel="nofollow">https://medium.com/@zack0x01_/find-xss-on-the-fly-full-guide-300f07fb86ae

Читать полностью…

The Bug Bounty Hunter

Pwn2Own: Pivoting from WAN to LAN to Attack a Synology BC500 IP Camera, Part 2

https://claroty.com/team82/research/pivoting-from-wan-to-lan-synology-bc500-ip-camera

Читать полностью…

The Bug Bounty Hunter

XBOW finds and exploits vulnerabilities in 75% of 647 renowned web benchmarks. Given a short description of the benchmark, it autonomously pursues high-level goals, executing commands and interpreting their output to achieve exploitation.

https://x.com/Xbow/status/1812853046956962065

Читать полностью…

The Bug Bounty Hunter

Android & iOS mobile security cheatsheets
https://github.com/justmobilesec/Android-iOS-Cheat-Sheet/

Читать полностью…

The Bug Bounty Hunter

How Ethical Hackers Are Securing Elections

https://www.hackerone.com/ethical-hacker/election-security

Читать полностью…
Subscribe to a channel