
I¯\_(ツ)_/¯I \ (•◡•) /
@BountyOverflow
BBH ( ͡° ͜ʖ ͡°) 💰 @Bugcrowd Top 50 \o/ ✌️ MVP✌️ I am here to learn/share application security stuff ✌️ I enjoy finding auth bypass bugs 🐞
Вам может понравиться
What a great month it was July 2022! I have ranked #2 world wide on @Bugcrowd bugcrowd.com/leaderboard

Why to use a simple #XSS vector like this 🤔 <img src=x onerror=alert(1)> when you can use a much better one? 🤩 1'//"</Script><Img/Src%0AOnError=alert(1)// The vector above pops in HTML and JS scenarios for single and double quotes! 🤯 Try it here: x55.is/brutelogic/xss…
New Rhino Blog Post: CVE-2025-0693: AWS IAM User Enumeration bit.ly/3QcEpnx
blog.cloudflare.com/resolving-a-mu… I don’t work there anymore but it’s truly so sick seeing this level of weird bug being patched so fast Hell yeah
Thanks to the recent @PortSwigger top 10, I finally found the motivation to finish writing the 2nd article about DOMPurify security! 😁 Before releasing it, I would like to share a small challenge 🚩 Challenge link 👇 challenges.mizu.re/xss_04.html 1/2

Unleashing The Power of a JavaScript Bookmarklet for Endpoint Discovery in Bug Bounty and… execure.medium.com/unleashing-the…
Seems rennie deleted his twitter so original post is gone :/ but someone made a post about it here with the code: execure.medium.com/unleashing-the…
Got a CSRF attack being blocked by Content-Type validation? You might be able to bypass it with this quality technique. x.com/lukejahnke/sta…
🧵Can you work out how to bypass this vulnerable CSRF protection? Read all about this gotcha in my latest blog post

After a 4-month break, I’m backon @Bugcrowd ! Life kept me busy with something truly special—welcoming my adorable daughter into the world. 🍼💕 Feeling so blessed! 🥰

There is a public website with the following folder path: txyz.com/wp-content/upl…<filename> Does anyone know of any tricks for WordPress websites that would allow me to list all files and folders in the 'uploads' directory? #thanks-in-adv
I was facing a very strict WAF while trying to exploit a XSS : no gt/lt signs, no parentheses, no double quotes, no backticks. I was injecting inside an html tag. Turns out the solution was very simple (and not well documented): <img src=x onerror=alert(document.domain)>

🚨Alert🚨CVE-2024-30103: Microsoft Outlook Remote Code Execution Vulnerability ⚠This Microsoft Outlook vulnerability can be circulated from user to user and doesn’t require a click to execute. Rather, execution initiates when an affected email is opened.This is notably dangerous…

INTRODUCING: Agentic Security - LLM Security Scanner! 🔍 🛠️ Customizable Rule Sets: Tackle agent-based attacks with precision! 🧪 Comprehensive Fuzzing: Dive deep into any LLM's vulnerabilities! 🔄 LLM API Integration & Stress Testing: Ensure robust performance!
Indeed, for me aswell ! Thanks @Bugcrowd from my bottom of the heart ❤️!
I <3 @Bugcrowd and everyone that worked to make it so good. Definitely improved my life overall.
When it comes to GraphQL recon, JavaScript is the next best thing to introspection. I made a tool (in go) which finds all graphql queries in js files (or folders) and uses ChatGPT to build the queries for you! github.com/xssdoctor/grap…
.@insiderPhD's 4 must have Burp Suite extensions:

A Day in the Life of an Unemployed Bug Hunter
United States Тренды
- 1. Bengals 32.1K posts
- 2. Ace Frehley 55.4K posts
- 3. Aaron Rodgers 12.1K posts
- 4. #911onABC 10.2K posts
- 5. Chase Brown 2,777 posts
- 6. Cuomo 43.9K posts
- 7. Bolton 159K posts
- 8. #HereWeGo 6,055 posts
- 9. Mookie 5,669 posts
- 10. Asheville 10.7K posts
- 11. #TNFonPrime 2,091 posts
- 12. RIP Spaceman 1,894 posts
- 13. Yoshi 20.4K posts
- 14. athena 11.6K posts
- 15. Sliwa 18K posts
- 16. #NYCMayoralDebate N/A
- 17. Glasnow 3,960 posts
- 18. Space Ace 2,096 posts
- 19. #PITvsCIN 1,643 posts
- 20. New York Groove N/A
Вам может понравиться
-
Youssef Sammouda (sam0)
@samm0uda -
The Bug Bounty Hunter
@tbbhunter -
𝐑𝐀𝐢𝐡𝐚𝐧 ✪
@zapstiko -
Hussein Daher
@HusseiN98D -
payloadartist
@payloadartist -
MorningStar
@0xMstar -
Julien | MrTuxracer 🇪🇺
@MrTuxracer -
Lu3ky13 ⚡️⚡️
@lu3ky13 -
todayisnew
@codecancare -
🇸🇦 Murtada Bin Abdullah (Rood)
@0x_rood -
Nagli
@galnagli -
Hazem
@_bughunter -
Ahsan Khan
@hunter0x7 -
Mahmoud Hamed
@7odamoo -
Ali Tütüncü
@alicanact60
Something went wrong.
Something went wrong.