CoderYounes's profile picture.

Deku

@CoderYounes

Pinned

#bugbounty #bugbountytips So, You want to Learn IDOR,SSRF....etc Use this Dork : site: intext:ssrf Kudos to @Alra3ees


Deku reposted

I just made a doc on how you can send 20,000 personalized cold emails to your ideal clients every month by leveraging $3/hr VAs. The Ultimate Cold Email Sauce for Businesses Above $5k/m to book 30+ calls/month. Like, RT & comment "email" & I'll send to you (must be following)

thecodycarnes's tweet image. I just made a doc on how you can send 20,000 personalized cold emails to your ideal clients every month by leveraging $3/hr VAs.

The Ultimate Cold Email Sauce for Businesses Above $5k/m to book 30+ calls/month.

Like, RT & comment "email" & I'll send to you

(must be following)

Deku reposted

Awesome RCE techniques:- Awesome list of techniques to achieve Remote Code Execution (RCE) on various apps! github.com/p0dalirius/Awe…

Alra3ees's tweet image. Awesome RCE techniques:-
Awesome list of techniques to achieve Remote Code Execution (RCE) on various apps!
github.com/p0dalirius/Awe…

Deku reposted

It's happening, I am starting a writeup series, check out the first article about a SSRF finding, many others scheduled to come ;) medium.com/@soufianehabti… #bugbountytips #BugBounty


Deku reposted

GooFuzz - A tool to perform fuzzing with an #OSINT approach, managing to enumerate directories, files, subdomains, or parameters without leaving evidence on the target's server and by means of advanced Google searches (Google Dorking) » github.com/m3n0sd0n4ld/Go… #cybersecurity

Pethuraj's tweet image. GooFuzz - A tool to perform fuzzing with an #OSINT approach, managing to enumerate directories, files, subdomains, or parameters without leaving evidence on the target's server and by means of advanced Google searches (Google Dorking)
» github.com/m3n0sd0n4ld/Go…
#cybersecurity

Deku reposted

New writeup! And some notes on productivity. 🐵 monke.ie/case-study-par…


Deku reposted

Some google dorks for finding sensitive files: intitle:"index of" "WebServers.xml" filetype:xls inurl:"email.xls" intitle:"Index of" wp-admin intitle:"index of" "admin/sql/" intitle:"index of" "system/config" #bugbountytips #infosec #BugBounty #CyberSecurity


Deku reposted

Alert !!! This PoC is fake do not run it. You will get a backdoor 🥲 github.com/rkxxz/CVE-2022…


Unlimited keys worth 89,99$ for certain service leaked in archive.org & google , reported to @Bugcrowd that was the reponse. The fix : re-configure the robots.txt file to block crawlers/spiders from crawli g the keys. Thanks @Bugcrowd

CoderYounes's tweet image. Unlimited keys worth 89,99$ for certain service leaked in archive.org & google , reported to @Bugcrowd that was the reponse.
The fix : re-configure the robots.txt file to block crawlers/spiders from crawli g the keys.
Thanks @Bugcrowd

Deku reposted

I couldn't sleep, so I made a simple, single Nuclei template to detect the Zyxel Unauthenticated Remote Command Injection vulnerability CVE-2022-30525, gist.github.com/z3r0-0t/a3bd4c…

z3r00t's tweet image. I couldn't sleep, so I made a simple, single Nuclei template to detect the Zyxel Unauthenticated Remote Command Injection vulnerability CVE-2022-30525,

gist.github.com/z3r0-0t/a3bd4c…

Deku reposted

If you haven't yet seen, this is how we hacked a BIG bank 😱 . With @infosec_au , We were able to gain RCE on more than 100 different subdomains by exploiting a 0day we discovered. Reported through their #bugbounty program. Enjoy the read! blog.assetnote.io/2022/05/03/hac…

HusseiN98D's tweet image. If you haven't yet seen, this is how we hacked a BIG bank 😱 . With @infosec_au , We were able to gain RCE on more than 100 different subdomains by exploiting a 0day we discovered. Reported through their #bugbounty program. Enjoy the read!

blog.assetnote.io/2022/05/03/hac…

Deku reposted

Some google dork I’m use it to find sign up pages site:example.com inurl:register site: inurl:signup site: inurl:join #bugbountytips #bugbounty #infosec


Deku reposted

Search for all leaked keys/secrets using one regex! regex: gist.github.com/h4x0r-dz/be69c… #BugBounty #bugbountytip

h4x0r_dz's tweet image. Search for all leaked keys/secrets using one regex! 

regex: gist.github.com/h4x0r-dz/be69c…

#BugBounty #bugbountytip

Loading...

Something went wrong.


Something went wrong.