EthicalhackerC's profile picture. Bug bounty hunter

Anouar Youcef

@EthicalhackerC

Bug bounty hunter

Anouar Youcef repostou

cat domains.txt | waybackurls | grep ".js" | grep -v ".json" | sort -u | anew js_files.txt Sometimes the above result won't be enough, so i go after scanning "js_files.txt" for more URLs using "gf" ( this takes time, sometimes ) - cat js_files.txt | gf urls | anew urls.txt…

bro how u gather js file as much as .?



Anouar Youcef repostou

Admin Panel Access Scenario I Found • During recon I found a domain with an empty main page • Port scan showed 1950 open • Visiting example.com:1950 revealed an admin login • Default creds worked and gave full admin access #CyberSecurity #BugBounty #bugbountytips

mooo_sec's tweet image. Admin Panel Access Scenario I Found

• During recon I found a domain with an empty main page
• Port scan showed 1950 open
• Visiting example.com:1950 revealed an admin login
• Default creds worked and gave full admin access

#CyberSecurity #BugBounty #bugbountytips
mooo_sec's tweet image. Admin Panel Access Scenario I Found

• During recon I found a domain with an empty main page
• Port scan showed 1950 open
• Visiting example.com:1950 revealed an admin login
• Default creds worked and gave full admin access

#CyberSecurity #BugBounty #bugbountytips
mooo_sec's tweet image. Admin Panel Access Scenario I Found

• During recon I found a domain with an empty main page
• Port scan showed 1950 open
• Visiting example.com:1950 revealed an admin login
• Default creds worked and gave full admin access

#CyberSecurity #BugBounty #bugbountytips

Anouar Youcef repostou

#bugbountytips ❌ Stop Doing These 10 Bug Hunting Mistakes ... And revise your methodology if : 1. You spend 2 days or less per program 2. You run automated tools on each URL and wait for unique results 3. You don't scan servers' open ports 4. You don't register an account in…

silentgh00st's tweet image. #bugbountytips 
❌ Stop Doing These 10 Bug Hunting Mistakes ... 
And revise your methodology if :

1. You spend 2 days or less per program
2. You run automated tools on each URL and wait for unique results
3. You don't scan servers' open ports
4. You don't register an account in…

Anouar Youcef repostou

10 powerful new AI tools you cannot miss: 1. Rose.ai - Research faster 2. Humata.ai - ChatGPT for your files 3. Perplexity.ai - ChatGPT on steroids 4. Durable.co - Build websites with AI 5. Stockimg.ai - Create…


Anouar Youcef repostou
lauriewired's tweet image.

Anouar Youcef repostou

As a bug hunter, you burn a lot of energy every day. That’s why it’s important to check in on your mental health regularly. Take a self-review each month. If you’re feeling tired or drained, step back and rest for a few days. Don’t let yourself slide into burnout, it’s brutal!


Anouar Youcef repostou

A lot of bug bounty beginners just need someone to tell them to keep going


Anouar Youcef repostou

Stuck In Bug Hunting? Don’t Know Where To Go Now? Don’t Worry More. I Got You! medium.com/great-hackers-… #bugbounty #bugbountytips #bugbountytip


Anouar Youcef repostou

People starting their journey in cyber security look up and turn to the community. If you could give one piece of advice to someone starting out in cyber today... What would it be? 🤔 🚀 Drop your tips in the comments!


Anouar Youcef repostou

4 Ways to bypass checkout systems in e-commerce targets! 🤑 A thread! 🧵 👇

intigriti's tweet image. 4 Ways to bypass checkout systems in e-commerce targets! 🤑

A thread! 🧵 👇

Anouar Youcef repostou

if you start today, I swear you will win in 2026. Just trust yourself, lock in everyday and do these, - read solodit reports - write code (Solidity, Rust, move) - do contest - do bug bounty Make mistakes, do it nasty. Do it badly. Do not care about perfection.


Anouar Youcef repostou

Understanding API key leaks bughunters.google.com/learn/invalid-…


Anouar Youcef repostou

self-doubt is such an odd thing. I've been doing bug bounties actively for a decade and I still struggle with the idea I may be coming to the "end of the road" in regards to finding new bugs that pay well.


Anouar Youcef repostou

You can’t be into cybersecurity and hate research ! DON’T BE LAZY DON’T BE LAZY DON’T BE LAZY DON’T BE LAZY DON’T BE LAZY DON’T BE LAZY DON’T BE LAZY DON’T BE LAZY DON’T BE LAZY DON’T BE LAZY DON’T BE LAZY DON’T BE LAZY


Anouar Youcef repostou

I just submitted 20 Bugs within 1 month to one single program. They paid me for 13 bugs & then the Company Shut down their program! 😒🧑‍💻💔 Lesson I learned: Never report too many bugs too quickly on Self-hosted. GO SLOW.. #bugbountytips for all Self-Hosted Hunter!

Joyerz5's tweet image. I just submitted 20 Bugs within 1 month to one single program. 

They paid me for 13 bugs & then the Company Shut down their program! 😒🧑‍💻💔

Lesson I learned: Never report too many bugs too quickly on Self-hosted. GO SLOW..

#bugbountytips for all Self-Hosted Hunter!

Anouar Youcef repostou

Hidden or disabled fields are commonly overlooked, but they can still open the door to some cool bugs. Try creating a bookmarklet to instantly reveal these fields. Here are some quick examples you can copy and paste: 🔖 Enable all disabled or readonly fields:…


Loading...

Something went wrong.


Something went wrong.