Moonlaunchfun's profile picture. BLH by @shamim_12__

Chilllz

@Moonlaunchfun

BLH by @shamim_12__

Trying something new youtu.be/uYYpK1j4ZFM?si… Any help would be appreciated 👍 Hoping for positive response


Chilllz reposted

Exciting start to 2024! 🚀 Just rejoined HackerOne and already made an impact - reported 5 vulnerabilities in the last 12 hours, with 3 already triaged! 💻 On a mission to hit that 500 rep points milestone, currently standing at 222 #BugBounty #bugbountytips #bugbountytip

Razeditz_12's tweet image. Exciting start to 2024! 🚀 Just rejoined HackerOne and already made an impact - reported 5 vulnerabilities in the last 12 hours, with 3 already triaged! 💻 On a mission to hit that 500 rep points milestone, currently standing at 222 #BugBounty #bugbountytips #bugbountytip ✨

Source code disclosure due to publicly available .git endpoint | P1 vulnerability Always check for endpoints related to /.git #bugbountytips #bugbounty #bugbountytip

Razeditz_12's tweet image. Source code disclosure due to publicly available .git endpoint | P1 vulnerability 
Always check for endpoints related to /.git
#bugbountytips #bugbounty #bugbountytip


Chilllz reposted

Source code disclosure due to publicly available .git endpoint | P1 vulnerability Always check for endpoints related to /.git #bugbountytips #bugbounty #bugbountytip

Razeditz_12's tweet image. Source code disclosure due to publicly available .git endpoint | P1 vulnerability 
Always check for endpoints related to /.git
#bugbountytips #bugbounty #bugbountytip

Chilllz reposted

If we get a Subdomain takeover here i am open to split bounty --> DM #infosecurity #bugbountyhelp #bugbountytips #bugbountytip #bugbountypoc


Chilllz reposted

The SubOver tool says "Takeover Possible At" and when I visit "can-i-take-over-xyz" repo I see that takeover is possible when we see "404 not found" and thats exactly what I am getting on subdomain but I am unable to takeover cant find details (cont) #bugbountytips

Razeditz_12's tweet image. The SubOver tool says "Takeover Possible At" and when I visit "can-i-take-over-xyz" repo I see that takeover is possible when we see "404 not found" and thats exactly what I am getting on subdomain but I am unable to takeover cant find details 
(cont) #bugbountytips
Razeditz_12's tweet image. The SubOver tool says "Takeover Possible At" and when I visit "can-i-take-over-xyz" repo I see that takeover is possible when we see "404 not found" and thats exactly what I am getting on subdomain but I am unable to takeover cant find details 
(cont) #bugbountytips
Razeditz_12's tweet image. The SubOver tool says "Takeover Possible At" and when I visit "can-i-take-over-xyz" repo I see that takeover is possible when we see "404 not found" and thats exactly what I am getting on subdomain but I am unable to takeover cant find details 
(cont) #bugbountytips

Chilllz reposted

The SubOver tool says "Takeover Possible At" and when I visit "can-i-take-over-xyz" repo I see that takeover is possible when we see "404 not found" and thats exactly what I am getting on subdomain but I am unable to takeover cant find details (cont) #bugbountytips

Razeditz_12's tweet image. The SubOver tool says "Takeover Possible At" and when I visit "can-i-take-over-xyz" repo I see that takeover is possible when we see "404 not found" and thats exactly what I am getting on subdomain but I am unable to takeover cant find details 
(cont) #bugbountytips
Razeditz_12's tweet image. The SubOver tool says "Takeover Possible At" and when I visit "can-i-take-over-xyz" repo I see that takeover is possible when we see "404 not found" and thats exactly what I am getting on subdomain but I am unable to takeover cant find details 
(cont) #bugbountytips
Razeditz_12's tweet image. The SubOver tool says "Takeover Possible At" and when I visit "can-i-take-over-xyz" repo I see that takeover is possible when we see "404 not found" and thats exactly what I am getting on subdomain but I am unable to takeover cant find details 
(cont) #bugbountytips


Chilllz reposted

Give me 2.5M USD in cash today and I’d quit Infosec entirely


Chilllz reposted

Rs 50,000 per day ok🙄🥴 #Scammers

Razeditz_12's tweet image. Rs 50,000 per day ok🙄🥴
#Scammers

I want a payloads file like : <One space> <Two spaces> ...... <100 spaces> ... Anyone have this? I dont wanna type manually is there a way to generate? any Website? Anything...? #bugbountytips #bugbounty #bugbountytip #infosec



Anybody knows how to exploit this --> CVE-2020-5412 Full-Read SSRF in spring-cloud-netflix-hystrix-dashboard when i visit --> GET /proxy.stream?origin=http://Burp.net I get my own IP #bugbounty #bugbountytips #infosec #Help #ssrf #cve



Chilllz reposted

Anybody knows how to exploit this --> CVE-2020-5412 Full-Read SSRF in spring-cloud-netflix-hystrix-dashboard when i visit --> GET /proxy.stream?origin=http://Burp.net I get my own IP #bugbounty #bugbountytips #infosec #Help #ssrf #cve


Chilllz reposted

then I get an error as shown in the pic Anyone knows how to exploit this code break or #bugbountytips #bugbounty #hackerone #infosec @GodfatherOrwa @remonsec @rootxyash @SMHTahsin33 @s0md3v @NahamSec @AkashHamal0x01 @Bugcrowd

Razeditz_12's tweet image. then I get an error as shown in the pic

Anyone knows how to exploit this code break or
#bugbountytips #bugbounty #hackerone #infosec 

@GodfatherOrwa @remonsec @rootxyash @SMHTahsin33 @s0md3v @NahamSec @AkashHamal0x01 @Bugcrowd

On a ContactUS page, I enter the following details: {"subject":"k", "content":"k", "firstName":"kk", "lastName":"lk", "email":"[email protected]"} then I get an OK response But as soon as I change any parameter value as """ ie {"subject":""", "content":"k",...} then (cont)



Chilllz reposted

Hello SO I was Randomly Scrolling through js codes and found this in one file: "dev_api_key":"X" "qa_api_key":"X" "perf_api_key":"X" "stage_api_key":"X" "prod_api_key":"X" and If found these Keys and Now I don't know where and How to use them .....and i m just blank


Done

Ok, let's try to do a swag giveaway. We are going to send a t-shirt and few goodies to one person who follows @PentesterLab and likes this tweet !!



Loading...

Something went wrong.


Something went wrong.