sec_bug's profile picture.

๐Ÿ‡ช๐Ÿ‡ฌ ุงู„ู…ุญุชุฑู ๐Ÿ‡ธ๐Ÿ‡ฆ

@sec_bug

๐Ÿ‡ช๐Ÿ‡ฌ ุงู„ู…ุญุชุฑู ๐Ÿ‡ธ๐Ÿ‡ฆ ๋‹˜์ด ์žฌ๊ฒŒ์‹œํ•จ

๐Ÿšจ I convinced my team to do one last giveaway! Options: hhub.io/eu2wxGj ๐Ÿ† Full Access: $199 ๐Ÿ’ป Lifetime Course: $39 (includes updates) ๐ŸŽฏ 1-Month trial (no updates): $19 TWO WINNERS (1 each): - Full cert bundle - Lifetime access Enter: โ†ช๏ธ RT + Reply with ๐ŸŽฏ

NahamSec's tweet image. ๐Ÿšจ I convinced my team to do one last giveaway!

Options: hhub.io/eu2wxGj
๐Ÿ† Full Access: $199 
๐Ÿ’ป Lifetime Course: $39 (includes updates)
 ๐ŸŽฏ 1-Month trial (no updates): $19

TWO WINNERS (1 each):
- Full cert bundle
- Lifetime access

Enter: โ†ช๏ธ RT + Reply with ๐ŸŽฏ

๐Ÿ‡ช๐Ÿ‡ฌ ุงู„ู…ุญุชุฑู ๐Ÿ‡ธ๐Ÿ‡ฆ ๋‹˜์ด ์žฌ๊ฒŒ์‹œํ•จ

๐Ÿš€Bug Bounty Tips: Act quickly to report issues related to CVE-2020-27838, as many vulnerable instances are still out there. I've identified over 100+ instances vulnerable to CVE-2020-27838 so far. A flaw was found in Keycloak in versions prior to 13.0.0. The client registrationโ€ฆ

Jayesh25_'s tweet image. ๐Ÿš€Bug Bounty Tips: Act quickly to report issues related to CVE-2020-27838, as many vulnerable instances are still out there. I've identified over 100+ instances vulnerable to CVE-2020-27838 so far.

A flaw was found in Keycloak in versions prior to 13.0.0. The client registrationโ€ฆ

๐Ÿ‡ช๐Ÿ‡ฌ ุงู„ู…ุญุชุฑู ๐Ÿ‡ธ๐Ÿ‡ฆ ๋‹˜์ด ์žฌ๊ฒŒ์‹œํ•จ

An automation tool for enumerating subdomains, filtering out XSS, SQLI, Open Redirect, LFI, SSRF, and RCE parameters, and scanning for vulnerabilities. github.com/h4r5h1t/webcopโ€ฆ


๐Ÿ‡ช๐Ÿ‡ฌ ุงู„ู…ุญุชุฑู ๐Ÿ‡ธ๐Ÿ‡ฆ ๋‹˜์ด ์žฌ๊ฒŒ์‹œํ•จ

๐ŸŒŸSubdominator๐ŸŒŸ is a powerful tool for passive subdomain enumeration during bug hunting and reconnaissance processes. ๐Ÿ“ฅgithub.com/sanjai-AK47/Suโ€ฆ #bugbountytip #bugbountytips #ethicalhacking #CyberSecurity #Pentesting #sqli #xss #CyberSecurityAwareness #bugbounty #GitHub #offsec

wtf_brut's tweet image. ๐ŸŒŸSubdominator๐ŸŒŸ is a powerful tool for passive subdomain enumeration during bug hunting and reconnaissance processes.

๐Ÿ“ฅgithub.com/sanjai-AK47/Suโ€ฆ

#bugbountytip #bugbountytips #ethicalhacking #CyberSecurity #Pentesting #sqli #xss #CyberSecurityAwareness #bugbounty #GitHub #offsec

๐Ÿ‡ช๐Ÿ‡ฌ ุงู„ู…ุญุชุฑู ๐Ÿ‡ธ๐Ÿ‡ฆ ๋‹˜์ด ์žฌ๊ฒŒ์‹œํ•จ

๐Ÿ“Scanning APK file for URIs, endpoints & secrets. ุฃุฏุงุฉ ู„ุชุญู„ูŠู„ ู…ู„ูุงุช apk ๐Ÿ–‡๏ธgithub.com/dwisiswant0/apโ€ฆ

A_cyb3r's tweet image. ๐Ÿ“Scanning APK file for URIs, endpoints & secrets.
ุฃุฏุงุฉ ู„ุชุญู„ูŠู„ ู…ู„ูุงุช apk
๐Ÿ–‡๏ธgithub.com/dwisiswant0/apโ€ฆ

๐Ÿ‡ช๐Ÿ‡ฌ ุงู„ู…ุญุชุฑู ๐Ÿ‡ธ๐Ÿ‡ฆ ๋‹˜์ด ์žฌ๊ฒŒ์‹œํ•จ

THREAD How did I find 2 DOM XSS by hacking Swagger-UI? 1-Do a subdomain enum to find subs that use Swagger Ui 2-Get the live subs 3-Run Nuclei in all the live subs using the (-tags swagger) 4-Find Swagger Ui endpoints #BugBounty #bugbountytip #bugbountytips #Cybersecurity

7evv1's tweet image. THREAD
 How did I find 2 DOM XSS by hacking Swagger-UI?

1-Do a subdomain enum to find subs that use Swagger Ui 
2-Get the live subs 
3-Run Nuclei in all the live subs using the (-tags swagger)
4-Find Swagger Ui endpoints
#BugBounty  #bugbountytip  #bugbountytips #Cybersecurity
7evv1's tweet image. THREAD
 How did I find 2 DOM XSS by hacking Swagger-UI?

1-Do a subdomain enum to find subs that use Swagger Ui 
2-Get the live subs 
3-Run Nuclei in all the live subs using the (-tags swagger)
4-Find Swagger Ui endpoints
#BugBounty  #bugbountytip  #bugbountytips #Cybersecurity
7evv1's tweet image. THREAD
 How did I find 2 DOM XSS by hacking Swagger-UI?

1-Do a subdomain enum to find subs that use Swagger Ui 
2-Get the live subs 
3-Run Nuclei in all the live subs using the (-tags swagger)
4-Find Swagger Ui endpoints
#BugBounty  #bugbountytip  #bugbountytips #Cybersecurity

๐Ÿ‡ช๐Ÿ‡ฌ ุงู„ู…ุญุชุฑู ๐Ÿ‡ธ๐Ÿ‡ฆ ๋‹˜์ด ์žฌ๊ฒŒ์‹œํ•จ

Thanks to Allah always and forever โ™ฅ๏ธ First Triage in 2024, HTML Injection on Login Page #Tips :- 1- site:*[.]redacted[.]com login.php 2- arjun -u .../login.php -> parameters with body length reflection (username) 3- Test for :- SQLi, LFI, XSS, HTML inj,..etc #bugbountytips

wadgamaraldeen's tweet image. Thanks to Allah always and forever โ™ฅ๏ธ

First Triage in 2024, HTML Injection on Login Page

#Tips :-

1- site:*[.]redacted[.]com login.php
2- arjun -u .../login.php -> parameters with body length reflection (username)
3- Test for :- SQLi, LFI, XSS, HTML inj,..etc

#bugbountytips

๐Ÿ‡ช๐Ÿ‡ฌ ุงู„ู…ุญุชุฑู ๐Ÿ‡ธ๐Ÿ‡ฆ ๋‹˜์ด ์žฌ๊ฒŒ์‹œํ•จ

- Simple tip for port scan 1) after enumerat your subdomains save in subs.txt 2) run this command "cat subs.txt | dnsx -a -ro | naabu -silent -top-ports 1000 -exclude-ports 80,443,21,22,25 -o ports.txt" #bugbountytips #bugbounty #infosec #cybersec

m0uka_Dz's tweet image. - Simple tip for port scan 
1) after enumerat your subdomains save in  subs.txt
2) run this command 
"cat subs.txt | dnsx -a -ro | naabu -silent  -top-ports 1000 -exclude-ports 80,443,21,22,25 -o ports.txt"

#bugbountytips #bugbounty #infosec #cybersec

๐Ÿ‡ช๐Ÿ‡ฌ ุงู„ู…ุญุชุฑู ๐Ÿ‡ธ๐Ÿ‡ฆ ๋‹˜์ด ์žฌ๊ฒŒ์‹œํ•จ

ุดูƒุฑู‹ุง ู„ุนุจุฏุงู„ุฑุญู…ู† ุฐูƒูŠุŒ ู„ุฎุต ููŠุฏูŠูˆ ุงู„ุฑูˆุฏ ู…ุงุจ ู ุชูƒุณุช โค๏ธ ู„ู„ูŠ ู…ุด ุญูŠู‚ุฏุฑ ูŠุชูุฑุฌ ุนุงู„ููŠุฏูŠูˆ ุงูˆ ู…ุนู†ุฏู‡ูˆุด ูˆู‚ุชุŒ ุฏู‚ูŠู‚ู‡ ุงู‚ุฑุง ุงู„ุงุชูŠ: โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€”โ€” 1. html | elzero.org 2. css ุงุฒุงูŠ ุชุนู…ู„ ุชุฒูŠูŠู† ุจุณ ูƒุฏุง ูˆุฎู„ุงุต | 3. js | 4. php |โ€ฆ

ุงู„ู‰ ู…ู† ูŠู‡ู…ู‡ ุงู„ุงู…ุฑุŒ ู†ุฒู„ุช ููŠุฏูŠูˆ ุฌุฏูŠุฏ ู„ู„ูŠ ุจูŠุฏูˆุฑ ุนู„ู‰ ุฑูˆุฏ ู…ุงุจ ูˆู…ุณุชู†ูŠู‡ุง ู…ุฎุตูˆุต ุนุดุงู† ูŠุจุฏุฃ ๐Ÿฅน youtu.be/ea-VT5mOknc?siโ€ฆ #cyberbugs #roadmap

SirBagoza's tweet image. ุงู„ู‰ ู…ู† ูŠู‡ู…ู‡ ุงู„ุงู…ุฑุŒ ู†ุฒู„ุช ููŠุฏูŠูˆ ุฌุฏูŠุฏ ู„ู„ูŠ ุจูŠุฏูˆุฑ ุนู„ู‰ ุฑูˆุฏ ู…ุงุจ ูˆู…ุณุชู†ูŠู‡ุง ู…ุฎุตูˆุต ุนุดุงู† ูŠุจุฏุฃ ๐Ÿฅน

youtu.be/ea-VT5mOknc?siโ€ฆ

#cyberbugs #roadmap


๐Ÿ‡ช๐Ÿ‡ฌ ุงู„ู…ุญุชุฑู ๐Ÿ‡ธ๐Ÿ‡ฆ ๋‹˜์ด ์žฌ๊ฒŒ์‹œํ•จ

๐Ÿ”–Penetration Testing, Beginner To Expert! Massive Web Application Penetration Testing & Bug Bounty Notes๐Ÿ“š github: github.com/xalgord/Massivโ€ฆ #web #pentest


๐Ÿ‡ช๐Ÿ‡ฌ ุงู„ู…ุญุชุฑู ๐Ÿ‡ธ๐Ÿ‡ฆ ๋‹˜์ด ์žฌ๊ฒŒ์‹œํ•จ

I'm thrilled to introduce Recon88r, a Python script designed to streamline and automate the reconnaissance process # Features: Subdomain Enumeration Live Results in Discord Perform XSS scans JS Exposures Port scanning Full nuclei scanning Panels #bugbounty t.ly/FfmSP


๐Ÿ‡ช๐Ÿ‡ฌ ุงู„ู…ุญุชุฑู ๐Ÿ‡ธ๐Ÿ‡ฆ ๋‹˜์ด ์žฌ๊ฒŒ์‹œํ•จ

"Don't ignore 403 subdomains" Try to bypass or fuzz more. Also, always check Symfony targets for these directories: /_profiler. You might find phpinfo containing Symfony secrets, which can lead to RCE. Great tip by @GodfatherOrwa! โค๏ธโค๏ธ #BugBounty #SecurityTips

khaleedsamy12's tweet image. "Don't ignore 403 subdomains"
Try to bypass or fuzz more. 
Also, always  check Symfony targets for these directories: /_profiler. 
You might find  phpinfo containing Symfony secrets, which can lead to RCE.
 Great tip by @GodfatherOrwa! โค๏ธโค๏ธ 
#BugBounty #SecurityTips

๐Ÿ‡ช๐Ÿ‡ฌ ุงู„ู…ุญุชุฑู ๐Ÿ‡ธ๐Ÿ‡ฆ ๋‹˜์ด ์žฌ๊ฒŒ์‹œํ•จ

Ghauri - An Advanced SQL Injection Automation Plugin-In By @SecurityFoster. ๐Ÿ’ซ๐Ÿ’ซ Latest Acunetix VS Ghauri ๐Ÿง๐Ÿง Coded By: @r0oth3x49 ๐ŸŽฉ #Cybersecurity #automationtesting #BugBounty #bugbountytips

XSaadAhmedX's tweet image. Ghauri - An Advanced SQL Injection Automation Plugin-In By @SecurityFoster. ๐Ÿ’ซ๐Ÿ’ซ
Latest Acunetix VS Ghauri ๐Ÿง๐Ÿง

Coded By: @r0oth3x49 ๐ŸŽฉ
#Cybersecurity #automationtesting #BugBounty #bugbountytips
XSaadAhmedX's tweet image. Ghauri - An Advanced SQL Injection Automation Plugin-In By @SecurityFoster. ๐Ÿ’ซ๐Ÿ’ซ
Latest Acunetix VS Ghauri ๐Ÿง๐Ÿง

Coded By: @r0oth3x49 ๐ŸŽฉ
#Cybersecurity #automationtesting #BugBounty #bugbountytips
XSaadAhmedX's tweet image. Ghauri - An Advanced SQL Injection Automation Plugin-In By @SecurityFoster. ๐Ÿ’ซ๐Ÿ’ซ
Latest Acunetix VS Ghauri ๐Ÿง๐Ÿง

Coded By: @r0oth3x49 ๐ŸŽฉ
#Cybersecurity #automationtesting #BugBounty #bugbountytips

๐Ÿ‡ช๐Ÿ‡ฌ ุงู„ู…ุญุชุฑู ๐Ÿ‡ธ๐Ÿ‡ฆ ๋‹˜์ด ์žฌ๊ฒŒ์‹œํ•จ

Some Shodan Dorks that might be useful in Bug Bounty. 1. org:"http://target. com" 2. http.status:"<status_code>" 3. product:"<Product_Name>" 4. port:<Port_Number> โ€œService_Messageโ€ 5. port:<Port_Number> โ€œService_Nameโ€ 6. http.component:"<Component_Name>" 7.โ€ฆ


๐Ÿ‡ช๐Ÿ‡ฌ ุงู„ู…ุญุชุฑู ๐Ÿ‡ธ๐Ÿ‡ฆ ๋‹˜์ด ์žฌ๊ฒŒ์‹œํ•จ

This tool ( unisub ) , its one of the best option for you to bypass WAF's and filters .๐Ÿ™‚ by @TomNomNom #bugbountytips #bugbounty #Hackingtime

zack0x01's tweet image. This tool ( unisub ) , its one of the best option for  you to bypass WAF&apos;s and filters .๐Ÿ™‚

by @TomNomNom 
#bugbountytips #bugbounty #Hackingtime

๐Ÿ‡ช๐Ÿ‡ฌ ุงู„ู…ุญุชุฑู ๐Ÿ‡ธ๐Ÿ‡ฆ ๋‹˜์ด ์žฌ๊ฒŒ์‹œํ•จ

Wanna know How I prevented a Mass Data Breach? Go Read: medium.com/@bxmbn/how-i-pโ€ฆ Wanna know How a Bank offer led to PII Leak? Go Read: medium.com/@bxmbn/i-receiโ€ฆ More writeups coming soon ๐Ÿ–ค


๐Ÿ‡ช๐Ÿ‡ฌ ุงู„ู…ุญุชุฑู ๐Ÿ‡ธ๐Ÿ‡ฆ ๋‹˜์ด ์žฌ๊ฒŒ์‹œํ•จ

1/7 Web Application Recon Tips 1 : Resolution # github.com/projectdiscoveโ€ฆ cat subdomains/subdomains.txt | httpx -follow-redirects -random-agent -status-code -silent -retries 2 -title -web-server -tech-detect -location -no-color -o websites.txt #bugbountytips #BugBounty #Hacking


๐Ÿ‡ช๐Ÿ‡ฌ ุงู„ู…ุญุชุฑู ๐Ÿ‡ธ๐Ÿ‡ฆ ๋‹˜์ด ์žฌ๊ฒŒ์‹œํ•จ

Ok, here is another #bugbountytip You can find this issue with โ€œlogin with Google โ€ too, or any other Idp providers During the signup process, delete the email value from the scope ๐Ÿ’ฃ

๐Ÿ”Secrets no one will share with you - Here's a technique that might grant you access to takeover other users' accounts using "Login with Facebook": Are you working on a target site that supports "Login with Facebook"? Disable email sharing during Facebook login and be readyโ€ฆ

Jayesh25_'s tweet image. ๐Ÿ”Secrets no one will share with you - Here&apos;s a technique that might grant you access to takeover other users&apos; accounts using &quot;Login with Facebook&quot;:

Are you working on a target site that supports &quot;Login with Facebook&quot;?

Disable email sharing during Facebook login and be readyโ€ฆ


๐Ÿ‡ช๐Ÿ‡ฌ ุงู„ู…ุญุชุฑู ๐Ÿ‡ธ๐Ÿ‡ฆ ๋‹˜์ด ์žฌ๊ฒŒ์‹œํ•จ

To who asked about the vulnerability type, i wrote this writeup about it before period of time, enjoy reading it :- medium.com/@wadqamar10/hoโ€ฆ

ุจุชูˆููŠู‚ ู…ู† ุงู„ู„ู‡ ุณุจุญุงู†ู‡ ูˆ ุชุนุงู„ู‰ โ™ฅ๏ธ One of my most notable achievements in 2023 is that I received my biggest Bounty and discovered security vulnerabilities in different companies, and if Allah willing, in 2024 I aim become a professional Security Researcher and get Security Certs

wadgamaraldeen's tweet image. ุจุชูˆููŠู‚ ู…ู† ุงู„ู„ู‡ ุณุจุญุงู†ู‡ ูˆ ุชุนุงู„ู‰ โ™ฅ๏ธ
One of my most notable achievements in 2023 is that I received my biggest Bounty and discovered security vulnerabilities in different companies, and if Allah willing, in 2024 I aim  become a professional Security Researcher and get Security Certs


๐Ÿ‡ช๐Ÿ‡ฌ ุงู„ู…ุญุชุฑู ๐Ÿ‡ธ๐Ÿ‡ฆ ๋‹˜์ด ์žฌ๊ฒŒ์‹œํ•จ

A less known CVE-2023-3793 - Weaver E-Cology SQL Injection. Nuclei Template Link Link: github.com/UltimateSec/ulโ€ฆ #BugBounty #SQLInjection

nav1n0x's tweet image. A less known CVE-2023-3793 - Weaver E-Cology SQL Injection.  Nuclei Template Link Link: github.com/UltimateSec/ulโ€ฆ 

#BugBounty #SQLInjection
nav1n0x's tweet image. A less known CVE-2023-3793 - Weaver E-Cology SQL Injection.  Nuclei Template Link Link: github.com/UltimateSec/ulโ€ฆ 

#BugBounty #SQLInjection
nav1n0x's tweet image. A less known CVE-2023-3793 - Weaver E-Cology SQL Injection.  Nuclei Template Link Link: github.com/UltimateSec/ulโ€ฆ 

#BugBounty #SQLInjection

Loading...

Something went wrong.


Something went wrong.