sec_bug's profile picture.

🇪🇬 المحترف 🇸🇦

@sec_bug

🇪🇬 المحترف 🇸🇦 reposted

🚨 I convinced my team to do one last giveaway! Options: hhub.io/eu2wxGj 🏆 Full Access: $199 💻 Lifetime Course: $39 (includes updates) 🎯 1-Month trial (no updates): $19 TWO WINNERS (1 each): - Full cert bundle - Lifetime access Enter: ↪️ RT + Reply with 🎯

NahamSec's tweet image. 🚨 I convinced my team to do one last giveaway!

Options: hhub.io/eu2wxGj
🏆 Full Access: $199 
💻 Lifetime Course: $39 (includes updates)
 🎯 1-Month trial (no updates): $19

TWO WINNERS (1 each):
- Full cert bundle
- Lifetime access

Enter: ↪️ RT + Reply with 🎯

🇪🇬 المحترف 🇸🇦 reposted

🚀Bug Bounty Tips: Act quickly to report issues related to CVE-2020-27838, as many vulnerable instances are still out there. I've identified over 100+ instances vulnerable to CVE-2020-27838 so far. A flaw was found in Keycloak in versions prior to 13.0.0. The client registration…

Jayesh25_'s tweet image. 🚀Bug Bounty Tips: Act quickly to report issues related to CVE-2020-27838, as many vulnerable instances are still out there. I've identified over 100+ instances vulnerable to CVE-2020-27838 so far.

A flaw was found in Keycloak in versions prior to 13.0.0. The client registration…

🇪🇬 المحترف 🇸🇦 reposted

An automation tool for enumerating subdomains, filtering out XSS, SQLI, Open Redirect, LFI, SSRF, and RCE parameters, and scanning for vulnerabilities. github.com/h4r5h1t/webcop…


🇪🇬 المحترف 🇸🇦 reposted

🌟Subdominator🌟 is a powerful tool for passive subdomain enumeration during bug hunting and reconnaissance processes. 📥github.com/sanjai-AK47/Su… #bugbountytip #bugbountytips #ethicalhacking #CyberSecurity #Pentesting #sqli #xss #CyberSecurityAwareness #bugbounty #GitHub #offsec

wtf_brut's tweet image. 🌟Subdominator🌟 is a powerful tool for passive subdomain enumeration during bug hunting and reconnaissance processes.

📥github.com/sanjai-AK47/Su…

#bugbountytip #bugbountytips #ethicalhacking #CyberSecurity #Pentesting #sqli #xss #CyberSecurityAwareness #bugbounty #GitHub #offsec

🇪🇬 المحترف 🇸🇦 reposted

📍Scanning APK file for URIs, endpoints & secrets. أداة لتحليل ملفات apk 🖇️github.com/dwisiswant0/ap…

A_cyb3r's tweet image. 📍Scanning APK file for URIs, endpoints & secrets.
أداة لتحليل ملفات apk
🖇️github.com/dwisiswant0/ap…

🇪🇬 المحترف 🇸🇦 reposted

THREAD How did I find 2 DOM XSS by hacking Swagger-UI? 1-Do a subdomain enum to find subs that use Swagger Ui 2-Get the live subs 3-Run Nuclei in all the live subs using the (-tags swagger) 4-Find Swagger Ui endpoints #BugBounty #bugbountytip #bugbountytips #Cybersecurity

7evv1's tweet image. THREAD
 How did I find 2 DOM XSS by hacking Swagger-UI?

1-Do a subdomain enum to find subs that use Swagger Ui 
2-Get the live subs 
3-Run Nuclei in all the live subs using the (-tags swagger)
4-Find Swagger Ui endpoints
#BugBounty  #bugbountytip  #bugbountytips #Cybersecurity
7evv1's tweet image. THREAD
 How did I find 2 DOM XSS by hacking Swagger-UI?

1-Do a subdomain enum to find subs that use Swagger Ui 
2-Get the live subs 
3-Run Nuclei in all the live subs using the (-tags swagger)
4-Find Swagger Ui endpoints
#BugBounty  #bugbountytip  #bugbountytips #Cybersecurity
7evv1's tweet image. THREAD
 How did I find 2 DOM XSS by hacking Swagger-UI?

1-Do a subdomain enum to find subs that use Swagger Ui 
2-Get the live subs 
3-Run Nuclei in all the live subs using the (-tags swagger)
4-Find Swagger Ui endpoints
#BugBounty  #bugbountytip  #bugbountytips #Cybersecurity

🇪🇬 المحترف 🇸🇦 reposted

Thanks to Allah always and forever ♥️ First Triage in 2024, HTML Injection on Login Page #Tips :- 1- site:*[.]redacted[.]com login.php 2- arjun -u .../login.php -> parameters with body length reflection (username) 3- Test for :- SQLi, LFI, XSS, HTML inj,..etc #bugbountytips

wadgamaraldeen's tweet image. Thanks to Allah always and forever ♥️

First Triage in 2024, HTML Injection on Login Page

#Tips :-

1- site:*[.]redacted[.]com login.php
2- arjun -u .../login.php -> parameters with body length reflection (username)
3- Test for :- SQLi, LFI, XSS, HTML inj,..etc

#bugbountytips

🇪🇬 المحترف 🇸🇦 reposted

- Simple tip for port scan 1) after enumerat your subdomains save in subs.txt 2) run this command "cat subs.txt | dnsx -a -ro | naabu -silent -top-ports 1000 -exclude-ports 80,443,21,22,25 -o ports.txt" #bugbountytips #bugbounty #infosec #cybersec

m0uka_Dz's tweet image. - Simple tip for port scan 
1) after enumerat your subdomains save in  subs.txt
2) run this command 
"cat subs.txt | dnsx -a -ro | naabu -silent  -top-ports 1000 -exclude-ports 80,443,21,22,25 -o ports.txt"

#bugbountytips #bugbounty #infosec #cybersec

🇪🇬 المحترف 🇸🇦 reposted

شكرًا لعبدالرحمن ذكي، لخص فيديو الرود ماب ف تكست ❤️ للي مش حيقدر يتفرج عالفيديو او معندهوش وقت، دقيقه اقرا الاتي: ——————————— 1. html | elzero.org 2. css ازاي تعمل تزيين بس كدا وخلاص | 3. js | 4. php |…

الى من يهمه الامر، نزلت فيديو جديد للي بيدور على رود ماب ومستنيها مخصوص عشان يبدأ 🥹 youtu.be/ea-VT5mOknc?si… #cyberbugs #roadmap

SirBagoza's tweet image. الى من يهمه الامر، نزلت فيديو جديد للي بيدور على رود ماب ومستنيها مخصوص عشان يبدأ 🥹

youtu.be/ea-VT5mOknc?si…

#cyberbugs #roadmap


🇪🇬 المحترف 🇸🇦 reposted

🔖Penetration Testing, Beginner To Expert! Massive Web Application Penetration Testing & Bug Bounty Notes📚 github: github.com/xalgord/Massiv… #web #pentest


🇪🇬 المحترف 🇸🇦 reposted

I'm thrilled to introduce Recon88r, a Python script designed to streamline and automate the reconnaissance process # Features: Subdomain Enumeration Live Results in Discord Perform XSS scans JS Exposures Port scanning Full nuclei scanning Panels #bugbounty t.ly/FfmSP


🇪🇬 المحترف 🇸🇦 reposted

"Don't ignore 403 subdomains" Try to bypass or fuzz more. Also, always check Symfony targets for these directories: /_profiler. You might find phpinfo containing Symfony secrets, which can lead to RCE. Great tip by @GodfatherOrwa! ❤️❤️ #BugBounty #SecurityTips

khaleedsamy12's tweet image. "Don't ignore 403 subdomains"
Try to bypass or fuzz more. 
Also, always  check Symfony targets for these directories: /_profiler. 
You might find  phpinfo containing Symfony secrets, which can lead to RCE.
 Great tip by @GodfatherOrwa! ❤️❤️ 
#BugBounty #SecurityTips

🇪🇬 المحترف 🇸🇦 reposted

Ghauri - An Advanced SQL Injection Automation Plugin-In By @SecurityFoster. 💫💫 Latest Acunetix VS Ghauri 🧐🧐 Coded By: @r0oth3x49 🎩 #Cybersecurity #automationtesting #BugBounty #bugbountytips

XSaadAhmedX's tweet image. Ghauri - An Advanced SQL Injection Automation Plugin-In By @SecurityFoster. 💫💫
Latest Acunetix VS Ghauri 🧐🧐

Coded By: @r0oth3x49 🎩
#Cybersecurity #automationtesting #BugBounty #bugbountytips
XSaadAhmedX's tweet image. Ghauri - An Advanced SQL Injection Automation Plugin-In By @SecurityFoster. 💫💫
Latest Acunetix VS Ghauri 🧐🧐

Coded By: @r0oth3x49 🎩
#Cybersecurity #automationtesting #BugBounty #bugbountytips
XSaadAhmedX's tweet image. Ghauri - An Advanced SQL Injection Automation Plugin-In By @SecurityFoster. 💫💫
Latest Acunetix VS Ghauri 🧐🧐

Coded By: @r0oth3x49 🎩
#Cybersecurity #automationtesting #BugBounty #bugbountytips

🇪🇬 المحترف 🇸🇦 reposted

Some Shodan Dorks that might be useful in Bug Bounty. 1. org:"http://target. com" 2. http.status:"<status_code>" 3. product:"<Product_Name>" 4. port:<Port_Number> “Service_Message” 5. port:<Port_Number> “Service_Name” 6. http.component:"<Component_Name>" 7.…


🇪🇬 المحترف 🇸🇦 reposted

This tool ( unisub ) , its one of the best option for you to bypass WAF's and filters .🙂 by @TomNomNom #bugbountytips #bugbounty #Hackingtime

zack0x01's tweet image. This tool ( unisub ) , its one of the best option for  you to bypass WAF&apos;s and filters .🙂

by @TomNomNom 
#bugbountytips #bugbounty #Hackingtime

🇪🇬 المحترف 🇸🇦 reposted

Wanna know How I prevented a Mass Data Breach? Go Read: medium.com/@bxmbn/how-i-p… Wanna know How a Bank offer led to PII Leak? Go Read: medium.com/@bxmbn/i-recei… More writeups coming soon 🖤


🇪🇬 المحترف 🇸🇦 reposted

1/7 Web Application Recon Tips 1 : Resolution # github.com/projectdiscove… cat subdomains/subdomains.txt | httpx -follow-redirects -random-agent -status-code -silent -retries 2 -title -web-server -tech-detect -location -no-color -o websites.txt #bugbountytips #BugBounty #Hacking


🇪🇬 المحترف 🇸🇦 reposted

Ok, here is another #bugbountytip You can find this issue with “login with Google ” too, or any other Idp providers During the signup process, delete the email value from the scope 💣

🔐Secrets no one will share with you - Here's a technique that might grant you access to takeover other users' accounts using "Login with Facebook": Are you working on a target site that supports "Login with Facebook"? Disable email sharing during Facebook login and be ready…

Jayesh25_'s tweet image. 🔐Secrets no one will share with you - Here&apos;s a technique that might grant you access to takeover other users&apos; accounts using &quot;Login with Facebook&quot;:

Are you working on a target site that supports &quot;Login with Facebook&quot;?

Disable email sharing during Facebook login and be ready…


🇪🇬 المحترف 🇸🇦 reposted

To who asked about the vulnerability type, i wrote this writeup about it before period of time, enjoy reading it :- medium.com/@wadqamar10/ho…

بتوفيق من الله سبحانه و تعالى ♥️ One of my most notable achievements in 2023 is that I received my biggest Bounty and discovered security vulnerabilities in different companies, and if Allah willing, in 2024 I aim become a professional Security Researcher and get Security Certs

wadgamaraldeen's tweet image. بتوفيق من الله سبحانه و تعالى ♥️
One of my most notable achievements in 2023 is that I received my biggest Bounty and discovered security vulnerabilities in different companies, and if Allah willing, in 2024 I aim  become a professional Security Researcher and get Security Certs


🇪🇬 المحترف 🇸🇦 reposted

A less known CVE-2023-3793 - Weaver E-Cology SQL Injection. Nuclei Template Link Link: github.com/UltimateSec/ul… #BugBounty #SQLInjection

nav1n0x's tweet image. A less known CVE-2023-3793 - Weaver E-Cology SQL Injection.  Nuclei Template Link Link: github.com/UltimateSec/ul… 

#BugBounty #SQLInjection
nav1n0x's tweet image. A less known CVE-2023-3793 - Weaver E-Cology SQL Injection.  Nuclei Template Link Link: github.com/UltimateSec/ul… 

#BugBounty #SQLInjection
nav1n0x's tweet image. A less known CVE-2023-3793 - Weaver E-Cology SQL Injection.  Nuclei Template Link Link: github.com/UltimateSec/ul… 

#BugBounty #SQLInjection

Loading...

Something went wrong.


Something went wrong.