I earned $2,500 for my submission on @Bugcrowd#ItTakesACrowd
Flow:
1. Dnsbrute and grep some subdomains
2. Start directory fuzzing with .aspx extention
3. Discovered Passwordresx.aspx and paste payload (' waitfor delay'0:0:20'--)
#BugBounty#BugBountytips #BugBountytip
Recon always wins.
1) Company and web application recon
2) Find legacy subdomains [This is my favorite :) ]
3) Parameter fuzz with private wordlist
4) Check reflection and XSS
#BugBountytips #BugBounty#BugBountytip #cybersecuritytips
ساده اما کاربردی :)
ابزاری که درحال حاضر ازش استفاده میکنم مشکلات زیادی داره، برای همین تصمیم گرفتم با یه برنامه نویس و چند نفر دیگه باهم کارو ببریم جلو.
امیدوارم نتیجه مطلوب حاصل بشه.✌🏻
#automation#recon
3K Followers 3K Followingنیمچه مهندس کامپیوتر - عاشق 🇩🇪 ---- مجاهد ، ارزشی ، اصلاح طلب ، طرفدار موسوی و سلطنت طلب متعصب ⛔
به جان عرزشی ها که میخوام نباشن من سالمم
233K Followers 1K FollowingCofounder @hackinghub_io | Advisor @CaidoIO. I hack companies and make content about it. #NahamCon organizer. ex @hacker0x01🇮🇷
187K Followers 6K FollowingThe leading provider of crowdsourced cybersecurity solutions purpose-built to secure the digitally connected world...Unleash Ingenuity™
3K Followers 389 FollowingRed Teamer & Security researcher
Maintainer of #NetExec, #DonPAPI, dploot, certsync, and all the stuff on my github repo
bsky: https://t.co/zISpgvDSWc
16K Followers 781 Following🔍 Top 100 Bug Bounty Hunter @ Bugcrowd | 🇩🇴 Dominican | Ethical hacking fanatic | 🎮🎵 Lover | Keeping the digital world safe. opinions are that of my own
52K Followers 616 FollowingGrzegorz Niedziela - a hacker who documents his hacking journey by creating and curating the best content about bug bounty and offensive security.
30K Followers 560 FollowingCyBeRsEcUrItY | Not afraid to put down with some THICC malware on disk | securing and breaking AI @PaloAltoNtwks | Ex @spacex
28K Followers 206 FollowingHacker at @OutsiderSec. Researches AD and Azure (AD) security. Likes to play around with Python and write tools that make work easier.
20K Followers 2K FollowingPrincipal Identity Security Researcher at Microsoft. Ex-Secureworks. (MSc, MEng, PhD, CITP, CCSK).
And yes, opinions are my own ;)
20K Followers 439 FollowingHacker, Infosec Researcher, Military Affairs & History, PowerShell, AD and Azure pwner, Creator of Nishang and others :)
Founder @alteredsecurity
10K Followers 1 FollowingUser friendly unofficial HackerOne public disclosures, keeps you updated about the recently disclosed bugs.
Made With ♥ By Hackers For Hackers. - @rohsec
14K Followers 915 FollowingWindows Internals expert, author, and trainer. Teaching system programming & debugging at TrainSec. Check out my books & courses! 🚀 #WindowsInternals #TrainSec