IDOR allows me to upgrade my own user role to Admin 😃
Also, I can downgrade the real Admin just by simply changing the ID and "isAdmin": true/false
Easy bug highest impact!
#bugbountytips
A recent SSRF in a PDF generator 👇
The server converted my supplied HTML into PDF, so I dropped in a <meta http-equiv="refresh" content="0;url=http://10.20.x.x/"> tag and got the backend to fetch responses from the internal network. I was able to access an API on internal…
pwnedOrNot: An OSINT Tool for Finding Passwords of Compromised Email Accounts
GitHub: github.com/thewhiteh4t/pw…
Per the repo: "pwnedOrNot works in two phases. In the first phase it tests the given email address using HaveIBeenPwned v3 API to find if the account have been breached…
You've identified a possible SQLi 🤑
But Cloudflare WAF is in the way... 😓
What if you could just entirely bypass this firewall and get your payload through? 🤠
In our latest article, we documented several ways to identify the origin IP of your target behind popular CDNs and…
One of the OSINT tools from my list I often use in bug hunting for admin logins is @osintleak. It’s a powerful platform that allows you to gather information from names, emails, passwords, subdomains, IPs, credit card searches and more from leakdb and stealer logs..
Back in the game after a long break 🎯
Even without finding a bug, discovering a hidden and undocumented endpoint feels rewarding.
You don’t always need an exploit — sometimes the hunt itself is the real win.
@p__oria 😘😘😘
SIM Card Function Explained
◾ Vcc – Powers the SIM card (1.8V / 3V / 5V).
◾ Reset – Used to restart or initialize the SIM card.
◾ Clock – Sends timing signals to sync communication.
◾ Ground (GND) – Common ground or reference point.
◾ Vpp – Used in older SIMs for…
The @SLCyberSec research team is releasing our final research post for our Christmas in July efforts, two RCEs and one XXE (all pre-auth) in Adobe Experience Manager Forms. One of the RCEs and the XXE still do not have official patches: slcyber.io/assetnote-secu…
82 Followers 2K FollowingTrust in His plan | God's love makes even the hardest journeys worthwhile | His love is the compass guiding your life's purpose |
23 Followers 725 FollowingPre-Final Yr @ReachNITT
Full time Hacker & Part time Founder and CPO Cywreck
Cybersecurity Hall of Fame Yubi @FreshworksInc @Mindtickle @ShiprocketIndia @Bayer
80 Followers 491 FollowingJust a simple guy with a passion for exploring and playing with security. Always looking for new challenges and ways to make the digital world safer.
2K Followers 974 FollowingTo catch an adversary you must become one. Always deliver more than expected !!!!!! All post are educational purposes only. prompt Library ⬇️ URL
63K Followers 9K Followingजय श्री राम | हर हर महादेव | सनातनी योद्धा: नफरत के कीड़ों का शिकारी | तर्क से लड़ता, कर्म से जीतता | हिंदुत्व की रक्षा में अडिग, आस्था पर हमला बर्दाश्त नहीं!
129K Followers 60 FollowingProviding Cyber Threat Intelligence from the Dark Web & Clearnet: Breaches, Ransomware, Darknet Markets, Threat Alerts & more. https://t.co/Fi7VW9lg94
4K Followers 766 FollowingLead Security Researcher at @sherlockdefi
Over 400 H/M found https://t.co/JZpEyygsPC
Request an audit at https://t.co/MXMdM6cwva
37K Followers 496 FollowingHacker, bug bounty hunter, guy behind https://t.co/TBAtP71Cop. 1st in Meta bug bounty program for the last 6 years. YES Team Member
24K Followers 427 FollowingSharing insights on AI, Entrepreneurship, Online Business & Productivity • help people to Market & Launch SaaS and AI products. 📧 [email protected]
5 Followers 2 Following✈️Sole Mono Pole Travel Agency provides customized tour packages for South Korea, Maldives, and Sri Lanka, ensuring unique and memorable experiences.