Found an improper SSO configuration on private program.
The application allows admin users to log in via šš¤šš & šš¦šš¢š„ ššš.
The šš¦šš¢š„ ššš implementation was flawed, allowing me to bypass authentication and gain unauthorized access to the admin portal. [Fixed]
šØ OSCP GIVEAWAY ALERTšØ
Weāre giving away 3 OSCP vouchers to supercharge your pentesting journey ā proudly sponsored by @offsectraining ! š„š
To enter:
1.ā Follow Us
2.š Retweet this post
3.ā¤ļø Like this post
4.š¬ Reply with your funniest cybersecurity meme
šÆ Weāll pick 3ā¦
Dear @TheOfficialSBI, There is a spelling mistake on the mcaregistration page. You have listed "Gujrat" (which is located in Pakistan), but the correct spelling for the Indian state is "Gujarat".
Kindly make the correction.
Thank you!
ā Gujarat, India
āGujrat, Pakistan
Found an interesting IDOR. After signing up on the same app with two diff. countries:USA & India. I noticed that the account registered under India had an option to pause payment notification. By manipulating `ID` values in the request, I was able to pause notification of anyone.
Thrilled to announce Iāve reached $100K on @Bugcrowd ! š Itās been an amazing journey securing sectors like banking, finance, education, healthcare, and content management, helping protect sensitive data along the way.
Submitting bugs? Keep it smooth with these tips:
ā³ Most are reviewed in 7 business days, clear reports help!
š¬ Need an update? Use "Request a Response" after 7 days
ā Finalization takes ~14 days, reach out if delayed
š¤ Feedback? Be professional & specific
Questions? Dropā¦
tried something new for the Bug Hunting community i hope this will help in there hunting jurney ā¤ļø
site:lostsec.xyz
special thanks to my team @1hehaq and @javxfps to make it more better..
Bugcrowd's RAR is truly mind-blowing! Big thanks to @Bugcrowd for this amazing feature, and a huge salute to "lemonade-bugcrowd" for the quick response time! šš
Web Pentesting / Bounty Tip:
Some people like using a command-line spider for gathering endpoints. Katana is one of these security focused spiders:
github.com/projectdiscoveā¦
When using katana:
1) use "-headless" as modern CDN WAFs block many command-line spiders.
2) useā¦
Understanding pen testing vs. bug bounty is key for cybersecurity.
āļø Pen testing: structured, comprehensive
š Bug bounty: taps global hackers, "pay for impact"
Both crucial, but intensity varies! Learn more: bgcd.co/4c4Y2HM#Cybersecurity#PenTesting#BugBounty
Back to hunting on @yeswehack
after a month and a half. Submitted 6 bugs to various programs and was surprised to see status change from 'new' to 'under review' in less than 30 seconds!š«” Hoping for more invitesš
#iamadityapatel#hackxadi#bughunter
145 Followers 2K FollowingI downloaded Twitter because it's funny š
In my free time š
Research on mordern Red Teaming tactics
Zerodays & Exploit development
Music, Meditation
2K Followers 7 FollowingOur mission is to be the quickest, most affordable solution to get you secured and compliant.
We keep your assets and peace of mind safe.
2K Followers 746 FollowingOSCP | eJPT | Lead Security Engineer @redsentry_tech | Synack Red Team | Web & Mobile Security | Chapter Lead @nullblr (she/her) ā ļø
35K Followers 80 FollowingWe're a 100% voluntary initiative dedicated to assisting those in distress. We don't accept donations or financial aid for the help we offer.
10K Followers 1 FollowingUser friendly unofficial HackerOne public disclosures, keeps you updated about the recently disclosed bugs.
Made With ā„ By Hackers For Hackers. - @rohsec
467K Followers 1 FollowingCustomer support handle of @reliancejio. Need help? Chat with us on MyJio, click https://t.co/9h7Ktdijbb Or on Whatsapp, click https://t.co/f32WLLqnHc
554 Followers 823 FollowingI provide top-notch cyber content for companies and cyber instructors to grow their online brand and get more clients & sales | Pentester | OSCPā£
145K Followers 215 FollowingWe are the Microsoft Security Response Center. To report security vulnerabilities or abuse in Microsoft products, visit https://t.co/kxEbdfMny1.
4K Followers 41 FollowingBug Bounty Village | 20-22 Feb, 2025 | International Center of Goa, India
#bugbounty #bugbountyvillage #infosec
Call for Nominations/Talks are open!
3K Followers 25 FollowingWe offers Cyber Security Training šā, Penetration Testing, and Bug Bounty Tipsš° to protect businesses and individuals from cyber attacks.
Feel Free to Ask.