Just a quick shout out to @nullr3x - found a possible #securitybreach and gave us the full details for is to fix it.
Keep this gentleman in mind if you need web or #Android application testing or #VAPT security audit.
Cheers!
When testing password fields, my preferred password is:
%01%E2%80%AEalert%0D%0A
Let's break it down:
%01 is SOH
%e2%80%ae is RTLO
%0d%0a is CRLF
Test cases on login:
1. can I log in only using %01?
2. without the CRLF in it?
3. is trela accepted instead of alert? (due to RTLO)
Doing Recon the right way keeps you a step ahead always and gives you a better attack surface to work on! Here's a snippet from my Recent Talk on Scope Based Recon talking about What to look for during Recon Based on Given Scope.
#bugbountytips #appsec#bugbounty#security
#bugbountytips
An almost universal way to theft or overwrite arbitrary files on #android is sharing activities. You can find them in AndroidManifest.xml. They handle android.intent.action.SEND. Use the PoC from blog.oversecured.com/Evernote-Unive… (ctrl+f "EXTRA_STREAM") and test 4 scenarios:
#bugbountytips
One more way to increase the impact of opening arbitrary URLs in a built-in WebView is Universal XSS. They are widespread on #android! Steps:
#bugbounty
You must love #Android deeplinks! They are the easiest way to get bounties
1. Decompile an app with jadx
2. Collect all deeplink handlers from AndroidManifest.xml, they look like <data android:scheme="airbnb" android:host="d"/>
165 Followers 3K FollowingPro Uk and Europe IT Recruiter specialized in hunting quality profiles... Hiring for Devops, Cloud, Java Engineers in London, UK
233K Followers 1K FollowingCofounder @hackinghub_io | Advisor @CaidoIO. I hack companies and make content about it. #NahamCon organizer. ex @hacker0x01🇮🇷
37K Followers 503 FollowingHacker, bug bounty hunter, guy behind https://t.co/TBAtP71Cop. 1st in Meta bug bounty program for the last 6 years. YES Team Member
3K Followers 371 FollowingResearch, prototype and build security tools for fun and profit. Author: MobSF, nodejsscan. Founder: @OpenSecurity_IN, @OpSecX.
43K Followers 897 FollowingCo-founder of @centrahq/@detectify/@poweredbyingrid. I do not advertise doing hacking services, do not trust the ones telling you I do.
7K Followers 186 FollowingRanked as the #1 security researcher for Google Play Security Rewards Program. The founder of @OversecuredInc Android and iOS vulnerability scanners