👨💻 Senior Security Consultant at @RedHuntLabs
🖥️ https://t.co/hAlhW0Tc2n In IT
🎭 Certified Ethical Hacker
👨💻 Penetration Tester
🇮🇳 CTF Player
💻 Programmer IndiaJoined April 2015
Bounty : 3,000,000 IDR
Bug : SQL injection UNION and BOOLEAN
Details : Found a GraphQL API , in request found Regin parameter. initially tried with basic payloads. After keeping testing found there was Boolean based vulnerability with payload : -1' OR 3*2*0=6 AND 000579=000579
Bug Bounty Tip
When testing an app for SQL injection, don't forget to check the form keys in addition to the values.
To bypass spaces, you can use the encoded tab %09. For other symbols, simply URL encode them
Hello everyone ♥
a little bit write-up of #bugbountytip#bugbountytips I am going to write here .....
Title:
getting unauthorized access on 3rd party's/workspaces & and building your checklist for quickly locating bugs there via massive recon
we know that its helpful to look…
Cybersecurity Meets Creativity—In the most epic way possible! 🎶❤️🔥
Introducing: "RedHunt Labs ASM: No Room to Hide" – the cybersecurity song you never knew you needed, but now going straight into your playlist. 🤩
Start Vibing Now 🎧: youtube.com/watch?v=LSnP_1…
This song is a…
Basic Static Analysis Script
(to find possible #XSS in source code)
#!/bin/bash
# 1) save it as xssaminer
# 2) allow execution: chmod +x xssaminer
# 3) run it & check usage: ./xssaminer
if [ -z $1 ]
then
echo -e "Usage:\n$0 FILE\n$0 -r FOLDER"
exit
else
f=$1
fi
sources=(GET…
We finally did it—turned those little profile pictures into real people! After what feels like ages of digital meetings and mystery voices, the @RedHuntLabs team hit Nainital to see who’s who in real life. Spoiler Alert: everyone’s even cooler off-screen! 😎
For four days, we…
I made a new tool called ServiceLens that maps services linked to a target's domain. This gives me insight into a good phishing template for the customer.
Spending time on a good template that mixes in with the normal traffic helps a lot.
github.com/nullenc0de/ser…
Screenshot:
If you have access to #jenkins dashboard
use below Script Console cmd for poc
```
def passwdFile = new File("/etc/passwd")
println passwdFile.text
```
#P1#bugbountytips #bugbounty
Vegas Calling! ❤️🔥 Cyber Enthusiasts favourite week of the year is here! 🤩
@RedHuntLabs crew is all set to touchdown at @BlackHatEvents USA 2024 and @defcon 32, and we can't wait to hang out with y'all between 24 July 2024 and 11 August 2024 in San Francisco/ Las Vegas.…
Found a GraphQL endpoint that you want to test? InQL is just for you!
InQL is an awesome BurpSuite extension for advanced GraphQL pentesting!! 😎
Check it out 👇
github.com/doyensec/inql
Just used
echo site.com | gau | httpx -mc 200 | grep .zip
To find valid URLs with .zip extensions. Found a zip file, but after downloading, a Java code exposed JDBC configuration! 💡🔒 #bugbountytips
Duplicate but high severity
@ADITYASHENDE17#kongsec
Voting is now live for the Top ten web hacking techniques of 2023! Make a brew, browse the nominations, and cast a vote for your personal top ten here: portswigger.net/polls/top-10-w…
7K Followers 2K FollowingGlobal leader in hands-on learning for enterprise and cloud security education. Join 40000+ infosec professionals from 130+ countries
54 Followers 827 FollowingMy Goal is Change My Country
India is super powerful country of World
HELP INDIA PUBLIC
🇮🇳JAI HIND JAI BHARAT 🇮🇳
I LOVE MY INDIA
36K Followers 2K FollowingExpert web3 bug bounty and crowdsourced audit platform with 220 programs and over 20 million in bounty
DS: https://t.co/41lshly4dI
YT: https://t.co/cLUr6ODztP
392 Followers 1K FollowingInterested in Software Security | Life Long Learner | Love to learn, how things work under the hood | Always Philosophically intrigued.
10K Followers 1 FollowingUser friendly unofficial HackerOne public disclosures, keeps you updated about the recently disclosed bugs.
Made With ♥ By Hackers For Hackers. - @rohsec
20K Followers 439 FollowingHacker, Infosec Researcher, Military Affairs & History, PowerShell, AD and Azure pwner, Creator of Nishang and others :)
Founder @alteredsecurity
7K Followers 2K FollowingGlobal leader in hands-on learning for enterprise and cloud security education. Join 40000+ infosec professionals from 130+ countries
36K Followers 2K FollowingExpert web3 bug bounty and crowdsourced audit platform with 220 programs and over 20 million in bounty
DS: https://t.co/41lshly4dI
YT: https://t.co/cLUr6ODztP
8K Followers 2K FollowingIndependent Smart Contract Researcher & Researcher at @ShieldifySec
My mission is to find vulnerabilities in smart contracts for a safer Web3 Space!
10K Followers 17 FollowingAnd there is fire where we walk. they/them
Find our active account here: https://t.co/Q3se8nVme8
Also, fuck you very much, @elonmusk
1K Followers 5K FollowingWe are building vulnerable applications using #Kotlin for education purposes #hpAndro 🏁 https://t.co/CDWDpr5xbv 🎥 https://t.co/mpKwPhklRn
6K Followers 7 FollowingI retweet all the tweets with #opensource to support the community. ❤️
Build your on-chain developer reputation using @SadaivCI 🚀
7K Followers 45 Followinghuntr provides a single place for security researchers to submit vulns, to ensure the security and stability of AI/ML applications on OSS.
810 Followers 2 FollowingUnofficial @huntrdev public disclosure watcher who keeps you up to date about the recently disclosed bugs. Maintained by @dwisiswant0.
56K Followers 3 FollowingOfficial account maintained by the CVE™ Program to notify the community of new CVE IDs. Posts contain abbreviated details. Full CVE Records on https://t.co/ALn4YvUtom
210 Followers 65 FollowingFor over 20 years, leading companies in Cybersecurity, Healthcare, Finance, New Media and more have come to rely on Loginsoft as a trusted technology partner.
1.1M Followers 20 FollowingLimitless innovation. ☁️ Follow along for the latest news and resources from the official #MicrosoftAzure team. For help, contact @AzureSupport.
3K Followers 828 FollowingReconshell - Our tutorials, case studies, Ethical Hacking, Penetration Testing Tools will prepare you for the upcoming, potential threats in the cyber security
342 Followers 8 FollowingOfficial Twitter account of @owasp DKTE Chapter for Application and Cyber Security
Tweets and DM's managed by @impramodsargar & @AnubhavSingh_
No recent Favorites. New Favorites will appear here.