Bug bounty can be a cruel mistress sometimes.
Dupes, downgrades, mass closes and misunderstandings get us all down.
Solid tips were dropped on the pod last week to help in these times.
Here are 14 of them.
🔔 New topic alert: Web LLM attacks 🔔
Stay ahead in application security - dive into the world of LLMs to discover their weaknesses and understand how to exploit them.
Read our latest learning materials and try your hand at the new interactive labs.
portswigger.net/web-security/l…
Great news! Our Proxy Enriched Sequence Diagrams (PSED) Exporter tool is fully integrated in #Burpsuite & in the BApp Store. You'll love how it creates professional diagrams & helps communicate complicated traffic flows. Install today!
#doyensec#appsecportswigger.net/bappstore/3c1b…
Here's another "meta" long-form hacking tip that has paid its weight in gold.
== Don't rely on TOO much automation ==
A thread 🧵
🚨follow, retweet, & like for more 🚨
Some examples:
👇
1/x
= Infosec super-thread =
A big part of my presos is tools/resources I like for offensive security & bug hunting.
Here's a thread of "PRINT" resources cited in the Bug Hunter's Methodology Application Analysis v1
docs.google.com/presentation/d…
a 🧵
#bugbountytips#Pentesting
1/x
You can now trigger file-upload XSS with no user-interaction using a technique spotted by @kkotowicz. We've just added it to our XSS cheat sheet:
portswigger.net/web-security/c…
We've launched the long-awaited @WebSecAcademy HTTP/2 topic! Learn about and practice HTTP/2 request smuggling, request tunnelling, and response queue poisoning! portswigger.net/web-security/r…
236 Followers 563 FollowingBug Bounty Hunter | Web App Hacker | Red Team Specialist | Finding vulnerabilities, exploiting weaknesses, and securing the web one app at a time. ▂▃▄▅▆▇█
187K Followers 105 FollowingWe're sharing/showcasing best of @github projects/repos. Follow to stay in loop. Promoting Open-Source Contributions. UNOFFICIAL, but followed by github
2K Followers 6 FollowingHacktron is an autonomous vulnerability hunter for ambitious engineering teams. Built by world-class security researchers. Powered by one principle: PoC || GTFO
10K Followers 6 FollowingBringing AI to offensive security by autonomously finding and exploiting web vulnerabilities. Watch XBOW hack things: https://t.co/D5Mco1u8zM
236 Followers 563 FollowingBug Bounty Hunter | Web App Hacker | Red Team Specialist | Finding vulnerabilities, exploiting weaknesses, and securing the web one app at a time. ▂▃▄▅▆▇█
8K Followers 206 Following#1 Hacker at BugCon LHE Mexico 2021 & 2022 | Top Ranked in H1 Mexico Leaderboard 2021, 2022, 2023, 2024 | Offensive Security Engineer | Tweets are my own
16K Followers 781 Following🔍 Top 100 Bug Bounty Hunter @ Bugcrowd | 🇩🇴 Dominican | Ethical hacking fanatic | 🎮🎵 Lover | Keeping the digital world safe. opinions are that of my own
7K Followers 140 FollowingWe create content and manage socials for your cybersecurity organization. 🚀
Sound good? 👉 https://t.co/H8NucTI4zJ
Founded by @hakluke
3K Followers 513 FollowingHacker | I try to hack things, or whatever. Memes are my own and represent my employer (me) | Formerly @microsoft & BB triage
26K Followers 2 FollowingOffensiveCon Berlin is a technical international security conference focused on offensive security only. Organised by @Binary_Gecko. Stay tuned #OffensiveCon26.
83K Followers 16 FollowingTrend Zero Day Initiative™ (ZDI) is a program designed to reward security researchers for responsibly disclosing vulnerabilities.
108K Followers 2 FollowingMonitor your external network, search the Internet of Things and perform empirical market research. You can also find us on https://t.co/nPLFbFy8R5
4K Followers 543 Following• Irish/Japanese web hacker living in Scotland.
• Researcher for @ctbbpodcast Lab.
I run https://t.co/Ja1P3vco1X | Newsletter weekly at https://t.co/KA5b2kY8ih