Web Security | Bug hunting
@cybersecurityresources
7.3K
subscribers
46
photos
2
files
473
links
A web penetration testing / General cybersecurity / Network related topics channel that provides direct links for interesting resources and notes.
Download Telegram
Join
Web Security | Bug hunting
7.3K subscribers
Web Security | Bug hunting
https://www.youtube.com/watch?v=08MkzhK1pyU
Web Security | Bug hunting
Toolkit to detect and keep track on Blind XSS, XXE & SSRF
https://github.com/SpiderMate/B-XSSRF
GitHub
GitHub - SpiderMate/B-XSSRF: Toolkit to detect and keep track on Blind XSS, XXE & SSRF
Toolkit to detect and keep track on Blind XSS, XXE & SSRF - SpiderMate/B-XSSRF
Web Security | Bug hunting
https://medium.com/@unknownuser1806/problems-i-have-faced-in-bug-bounty-3c9d0a679d8b
Medium
Problems I have faced in Bug Bounty
This is my second blog about #bugbounty.You can check out my first blog that is full of resources and content for bug bounty hunters. If…
Web Security | Bug hunting
https://medium.com/@terjanq/blind-sql-injection-without-an-in-1e14ba1d4952
Medium
Blind SQL Injection without an “in”
Alternative ways to retrieve table names in MySQL — without information_schema.
Web Security | Bug hunting
https://hipotermia.pw/bb/http-desync-account-takeover
hipotermia.pw
hipotermia - Account takeover via HTTP Request Smuggling
A bug chain of HTTP Request Smuggling that led to account takeover
Web Security | Bug hunting
https://hackbotone.com/blog/10-recon-tools-for-bug-bounty
Web Security | Bug hunting
https://medium.com/cyberverse/crlf-injection-playbook-472c67f1cb46
Medium
CRLF Injection Playbook
Hello Guys,
Just a Rough analysis of bugs Disclosed Publicly about CRLF injection
Web Security | Bug hunting
https://twitter.com/mashoud1122/status/1221855871711547397
Web Security | Bug hunting
https://medium.com/@vbharad/account-takeover-through-password-reset-poisoning-72989a8bb8ea
Medium
Account Takeover Through Password Reset Poisoning
Introduction :
Web Security | Bug hunting
https://blog.intigriti.com/2020/02/24/twitter-recap-1-bug-bounty-tips-by-the-intigriti-community/
Intigriti
Twitter Recap #1 - Bug Bounty Tips by the Intigriti Community
Bug Bounty Tips Over the past years we have shared a lot of tips to help our readers in one way or another. Thinking outside the box or trying a different approach could be the defining factor in...
Web Security | Bug hunting
https://www.youtube.com/watch?v=Jd-6ezrpxJc
YouTube
PHP PHAR - file_exists can be dangerous
Today in "from 0 to pentesting hero" we will talk about a function that checks if a file with the given name exists on the hard drive.
Could such a simple functionality be harmful? You will find out in today's episode.
Blackhat presentation: https://github.com/s…
Web Security | Bug hunting
https://medium.com/@ozguralp/weird-vulnerabilities-happening-on-load-balancers-shallow-copies-and-caches-9194d4f72322
Medium
Weird Vulnerabilities Happening on Load Balancers, Shallow Copies and Caches
When looking for security vulnerabilities on a web application - either for bug hunting or a penetration test project -, I always check 2…
Web Security | Bug hunting
https://lab.wallarm.com/blind-ssrf-exploitation/
Wallarm
Blind SSRF exploitation
❗️
- Wallarm
SSRF exploitation. There is such a thing as SSRF. There’s lots of information about it, but here is my quick summary.
🔍
Web Security | Bug hunting
https://blog.intigriti.com/2020/02/27/twitter-recap-2-polls-by-the-intigriti-community
Intigriti
Twitter Recap #2 - Polls by the Intigriti Community - Intigriti
Insights from Europe’s #1 ethical hacker community As a community-driven platform, we build upon the insights and feedback from our valuable hackers. Over the past few months, we’ve asked our researcher community various questions concerning bug bounties…
Web Security | Bug hunting
https://www.youtube.com/watch?v=t5fB6OZsR6c
YouTube
Exploiting a Server Side Request Forgery (SSRF) in WeasyPrint to hack Lyft & HackerOne’s $50M CTF
Purchase my Bug Bounty Course here
👉🏼
bugbounty.nahamsec.training
Live every Sunday on Twitch:
https://twitch.tv/nahamsec
Follow me on social media:
https://twitter.com/nahamsec
https://instagram.com/nahamsec
https://twitch.com/nahamsec
https://hackerone.com/nahamsec…
Web Security | Bug hunting
https://www.youtube.com/watch?v=oWRseGm-a6I
YouTube
[BURP] 12 tricks for Burp Repeater
Repeater is one of the most frequently used part of Burp Suite. But there is plenty of hidden features there. Do you know all of them? Check my video with 12 tricks.
0:09 Change tab name
0:24 Restore closed tab
0:44 Request history
0:55 Auto scroll
1:19…
Web Security | Bug hunting
https://medium.com/@bhaveshthakur2015/account-hijack-using-authorization-bypass-which-made-me-richer-by-ba9dace72682
Medium
Account Hijack using Authorization bypass $$$$
Hello readers,
Web Security | Bug hunting
https://twitter.com/YourNextBugTip/status/1233956268072521728
Web Security | Bug hunting
https://twitter.com/Bayufedraa/status/1232946137763442688
Web Security | Bug hunting
https://youtu.be/WC5kUPwzUtk
Web Security | Bug hunting
https://medium.com/@timpaxerror/page-admin-disclosure-via-an-upgraded-page-post-57863fb02c50
Medium
Page Admin Disclosure via an Upgraded Page Post
Been in the bug bounty and/or ethical hacking scene for more than 2 years now and this is my first write-up (I hope you bear with me)…