BePractical – Telegram
BePractical
7.4K subscribers
232 photos
24 videos
6 files
395 links
If you have any doubts then email at faiyazahmad.online@gmail.com
Download Telegram
Upcoming topics for the video
Anonymous Poll
39%
IDOR
32%
SQL Injection
23%
CSRF Automation
6%
Other
👍1
This media is not supported in your browser
VIEW IN TELEGRAM
18K subs completed!!!
Thank you all for all the support & love you guys have given me❤️

Keep showing your support and we will reach up to 20k soon!!
👏117🔥2🥰1
These are the two books that i often read to get a better understanding of vulnerabilities!
Bug Bounty Bootcamp by Vickie Li
Real World Bug Hunting by Peter Yaworski

What books do you read? Let me know in the comments!
👍16
What is your level in ethical hacking or bug bounty?
Anonymous Poll
56%
Beginner
36%
Intermediate
8%
Advanced
8👍2
Hi everyone! New video will be releasing soon in the next week! Stay Tuned
13👍1
Should I start another batch for Web Recon workshop in July?
Anonymous Poll
79%
Yes
21%
No
👍1
Hi everyone! Here's a small task for all of you

Can you find the subdomain on which this webpage is hosted?😉
3👍3
Another task!

Can you find the subdomain on which this webpage is hosted?

Difficulty Level: High~Medium
Once you have solved this challenge, please write a small writeup and send it to business@bepractical.tech

The people who will be able to solve both of these challenge will receive a shoutout in the upcoming video!

Challenge ends in 10 hrs
How many of you are trying to solve these challenges?
Anonymous Poll
59%
Me
41%
Not Me
👍62😁1
Hi everyone, The solution for task two is not on main.bepractical.tech
Actually that subdomain was used as a subdomain takeover lab and some participant have exploited it & uploaded the same webpage given as the challenge. We have removed every lab's dns record for now. The time duration for this challenge is now also increased to 24 hrs. ( It will expire on 1st July 2024 at 7pm IST)

Currently no one is able to find the solution for task 2!
2
Hint: It is a reconnaissance challenge so please don't focus on finding or exploiting any vulnerabilities!
😁3
Hint 2: It is not related to content discovery 😉
😁3
So far, no one is able to solve the second challenge! The challenge will end at 7:00pm IST
👍4😁1
Congratulations Mehraj for solving both of the challenges🥳🥳🥳
👏7
The challenge has been ended now! (Only three people were able to solve both of the challenges)
Congrats to Mehraj, Abhisekh and Akshit for successfully solving the challegnge!🥳🥳🥳
Media is too big
VIEW IN TELEGRAM
Here is the solution for both of the challenges!

We will be conducting a web recon workshop again for beginner-intermediate bug bounty hunters where you will learn how to dive deep into the target in this month! Stay Tuned
11👍2
In a recent penetration testing engagement, I was able to find an api endpoint which was disclosing every user's information present on the web page without any authentication!!

Here's what i did:
1. Used ffuf with valid cookies and headers to enumerate the content.
2. After the discovery of this endpoint, I simply remove the required cookies & headers.
3. I was still able to fetch the data!

As always, a proper reconnaissance is necessary to uncover interesting vulnerabilities!
22🔥6👍2
Finally we have completed our first workshop i.e Web Reconnaissance! I really hope that all our participants have learned something new & interesting that will help you all to upskill your recon game! Keep Hacking Everyone🤖
🥰9👍51
New Batch for this same workshop will be releasing soon this month! Stay Tuned❤️
7👍1
New video will be releasing within an hr!
👍74