Hi everyone! I have just released a new video in which i tested some of the popular tools on target protected by WAF.
To know which tool is better, Check out the video:
https://youtu.be/_oLyUxRMnJk
To know which tool is better, Check out the video:
https://youtu.be/_oLyUxRMnJk
YouTube
Testing XSS Tools On Target Protected By WAF | 2024
In this video, we dive into the world of web application security by testing various XSS tools on a target protected by a Web Application Firewall (WAF). We'll explore how effective different XSS tools are at bypassing WAF defenses and highlight techniques…
❤10👍3👎1🔥1
For those who have registered into the workshop which is going to be held on 20th July 2024, Your mobile number will be added in our group on 18th July 2024.Thank you. Keep learning, Keep Hacking!!!
👍3
Bug Bounty Tip: While testing on endpoints like /uploadedFiles or /uploads where you think that the app is storing files..make sure to look for common files (like .txt,.pdf,.zip,.tar.gz)
In a recent penetration testing engagement, I was able to uncover sensitive log files and some invoices of a company using this same method!
Keep Hacking!
In a recent penetration testing engagement, I was able to uncover sensitive log files and some invoices of a company using this same method!
Keep Hacking!
👍26❤6🔥5
Hi everyone, I have recently found an interesting vulnerability which allowed me to get all the exposed log files that contains juicy information like hidden directories, credentials etc
Here's the methodology:
1. Did initial content discovery and found /system endpoint (It was giving 403 error)
2. Then i went to discover content inside the "/system" directory and found "/system/logs"
3. Finally, Got the log files!!!
Here's the methodology:
1. Did initial content discovery and found /system endpoint (It was giving 403 error)
2. Then i went to discover content inside the "/system" directory and found "/system/logs"
3. Finally, Got the log files!!!
❤33👍13🔥5😁2
Hi guys! I hope you all are doing well. First of all, I am really sorry that i am not uploading any videos for a long time. To be honest, I was not feeling well and lot of other things were happening at the same time so couldn't get the time to upload new videos. However, I will try my best to be active from now on & help the cyber security community with whatever i can!!
With that being said, Let me share an exciting news with you all. I am happy to share that i am currently ranking as number 1 hacker in one of the private VDP programs on hackerone! The only suggestion/advise i can give you all is:- Focus on 1 target & hunt on it for months!
Keep learning & Keep hacking🔥
With that being said, Let me share an exciting news with you all. I am happy to share that i am currently ranking as number 1 hacker in one of the private VDP programs on hackerone! The only suggestion/advise i can give you all is:- Focus on 1 target & hunt on it for months!
Keep learning & Keep hacking🔥
🔥17👍11❤10
Hi everyone! After a long time, Here's my new video that will help you to effectively recon on large scopes to discover content or sensitive files on your large scope based targets!
https://youtu.be/ie84NeBxPCM
https://youtu.be/ie84NeBxPCM
YouTube
Bug Bounty: Content Discovery on Large Scope Like a Pro! | 2024
Are you ready to take your content discovery game to the next level? In my latest video, I dive deep into how you can approach large-scope targets like a pro using the powerful tool, meg by tomnomnom. If you’ve ever felt overwhelmed by the sheer size of your…
❤11👍1
Sometimes i feel like h1 triager's goal is to just mark every report as "Informative"
I have recently submitted a report the a private company which was marked as Informative by H1 security analyst. I knew it was a valid security issue so i asked for mediation and the internal staff from the company then finally triaged the report
I have recently submitted a report the a private company which was marked as Informative by H1 security analyst. I knew it was a valid security issue so i asked for mediation and the internal staff from the company then finally triaged the report
👏16❤3👍1
To all my mates from our beloved country India, Happy Independence Day 🇮🇳
❤24🔥6👍2❤🔥1😇1
We’ve Reached 20K Subscribers on YouTube!
I can’t put into words how grateful I am today. Just a few months ago, we celebrated 10K subscribers, and now, we’re a community of over 20,000! I’m truly thankful to each and every one of you for your incredible support and encouragement throughout this journey.
To show my appreciation, I’m planning to host a free 2-hour webinar on bug bounty (I’ll announce the topic and date soon).
Thank you all so much from the bottom of my heart. Let’s keep learning and keep hacking together!
I can’t put into words how grateful I am today. Just a few months ago, we celebrated 10K subscribers, and now, we’re a community of over 20,000! I’m truly thankful to each and every one of you for your incredible support and encouragement throughout this journey.
To show my appreciation, I’m planning to host a free 2-hour webinar on bug bounty (I’ll announce the topic and date soon).
Thank you all so much from the bottom of my heart. Let’s keep learning and keep hacking together!
❤22👍6🔥3👎1🕊1
Hi everyone! Just wanted to update you all with our website. Our website is down because of the vps service provider have banned it for some reason. We are trying our best to communicate with them & hope to make it live soon.
❤9
For the last few months, I am using macbook for hacking and the experience is amazing! Even though my windows machine has a lot better specs that Mac, but still this device outperforms mine in terms of hacking, video editing, battery life etc.. I really love it!
Here's how I use my Mac for hacking:
Installed Kali Linux with Vmware Fusion(works amazing)
Installed some tools directly on my machine like ffuf, nuclei, wpscan etc through brew
btw guys, do let me know what machine do you all use for hacking!
Here's how I use my Mac for hacking:
Installed Kali Linux with Vmware Fusion(works amazing)
Installed some tools directly on my machine like ffuf, nuclei, wpscan etc through brew
btw guys, do let me know what machine do you all use for hacking!
👍10❤8🔥2
Hi guys, In case you are free then do checkout this awesome report: https://hackerone.com/reports/180074
HackerOne
Paragon Initiative Enterprises disclosed on HackerOne: BAD Code !
he is don't know anything about coding .. as we learned in PHP .. if we start an PHP file by <?php we should close it by ?>.. anyway .. ok .. here is example >>
<?php
echo "Hello world";
?>
<?php
echo "Hello world";
?>
🤣20😁7