⚡Bug Bounty Reports Extractor - CLI tool that fetches resolved & disclosed HackerOne reports by vulnerability and exports them to CSV.
✅ https://github.com/newstartlikenoneanthor-pixel/report-extractor
✅ https://github.com/newstartlikenoneanthor-pixel/report-extractor
❤17🔥6😱2
Please open Telegram to view this post
VIEW IN TELEGRAM
Medium
Best Bug Bounty and Pentesting Methodology for Beginners: A Step-by-Step Guide
Bug bounty programs and penetration testing (pentesting) are popular ways for ethical hackers to make money while helping companies enhance…
1❤13👍4🔥3👏1
This media is not supported in your browser
VIEW IN TELEGRAM
"© <COMPANY>. all rights reserved." -".<COMPANY>.com"Please open Telegram to view this post
VIEW IN TELEGRAM
🔥17❤7👍4😱1
Hey Hunter's,
DarkShadow here back again!
A hidden backdoor was in PHP version which allow remote code execution In user-agent header.
Guess Guy's which version it is?
#backdoor
DarkShadow here back again!
A hidden backdoor was in PHP version which allow remote code execution In user-agent header.
Guess Guy's which version it is?
#backdoor
❤19😁2👨💻1
site:example[.]com ext:log | ext:txt | ext:conf | ext:cnf | ext:ini | ext:env | ext:sh | ext:bak | ext:backup | ext:swp | ext:old | ext:~ | ext:git | ext:svn | ext:htpasswd | ext:htaccess | ext:json
Please open Telegram to view this post
VIEW IN TELEGRAM
❤30👍13🔥6
Please open Telegram to view this post
VIEW IN TELEGRAM
1🔥24❤8👍4👏4🤝1
Please open Telegram to view this post
VIEW IN TELEGRAM
❤14👍9👏2
Google Dork - XSS Prone Parameters 🔥
site:example[.]com inurl:q= | inurl:s= | inurl:search= | inurl:query= | inurl:keyword= | inurl:lang= inurl:&Please open Telegram to view this post
VIEW IN TELEGRAM
👍11❤8🤨1
Please open Telegram to view this post
VIEW IN TELEGRAM
❤10👍4🔥3👏2
⌨️
wget -r --no-parent -R "index.html*" wordlists-cdn.assetnote.io/data/ -nH -e robots=offPlease open Telegram to view this post
VIEW IN TELEGRAM
🔥13
Please open Telegram to view this post
VIEW IN TELEGRAM
owasp-noir.github.io
OWASP Noir
👍13
Hey Hunter's,
DarkShadow here back again!
SSRF in pdf generation!
this api endpoint send the pdf generation request:
POST /api/v1/convert/markdown/pdf
Add this payload:
<img src=‘burp collab url’ />
comes 200ok and hit request in burp collaborator.
You can follow me in my x.com/darkshadow2bd
#ssrf #bugbountytips
DarkShadow here back again!
SSRF in pdf generation!
this api endpoint send the pdf generation request:
POST /api/v1/convert/markdown/pdf
Add this payload:
<img src=‘burp collab url’ />
comes 200ok and hit request in burp collaborator.
You can follow me in my x.com/darkshadow2bd
#ssrf #bugbountytips
❤14🔥4