Web Security | Bug hunting
@cybersecurityresources
7.18K
subscribers
46
photos
2
files
473
links
A web penetration testing / General cybersecurity / Network related topics channel that provides direct links for interesting resources and notes.
Download Telegram
Join
Web Security | Bug hunting
7.18K subscribers
Web Security | Bug hunting
https://github.com/hisxo/gitGraber
GitHub
GitHub - hisxo/gitGraber: gitGraber: monitor GitHub to search and find sensitive data in real time for different online services…
gitGraber: monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github, Mailgun, Facebook, Twitter, Heroku, Stripe... - hisxo...
Web Security | Bug hunting
https://blog.usejournal.com/graphql-bug-to-steal-anyones-address-fc34f0374417
Medium
Graphql Abuse to Steal Anyone’s Address
Introduction
Web Security | Bug hunting
https://medium.com/@saadahmedx/complete-web-server-access-46d19279a2b
Medium
Complete Web Server Access
Hi guy I am back with another POC that I found in PRIVATE program on bugcrowd let get started. So let assume the SITE name private.com I…
Web Security | Bug hunting
https://medium.com/@cc1h2e1/write-up-of-two-http-requests-smuggling-ff211656fe7d
Medium
Write up of two HTTP Requests Smuggling
This article about how I found two sites for HTTP Request Smuugling
Web Security | Bug hunting
https://medium.com/@heinthantzin/how-does-my-recon-win-250-in-15-minutes-a1992508b911
Medium
How does my recon win $250 in 15 minutes
Hi there again,
Web Security | Bug hunting
https://medium.com/@jayateerthag/google-referer-leak-bug-434f6293ce66
Medium
GOOGLE REFERER LEAK BUG
I followed the usual Recon process after enumerating subdomains ,
Web Security | Bug hunting
http://tweetedtimes.com/v/1939
Web Security | Bug hunting
cyberscurity books :
https://mega.nz/#F!oawFzJiI!nYW_l4i1a61QtyuS18GnnA
mega.nz
MEGA provides free cloud storage with convenient and powerful always-on privacy. Claim your free 20GB now
Web Security | Bug hunting
https://github.com/BugHunterID/bugbounty-cheatsheet
GitHub
GitHub - BugHunterID/bugbounty-cheatsheet: A list of interesting payloads, tips and tricks for bug bounty hunters.
A list of interesting payloads, tips and tricks for bug bounty hunters. - BugHunterID/bugbounty-cheatsheet
Web Security | Bug hunting
https://github.com/AlexisAhmed/hacker101
GitHub
GitHub - AlexisAhmed/hacker101: Hacker101
Hacker101. Contribute to AlexisAhmed/hacker101 development by creating an account on GitHub.
Web Security | Bug hunting
https://github.com/AlexisAhmed/Awesome-Red-Teaming
GitHub
GitHub - AlexisAhmed/Awesome-Red-Teaming: List of Awesome Red Teaming Resources
List of Awesome Red Teaming Resources. Contribute to AlexisAhmed/Awesome-Red-Teaming development by creating an account on GitHub.
Web Security | Bug hunting
https://medium.com/@akshukatkar/rce-with-flask-jinja-template-injection-ea5d0201b870
Medium
RCE with Flask Jinja Template Injection
I got invite for private program on bugcrowd. Program do not have huge scope , just a single app with lots of features to test. I usually…
Web Security | Bug hunting
https://medium.com/@vickieli/how-to-find-more-idors-ae2db67c9489
Medium
How to find more IDORs
And maximize their impact while hunting for bugs.
Web Security | Bug hunting
https://medium.com/@unknownuser1806/problems-i-have-faced-in-bug-bounty-3c9d0a679d8b
Medium
Problems I have faced in Bug Bounty
This is my second blog about #bugbounty.You can check out my first blog that is full of resources and content for bug bounty hunters. If…
Web Security | Bug hunting
CyberSecurity Courses :
https://mega.nz/?fbclid=IwAR1CuD7uIQX_FcA4e5YkVVMOCDZQ5vvHuLwCpgyPVu3HDB4lG7wgIThRx70#F!cRUAyIoL!SDxFAneySUrA6U4nuewW4Q
mega.nz
MEGA provides free cloud storage with convenient and powerful always-on privacy. Claim your free 20GB now
Web Security | Bug hunting
https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/
Invicti
SQL Injection Cheat Sheet
The Invicti SQL Injection Cheat Sheet is the definitive resource for payloads and technical details about exploiting many different variants of SQLi vulnerabilities.
Web Security | Bug hunting
https://addictivehackers.blogspot.com/2015/07/self-xss-to-stored-xss-on-zendesk.html
Blogspot
Self -Xss to Stored Xss On Zendesk
All about hacking, here you can learn all new methods of hacking ,
Web Security | Bug hunting
https://medium.com/@SundownDEV/phone-number-scanning-osint-recon-tool-6ad8f0cac27b
Medium
Building an OSINT Reconnaissance Tool from Scratch
Everyone has a phone, using at least one phone number. Phone numbers are a very common resource for Social Engineering. It’s something we…
Web Security | Bug hunting
https://medium.com/@04sabsas/bugbounty-writeup-creative-thinking-is-our-everything-race-condition-business-logic-error-2f3e82b9aa17
Medium
BugBounty WriteUp — Creative thinking is our everything (Race Condition + Business Logic Error)
Story about Race Condition and understanding the logic of application
Web Security | Bug hunting
https://anotherhackerblog.com/exploiting-file-uploads-pt-2/
Web Security | Bug hunting
https://medium.com/@adrien_jeanneau/how-i-was-able-to-list-some-internal-information-from-paypal-bugbounty-ca8d217a397c
Medium
How I was able to list some internal information from PayPal #BugBounty
TL;DR : A page on domain manager.paypal.com was vulnerable to “Expression Language Injection” (JSTL) and I was able to extract some…
TWeb.init({scrollToPost:'cybersecurityresources/169'});