BugBounty & Hacking Resources
@projectzeroTM
1.18K
subscribers
22
photos
2
videos
5
files
362
links
Download Telegram
Join
BugBounty & Hacking Resources
1.18K subscribers
BugBounty & Hacking Resources
https://lite.evernote.com/note/3c0c0a20-1b65-10b8-b710-0c4a2a4e209d
🔥
4
BugBounty & Hacking Resources
https://x.com/garethheyes/status/1851614921936552330?t=kavctqknDdpkIftgOKcr4A&s=19
❤
1
BugBounty & Hacking Resources
https://x.com/NahamSec/status/1851818696685314160
❤
4
🔥
2
BugBounty & Hacking Resources
https://mizu.re/post/heroctf-v6-writeups
mizu.re
HeroCTF v6 Writeups. Tags:Writeups - Writeups - Web
❤
1
BugBounty & Hacking Resources
https://rikeshbaniya.medium.com/tale-of-zendesk-0-day-and-a-potential-25k-bounty-61bcf9c5dc06
Medium
User info extraction abusing placeholder injection in Zendesk
In this blog, I will share how I found template injection affecting Zendesk customers with default configuration.
🔥
2
BugBounty & Hacking Resources
https://x.com/kinugawamasato/status/1816234368714871185
X (formerly Twitter)
Masato Kinugawa (@kinugawamasato) on X
ooh, this works on Chrome Canary :D
<input type="hidden" oncontentvisibilityautostatechange="alert(/ChromeCanary/)" style="content-visibility:auto">
🔥
3
BugBounty & Hacking Resources
https://swisskyrepo.github.io/PayloadsAllTheThings/XSS%20Injection/#xss-in-noscript
swisskyrepo.github.io
Cross Site Scripting - Payloads All The Things
Payloads All The Things, a list of useful payloads and bypasses for Web Application Security
❤
2
🔥
2
BugBounty & Hacking Resources
https://www.wetest.net/blog/a-comprehensive-guide-to-xss-attacks-and-defenses-862.html
www.wetest.net
A Comprehensive Guide to XSS Attacks and Defenses
This article provides a detailed introduction to XSS(Cross Site Scripting) vulnerability attacks and defenses, including vulnerability basics, XSS fundamentals, encoding basics, XSS Payload, and XSS attack defense.
❤
2
🔥
2
BugBounty & Hacking Resources
https://medium.com/@mrhavit/breaking-tiktok-our-journey-to-finding-an-account-takeover-vulnerability-b0646aba1c4b
Medium
Breaking TikTok: Our Journey to Finding an Account Takeover Vulnerability
Hello, fellow security researchers and bug bounty hunters!
❤
3
BugBounty & Hacking Resources
https://www.yeswehack.com/learn-bug-bounty/dom-explorer-tool-parse-html?utm_source=twitter&utm_medium=social&utm_campaign=dom-explorer-tool
YesWeHack
Dom-Explorer launched to reveal how browsers parse HTML, mutated XSS
Learn about Dom-Explorer, a new open-source tool for understanding how popular browsers parse HTML and uncovering mutation XSS vulnerabilities.
🔥
2
❤
1
BugBounty & Hacking Resources
https://www.mdsec.co.uk/2024/10/when-wafs-go-awry-common-detection-evasion-techniques-for-web-application-firewalls/
MDSec
When WAFs Go Awry: Common Detection & Evasion Techniques for Web Application Firewalls - MDSec
Web Application Firewalls (WAFs) help to protect web applications by monitoring, filtering, and blocking HTTP traffic to and from a web service. However, WAFs are too often relied upon as...
🔥
2
❤
1
BugBounty & Hacking Resources
https://x.com/05__Yash/status/1853803857433837638
❤
2
BugBounty & Hacking Resources
https://x.com/0x0SojalSec/status/1853532267215519991
❤
2
🔥
2
BugBounty & Hacking Resources
https://blog.sicuranext.com/breaking-down-multipart-parsers-validation-bypass/
Sicuranext Blog
Breaking Down Multipart Parsers: File upload validation bypass
TL;DR: Basically, all multipart/form-data parsers fail to fully comply with the RFC, and when it comes to validating filenames or content uploaded by users, there are always numerous ways to bypass validation. We'll test various bypass techniques against…
❤
2
BugBounty & Hacking Resources
https://x.com/d4d89704243/status/1854562239547674971
👍
4
🔥
2
BugBounty & Hacking Resources
https://htmlparser.info/parser/
htmlparser.info
Idiosyncrasies of the HTML parser
This book will highlight the ins and outs of the HTML parser, and contains almost-impossible quizzes.
👍
3
🔥
2
BugBounty & Hacking Resources
https://x.com/renniepak/status/1854526392895000842?t=Ttm1lYBHpNaqd_7WUQUnrA&s=19
❤
2
BugBounty & Hacking Resources
https://abrahack.com/posts/learnpress-sqli/
Abrahack's Blog
Learnpress SQLi
Full Disclosure of CVE-2024-8522 & CVE-2024-8529
❤
2
BugBounty & Hacking Resources
https://web.archive.org/web/20181224143634/https://security.szurek.pl/exploit-bypass-php-escapeshellarg-escapeshellcmd.html
❤
3
🔥
2
BugBounty & Hacking Resources
http://meydi.hashnode.dev/master-of-xss-waf-bypass-part-1
my first blog post
❤
13
👍
2
🔥
1
👌
1
BugBounty & Hacking Resources
https://medium.com/@RaunakGupta1922/mastering-idor-the-ultimate-resource-guide-84e44052f70c
Medium
All You Need to Master IDOR: A Complete Resource Guide
Today, I’m excited to share all the resource I documented and personally used to master IDOR Vulnerability, soo lessssss gooo!!!!!
❤
3
🔥
1
TWeb.init({scrollToPost:'projectzeroTM/136'});