def1ant(@0xdef1ant) 's Twitter Profile Photo

Discovered a SQL injection in a big program:
1. Find subdomains with amass/subfinder
2. Fuzz to find new/unknown endpoints
3. Pick one endpoint to inspect further and fuzz POST requests
4. Boom! time-based blind SQLi

njection

Discovered a SQL injection in a big program:
1. Find subdomains with amass/subfinder
2. Fuzz to find new/unknown endpoints
3. Pick one endpoint to inspect further and fuzz POST requests
4. Boom! time-based blind SQLi

#bugbountytips #wearehackerone #infosec #sqlinjection #sqli
account_circle