Ninad Mishra(@NinadMishra5) 's Twitter Profile Photo

Want to scan for command injection vulnerabilities on auto-pilot? 😎️👇️

Commix is an open-source command injection scanner written in python to help you scan for these bugs easily!

hubs.li/Q025-9sZ0

tips

Want to scan for command injection vulnerabilities on auto-pilot? 😎️👇️

Commix is an open-source command injection scanner written in python to help you scan for these bugs easily!

hubs.li/Q025-9sZ0

#bugbountytips #bugbounty
account_circle
Ninad Mishra(@NinadMishra5) 's Twitter Profile Photo

Subdominator

A powerful tool for passive subdomain enumeration during bug hunting and reconnaissance processes. It is designed to help researchers and cybersecurity professionals discover potential vulnerabilities.

github.com/RevoltSecuriti…

Subdominator

A powerful tool for passive subdomain enumeration during bug hunting and reconnaissance processes. It is designed to help researchers and cybersecurity professionals discover potential vulnerabilities.

github.com/RevoltSecuriti…

#bugbountytips #BugBounty
account_circle
Root Moksha(@RootMoksha) 's Twitter Profile Photo

If you find Web frameworks like Symfony, add '/app_dev.php/_profiler/open?file=app/config/parameters.yml' to the wordlist, and you may get juicy data. Enjoy!'

Credit: BBR - Bug Bounty Resources 🧵

If you find Web frameworks like Symfony, add '/app_dev.php/_profiler/open?file=app/config/parameters.yml' to the wordlist, and you may get juicy data. Enjoy!'  

Credit: @bbr_bug 

#bugbountytips #BugBounty
account_circle
Anindya Roy(@TheTeaToast) 's Twitter Profile Photo

Stored XSS via pdf upload 🫡❤️

Tip: Upload files and check the response. Sometimes We can see the path of the uploaded file.

Stored XSS via pdf upload 🫡❤️

Tip: Upload files and check the response. Sometimes We can see the path of the uploaded file.

#BugBounty #bugbountytips
account_circle
X(@TheMsterDoctor1) 's Twitter Profile Photo

200+ Hacking / Infosec pdfs

Like and Repost

Red Team Experts that explains the importance and details of Windows APIs❗️📷😈📷

Source: drive.google.com/drive/u/0/mobi…

Source: drive.google.com/file/d/1qUoyzw…

Credit:Joas Antonio

urity

200+ Hacking / Infosec pdfs   

Like and Repost

Red Team Experts that explains the importance and details of Windows APIs❗️📷😈📷

Source: drive.google.com/drive/u/0/mobi…

Source: drive.google.com/file/d/1qUoyzw…

Credit:@C0d3Cr4zy

#infosec #Hacking #infosecurity #Malware #bugbountytips #CTF…
account_circle
Root Moksha(@RootMoksha) 's Twitter Profile Photo

Just in case you still use gau...
it no longer gets any links back from Wayback Machine because of a change to their API.
Use: github.com/xnl-h4ck3r/way…

Credit: / XNL -н4cĸ3r (@[email protected])

tips

Just in case you still use gau... 
it no longer gets any links back from Wayback Machine because of a change to their API.
Use: github.com/xnl-h4ck3r/way…

Credit: @xnl_h4ck3r

#bugbountytips #bugbounty
account_circle
BBR - Bug Bounty Resources 🧵(@bbr_bug) 's Twitter Profile Photo

If you find Web frameworks like Symfony, add '/app_dev.php/_profiler/open?file=app/config/parameters.yml' to the wordlist, and you may get juicy data. Enjoy!'
s

If you find Web frameworks like Symfony, add '/app_dev.php/_profiler/open?file=app/config/parameters.yml' to the wordlist, and you may get juicy data. Enjoy!'  
#bugbountytips #bugbountytip #cybersecurity #ethicalhacking
account_circle
Root Moksha(@RootMoksha) 's Twitter Profile Photo

Stored XSS via cache poisoning 🧪

Tired of Akamai WAF, try this payload:

'><a nope='%26quot;x%26quot;'onmouseover='Reflect.get(frames,'ale'+'rt')(Reflect.get(document,'coo'+'kie'))'>

credit: Rachid.A

Stored XSS via cache poisoning 🧪

Tired of Akamai WAF, try this payload:

'><a nope='%26quot;x%26quot;'onmouseover='Reflect.get(frames,'ale'+'rt')(Reflect.get(document,'coo'+'kie'))'>

credit: @zhero___ 

#bugbountytips #bugbountytips
account_circle
shuvo kumar saha(@syper_shuvo) 's Twitter Profile Photo

📷 Learn SSRF 📷
[+] portswigger.net/web-security/s…
[X] book.hacktricks.xyz/.../ssrf-serve…...
[*] gowthams.gitbook.io/.../list-of...…
[-] youtube.com/watch?v=1pyoYa…
📷Tryhackme Lab:- 📷
1. tryhackme.com/r/room/ssrfqi
2. tryhackme.com/r/room/ssrfhr

📷 Learn SSRF  📷
[+] portswigger.net/web-security/s…
[X] book.hacktricks.xyz/.../ssrf-serve…...
[*] gowthams.gitbook.io/.../list-of...…
[-] youtube.com/watch?v=1pyoYa…
📷Tryhackme Lab:- 📷
1. tryhackme.com/r/room/ssrfqi
2. tryhackme.com/r/room/ssrfhr
#BugBounty  #bugbountytips  #ssrf
account_circle
Siddhartha S(@sidharthas8962) 's Twitter Profile Photo

Hey everyone, I have found multiple HTML injection in chat bot, should I report this?

1. payload <img src='index.jpg' alt='@coffinxp in a Jacket' width='1000' height='600'>

Hey everyone, I have found multiple HTML injection in chat bot, should I report this?
#BugBounty #bugbountytips 
1. payload  <img src='index.jpg' alt='@coffinxp in a Jacket' width='1000' height='600'>
account_circle