tgindex
Bug Bounty

Bugbounty Resources • Tips • Security Zines • Writeups • Vulnerability Update • Notes • Mindmaps • Cheatsheets • Checklists • Article / Blogs • PDFs • ebooks •

Последний пост
15 авг.
Последнее чтение
15 авг.
Постов за неделю
5
Всего постов
33
Тип
открытый
Язык
und
Категория
Новости и СМИ (по похожим)
В каталоге с
13 авг.
Подписчики
12 102
+45 за 3 дн.
Сутки
+8
+0,07%
Неделя
 
Месяц
 
Просмотров на пост
2 223
32 постов
Вовлечённость
18,4%
к подписчикам
Постов в день
0,7
всего 33
Упоминаний
0
каналов
Охват размещения
оценка
1/24сутки в ленте
794
1/48двое суток
909
1/72трое суток
981

Оценка по просмотрам недавних постов: пост набирает почти всё за первые сутки.

Посты

  • IP Spoofing to Account Takeover Leveraging IP spoofing to achieve one-click account takeover in OAuth • Blog: https://blog.mirzadzare.net/ip-spoofing-to-account-takeover

  • видео или голосовое, без подписи

  • Starting Claude For Bug Bounty - # Series I’m starting from absolute zero and showing beginners how to actually use Claude for: → Recon → Burp Suite → API testing → XSS → IDOR → JS analysis → Finding bugs → Writing solid reports I’ll show what Claude is doing, why it works, and how to verify the findings yourself. first part coming soon. 👀

  • 14 авг.1 0861547

    🚨 FREE DeepSeek V4 Flash for Bug Bounty! Try hunting for bugs that are getting found a lot right now: → IDOR / BOLA → Auth bypass → SSRF → Race conditions → Business logic bugs → XSS Give it a target, build hypotheses, and see if it can find something you might miss. It’s free, so worth testing. 👉 Sign up here: Freebuff If you find an interesting bug with it, share the result on X 🔥

  • 11 авг.1 4861360

    → 100 Web Vulnerabilities, categorized into various types : + Injection Vulnerabilities: 1. SQL Injection (SQLi) 2. Cross-Site Scripting (XSS) 3. Cross-Site Request Forgery (CRF) 4. Remote Code Execution (RCE) 5. Command Injection 6. XML Injection 7. LDAP Injection 8. XPath Injection 9. HTML Injection 10. Server-Side Includes (SSI) Injection 11. OS Command Injection 12. Blind SQL Injection 13. Server-Side Template Injection (SSTI) + Broken Authentication and Session Management: 14. Session Fixation 15. Brute Force Attack 16. Session Hijacking 17. Password Cracking 18. Weak Password Storage 19. Insecure Authentication 20. Cookie Theft 21. Credential Reuse + Sensitive Data Exposure: 22. Inadequate Encryption 23. Insecure Direct Object References (IDOR) 24. Data Leakage 25. Unencrypted Data Storage 26. Missing Security Headers 27. Insecure File Handling + Security Misconfiguration: 28. Default Passwords 29. Directory Listing 30. Unprotected API Endpoints 31. Open Ports and Services 32. Improper Access Controls 33. Information Disclosure 34. Unpatched Software 35. Misconfigured CORS 36. HTTP Security Headers Misconfiguration + XML-Related Vulnerabilities: 37. XML External Entity (XXE) Injection 38. XML Entity Expansion (XEE) 39. XML Bomb 4 Broken Access Control: 40. Inadequate Authorization 41. Privilege Escalation 42. Insecure Direct Object References 43. Forceful Browsing 44. Missing Function-Level Access Control + Insecure Deserialization: 45. Remote Code Execution via Deserialization 46. Data Tampering 47. Object Injection 4 API Security Issues: 48. Insecure API Endpoints 49. API Key Exposure 50. Lack of Rate Limiting 51. Inadequate Input Validation + Insecure Communication: 52. Man-in-the-Middle (MITM) Attack 53. Insufficient Transport Layer Security 54. Insecure SSL/TLS Configuration 55. Insecure Communication Protocols + Client-Side Vulnerabilities: 56. DOM-based XSS 57. Insecure Cross-Origin Communication 58. Browser Cache Poisoning 59. Clickjacking 60. HTML5 Security Issues + Denial of Service (DoS): 61. Distributed Denial of Service (DoS) 62. Application Layer DoS 63. Resource Exhaustion 64. Slowloris Attack 65. XML Denial of Service + Other Web Vulnerabilities: 66. Server-Side Request Forgery (SSRF) 67. HTTP Parameter Pollution (HPP) 68. Insecure Redirects and Forwards 69. File Inclusion Vulnerabilities 70. Security Header Bypass 71. Clickjacking 72. Inadequate Session Timeout 73. Insufficient Logging and Monitoring 74. Business Logic Vulnerabilities 75. API Abuse + Mobile Web Vulnerabilities: 76. Insecure Data Storage on Mobile Devices 77. Insecure Data Transmission on Mobile Devices 78. Insecure Mobile API Endpoints 79. Mobile App Reverse Engineering + loT Web Vulnerabilities: 80. Insecure loT Device Management 81. Weak Authentication on loT Devices 82. loT Device Vulnerabilities + Web of Things (WoT) Vulnerabilities: 83. Unauthorized Access to Smart Homes 84. loT Data Privacy Issues 4 Authentication Bypass: 85. Insecure "Remember Me" Functionality 86. CAPTCHA Bypass + Server-Side Request Forgery (SSRF): 87. Blind SSR 88. Time-Based Blind SSRF + Content Spoofing: 89. MIME Sniffing 90. X-Content-Type-Options Bypass 91. Content Security Policy (CSP) Bypass + Business Logic Flaws: 92. Inconsistent Validation 93. Race Conditions 94. Order Processing Vulnerabilities 95. Price Manipulation 96. Account Enumeration 97. User-Based Flaws + Zero-Day Vulnerabilities: 98. Unknown Vulnerabilities 99. Unpatched Vulnerabilities 100. Day-Zero Exploits

  • 9 авг.1 691521

    Read “RCE in 2026 Doesn’t Look Like RCE in 2020. Here’s What Actually Matters Now.“ https://medium.com/@Aacle/rce-in-2026-doesnt-look-like-rce-in-2020-here-s-what-actually-matters-now-fedb5bee2c86

  • 3 авг.2 474729

    Shubs spent 40+ hours understanding one company's attack surface before testing anything. NahamSec found a critical SSRF through an expense report PDF generator nobody else looked at. The difference is not skill. It is where you look. 7 surfaces: https://medium.com/@Aacle/most-hunters-test-the-same-surface-as-everyone-else-c6512bfc66de?sk=aea57ad2b25592b67d7e9c2785e003d5

  • 3 авг.2 2961028

    Subdomain takeover: dig +short CNAME http://sub.target.com Points to: http://herokuapp.com → claim the app http://cloudfront.net → claim the distribution http://github.io → create the repo http://s3.amazonaws.com → claim the bucket Service gone, DNS still pointing = takeover.

  • 3 авг.2 139815

    OAuth HPP test: send two redirect_uri parameters. ?redirect_uri=https://app.com&redirect_uri=https://evil.com If server validates the first and uses the last, the token goes to http://evil.com. Validate first, use last. Source: Twitter/Digits #114169.

  • 3 авг.2 143611

    SAML bypass test: craft a SAML response with an arbitrary username and admin role. Leave out the Signature element entirely. Some plugins skip signature verification when the element is empty. If the server provisions the user, you have admin. Source: Uber #136169 ($10,000).

  • 3 авг.2 05213

    🔗 https://x.com/aacle_/status/2083961160978837639

  • 26 июл.2 920622

    GCP metadata SSRF tip: the /v1beta1 endpoint does not require the Metadata-Flavor: Google header, while /v1 does. Test: 👆 Source: Shopify #341876 ($25,000).

  • 26 июл.2 894742

    I analysed 313 disclosed SSRF reports from HackerOne. 5 patterns repeat in almost every report. Two different chains lead to full RCE. I turned it into a testing framework you can run on every endpoint. Full breakdown on Medium: https://medium.com/@Aacle/the-bug-bounty-playbook-ssrf-18e39248fedb?sk=6b1a96b17f553f1ab46e97ee89c7d05e

  • 22 июл.3 0821021

    Android bug bounty tips APK unpacking Never assume API keys or endpoints are hidden just because they are inside a mobile application. Use apktool to unpack the APK and then use grep (Linux) or ag (Silver Searcher) to find sensitive strings: #bugbountytips

  • 22 июл.2 7991122

    Found a naked IP redirecting to a main hostname? Don't skip it. Fuzz the Host header directly against that IP: 👇 Easiest way to bypass front-facing WAFs & expose hidden staging endpoints. #bugbounty

  • 22 июл.2 832512

    A bug Cursor doesn't consider a bug. Drop a git.exe in any repo, open it in Cursor on Windows. The file runs. No click, no prompt. RCE as your user. 7 months. 70+ versions. Still there. You can argue the classification. You can't argue the file ran. medium.com/@Aacle/the-cursor-zero-day-that-sat-through-70-versions-a144c79ae20f?sk=372fde5c15c261ad4685534f0659ba4d

  • 19 июл.2 8251621

    Recon pro-tip: Stop scanning just the official corporate GitHub organization. Developers constantly push corporate API keys and secrets to their personal repos by mistake. Track down the public profiles of the devs working there and run gitleaks over them. 🛠️

  • 18 июл.2 9601222

    I used to think prompt injection was an AI safety problem. Then I wrote it up as SSRF and the whole thing clicked. → The boundary is the same. → The bug is the same. → The bounty table row already exists. Part 3 of the MCP bug bounty guide: https://medium.com/@Aacle/prompt-injection-is-just-ssrf-for-text-7c864c73571e?sk=72f8e982df275aaa51704ec32e733d99

  • 18 июл.2 700621

    1/ Everyone knows HackTricks and PortSwigger. These are the resources that actually find bugs. Less hyped, higher yield. A short list I keep going back to. 🧵 https://x.com/aacle_/status/2078389119261258011?s=20

  • 18 июл.2 484614

    "I'm going to bed. Keep hunting. Don't stop until 8am. If you're about to summarise, pause, check the time, and if it's not 8am, don't stop." Claude did bug bounty hunt through the night. Woke up with Claude findings & he deleted test acc for IDOR 🤩 https://medium.com/@Aacle/the-night-claude-found-a-critical-idor-and-deleted-the-test-account-6a685cc205d3?sk=41135dbeba4065a0fb1a2ccb8de7baab

Bug Bounty — tgindex