🗒Open Redirect via Non\-Latin Subdomain in vcc\-\*\.8x8\.com/AGUI/test\.php
https://hackerone.com/reports/2331473
@PenTest_Tm
https://hackerone.com/reports/2331473
@PenTest_Tm
🗒 One-click Account Take Over
https://dynnyd20.medium.com/one-click-account-take-over-e500929656ea
@PenTest_Tm
https://dynnyd20.medium.com/one-click-account-take-over-e500929656ea
@PenTest_Tm
🗒 How I Found Multiple XSS Vulnerabilities Using Unknown Techniques
https://infosecwriteups.com/how-i-found-multiple-xss-vulnerabilities-using-unknown-techniques-74f8e705ea0d
@PenTest_Tm
https://infosecwriteups.com/how-i-found-multiple-xss-vulnerabilities-using-unknown-techniques-74f8e705ea0d
@PenTest_Tm
Log files Dorks
Universal for Google, Bing etc:
https://github.com/Proviesec/google-dorks/blob/main/google-dorks-best-log.txt
@PenTest_Tm
Universal for Google, Bing etc:
https://github.com/Proviesec/google-dorks/blob/main/google-dorks-best-log.txt
@PenTest_Tm
🗒 Bug Bounty Cheat Sheets
SSRF
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Server%20Side%20Request%20Forgery
https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/ssrf.md
CRLF
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/CRLF%20Injection
https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/crlf.md
@PenTest_Tm
SSRF
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Server%20Side%20Request%20Forgery
https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/ssrf.md
CRLF
https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/CRLF%20Injection
https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/crlf.md
@PenTest_Tm
GIT files Dorks
Universal for Google, Bing etc
https://github.com/Proviesec/google-dorks/blob/main/google-dorks-for-git-files.txt
Bug Bounty Dorks
Universal for Google, Bing etc
https://github.com/hackingbharat/bug-bounty-dorks-archive/blob/main/bbdorks
@PenTest_Tm
Universal for Google, Bing etc
https://github.com/Proviesec/google-dorks/blob/main/google-dorks-for-git-files.txt
Bug Bounty Dorks
Universal for Google, Bing etc
https://github.com/hackingbharat/bug-bounty-dorks-archive/blob/main/bbdorks
@PenTest_Tm
🗒 Wordpress Plugin Background Image Cropper v1.2 - Remote Code Execution
آسیب پذیری RCE از افزونه وردپرسیه Background Image CROPPER ورژن 1.2
https://www.exploit-db.com/exploits/51998
@PenTest_Tm
آسیب پذیری RCE از افزونه وردپرسیه Background Image CROPPER ورژن 1.2
https://www.exploit-db.com/exploits/51998
@PenTest_Tm
🗒 Extract IPS From list of domains and then you can conduct your FUZZ/Manually check them for SDE /BAC , Ports , ..etc
@PenTest_Tm
grep -o '[0-9]\{1,3\}\.[0-9]\{1,3\}\.[0-9]\{1,3\}\.[0-9]\{1,3\}'
@PenTest_Tm