#bug-bounty

1 messages · Page 7 of 1

young storm
#

is it ok the skip networking in pre security since its premium? i am a beginner

split temple
#

Hey everyone

sharp blaze
young socket
#

As per Google A bug bounty program is a crowdsourced security initiative where organizations reward ethical hackers for discovering and responsibly reporting software vulnerabilities before they are exploited

#

What's that 🤔

#

Got it

uneven galeBOT
#

Gave +1 Rep to @sharp blaze (current: #3736 - 1)

fervent harbor
#

Bruh

rigid dirge
#

Thanks

uneven galeBOT
#

Gave +1 Rep to @fervent harbor (current: #3736 - 1)

runic mortar
#

hell yea i mean no

green granite
#

does someone where i can find promotion codes for tryhackme payment?

white sparrow
light ivy
#

@obtuse fern

vivid topaz
#

@obtuse fern ^ multiple rooms

rare barnBOT
#

Done!

obtuse fern
uneven galeBOT
#

Gave +1 Rep to @vivid topaz (current: #377 - 24)

spring crown
#

Hi

empty ice
#

Hello

fresh oar
#

Whats going on brothers?

#

I am a beginner and learning Pre Security form THM

#

Who want to become my career companion and friend to share things with DM

#

I am waiting for someone who wants?

#

Happy Hacking

fiery star
fiery star
fiery star
soft raptor
#

I need an advice.
As someone who is just getting into bug bounty, what will be your advice. Should I or should I not get into it. It seems a little useless ? Because mythos etc , however speculative, is a future possibility. If ai can automate the whole process of bug hunting and even recommending fixes, isn't it better to get into ai security or maybe cloud security? Or something that has a scope of being relevant for a longer period of time ?

My perspective could be due to lack of knowledge, kindly enlighten 🙂

zenith bluff
neon pond
uneven galeBOT
#

Gave +1 Rep to @zenith bluff (current: #900 - 8)

vernal violet
celest aurora
#

Hello, just leaving a footprint. Security Researcher and Engineer trying to get back into Bug bounties. Have 6 years in the field and still learning daily. DM me if anyone wants to run some rooms, study, or bug programs

silent hinge
#

Hey can I ask someone a question ASAP in DMs about a bug bounty I might have just got

valid ridge
#

Hi, how do you make AI help you? I have to reasure my ai im working white hat 10 times before its giving me answer to my question (also answer is shit) im sending stuff and its telling me it wont help and that i should delete this conversation all the time

celest aurora
celest aurora
# fossil edge such as?

such as what? If you're referring to which models are best, I suggest researching on that to get your own understanding. It's subjective on which models are "best" for certain task

fossil edge
#

i see, thanks

valid ridge
#

it got to the point I had to send fake email and screenshot it to ai lol

celest aurora
#

depending on the model a good rule of thumb is to create a "workspace" from what some platforms refer to as and give it direct and thorough instructions to ensure that doesn't happen. You also have to learn how to word certain things to get those responses.

mint lava
#

Hi everyone 👋
I just joined this channel. I'm currently learning penetration testing and looking for someone experienced who could guide me or mentor me.

If anyone is willing to help or point me in the right direction, I’d really appreciate it. Thanks!

stone copper
#

looking for people to add to a growing team bug bounty/red team and security focused group people who are actually trying to learn not just lurk
you do not need to be an expert but you need to be active curious and willing to put in work focused on real world skills like recon vulnerability research web testing api analysis and general offensive security mindset
this is for people who want to level up together share findings and build real experience not just theory if you are consistent ask questions and actually show up you will fit in
drop in if you want to grow in tech and be around others doing the same🫡. Private Dm Me!

solid swan
#

Hey there guys I’m new here and recently started learning about the fundamentals of cybersecurity. I would like to try bug bounty in the future, but for now I would like to make sure that I have the “ground” to step on. Is anyone interested in learn with me or mentor if it’s not too much of a problem? Thank you in advance. Y’all can dm me, I’d love to meet.

buoyant thicket
buoyant thicket
rigid dirge
#

How to get started with bug bounty

fresh oar
#

Then you will find your own way. Keep Going.

#

That's not a straight path.

rigid dirge
#

Thx

young socket
fresh oar
#

But I am saying right that you should just started.

#

You can start with Pre Security

#

Cyber Security is not stuck

#

It changes every second so adapting it

#

Know jus start with pre security course at THM

#

I am also at it

rigid dirge
#

Thx for the advice

split axle
limpid marsh
#

hi

#

i have 2yr + experience in cyber sec in domains like reverse engineering , some android pentesting , web app pentesting , and Ai as well.

#

i would like to team up with well experienced hackers

#

for knowledge and ctf solving

lapis forge
#

I have 1yr core experience

limpid marsh
#

anyone into CVE hunting

rustic thunder
#

I would like to team up as well

#

Is there a separate group created so we could hunt and learn stuff ??

thin vigil
#

Hi everyone, I'm looking for someone who'll scam with me and earn!

limpid marsh
torn stump
#

Hello I'm better decent with hacking more of offensive anyone wanna team up

robust hollow
#

I want learn does anybody have time to mentor or anything, I have a roadmap and I want get started with windows basics and networking

tepid marten
#

Hi

topaz glen
#

I'll send you pm

topaz glen
torn stump
#

Useful for what

robust hollow
#

@night gust I’m just looking to make friends with similar interests. I’d like to do bug bounties, challenges and projects. Until now I’ve learned almost nothing in college and I’m thinking of dropping out. If anybody wants to learn along with you can dm me.

slim anvil
gentle bear
slim anvil
gentle bear
#

I'm in class rn wait let me text u when this class ends

slim anvil
#

Ok

torn stump
#

Yep

torn stump
slim anvil
shut trail
#

🤨

robust hollow
#

@gentle bear I just sent a friend request. Teach me whatever you can bro and try to tag along.

#

Yo

gentle bear
robust hollow
#

Yea

#

Bro I didn’t study hard enough or I just took useless classes

gentle bear
#

I do use Linux and rn I'm a masters student in computer applications.

robust hollow
#

@gentle bear wow

gentle bear
robust hollow
#

I kinda want finish with iIT

#

IT

#

Yea nice

slim anvil
gentle bear
slim anvil
#

if u are into off sec

#

i know about off sec

gentle bear
#

Create a server let's learn there

robust hollow
#

Yes

slim anvil
gentle bear
robust hollow
#

I am a begunner

robust hollow
#

I can’t spell I have auto correct off

slim anvil
gentle bear
slim anvil
robust hollow
#

Yo

#

I’m here

slim anvil
gentle bear
tepid marten
torn stump
#

@slim anvil @gentle bear what's ur level?

gentle bear
split coyote
#

heyy, new member here👋

#

im a green hat

gentle bear
#

I might've joined this server 1 Yr ago but I never used thm, all I did was login and yah that's it. I've been learning from pwn.ccollege (linux)

torn stump
#

U use Linux or windows

gentle bear
#

I'm about to distro hop again for 1 last time let's c.

torn stump
#

http://<metasploitable-ip>/dvwa

#

And do the cybersecurity paths on thm

#

I still use old school Debian

severe badge
#

hi

severe badge
torn stump
#

What distro?

flint sleet
flint sleet
severe badge
#

Well I downloaded it with the help of some tutorial, but i think the video was made like five years back so the version was not the version i downloaded, but i think i will delete it if possible then restart. Thanks for asking.

versed plover
torn stump
#

@severe badge DM me

torn stump
#

How well are u with cybersecurity

slim anvil
#

intermediate level

torn stump
slim anvil
#

check your dm dude we already talk yesterday

#

@torn stump

gentle bear
#

Nvm it was the other guy

topaz dagger
#

@severe badge Hi Crypo s33d I can see you are having some trouble?

#

can we team up?

#

DM me

soft raptor
#

Hi guys !

#

Needed a little help

#

I've recently finished the web fundamentals path

#

And I wanted to practice some CTF style rooms

#

Is there like a list of machines I can begin with on thm

void crest
woeful tiger
#

bro

#

are u being serious

#

wdym by "provide a hack"

#

BRO 😭😭

#

im not assuming that

#

idk what ur on

rare barnBOT
#

:hammer: zerox25122011#0 has been banned.

woeful tiger
#

thank you kgb

void crest
#

hello guys, how do i start with bug bounty? i have been doing CTFs on tryhackme since the AOC2025, and i want to level up my skills and profile with some actual bugbounty experience. help a newbie out 😉

young socket
void crest
buoyant ice
#

can i actually send a message now my stupid ban is lifted well

unkempt kayak
woeful tiger
lapis forge
#

Hiee everyone

gray onyx
#

Hi

warped crater
#

I’m looking for a mentor. Got decent knowledge but need some supervision for guidance on bug bounties. If anyone willing to mentor me, would love that.

timid kiln
#

So a few weeks ago, I say TryHackMe's Bug Bounty PDF they had on LinkedIn. Really inspired me to get into Bug Bounty. Actually got a TryHackMe Account a few weeks later when they ran a promo. Going through OWASP top 10 and getting a refresh on TryHackMe before hitting the PortSwiger Labs.

Anyway, part of the doc mentioned getting into a program. What would be a good program for someone new to bug bounties?

fading grotto
thorn parcel
#

First

frail compass
#

no u

thorn parcel
#

Yes me

frail compass
#

oi

thorn parcel
#

I got sum bugs

frail compass
#

mind your language

thorn parcel
#

🐛

young cloud
#

berg bernty

tough garnet
vocal folio
#

Bug bounty is great fun when you discover something accidentally and work with Muir to form a PoC XSS attack for it

lavish hollow
#

Do you know from experience?

frail compass
#

or you send xss through a PR

thorn parcel
merry plume
#

Hiii

thorn parcel
#

Rogue bug

frail compass
vocal folio
#

Yes, THM has paid out for an XSS to muir and I @lavish hollow

lavish hollow
#

THM is teaching me how to exploit THM 🤔

frail compass
#

to some extent kekw

vocal folio
#

If I wasn't so active helping, I wouldn't have found the flaw

prisma axle
#

can we put a bounty on spooks?

latent tree
#

can we put a bounty on spooks?
@prisma axle how much? I’ll go get the rifle

tough garnet
#

I'll go get the sword!

#

lightsaber

latent tree
frail compass
#

depends what kind of bugs we find

#

bed bugs don't classify for bounties

young cloud
#

I see how well this channel is going to do.

prisma axle
#

a great video by Jason Haddix that can give a lot of insight on the methodology behind finding a bug especially the reconnaissance methodology

frail compass
#

did red team village upload everything on youtube now?

prisma axle
#

yes every talk as well as workshop is on YouTube

frail compass
#

awesome that is good news

#

i checked on saturday and it was empty

ruby skiff
#

Bug hunters

merry plume
#

here I’ll start it out on topic https://m.youtube.com/watch?v=gIz_yn0Uvb8
@prisma axle yes everyone watch this video, especially when Jason starts talking about port scanning tools

The Bug Hunter’s Methodology Jason Haddix @jhaddix
The Bug Hunter’s Methodology is an ongoing yearly installment on the newest tools and techniques for bug hunters and red teamers. This version explores both common and lesser-known techniques to find assets for a target. Th...

▶ Play video
#

No reason at all lads

ebon tapir
young cloud
#

Sorry, it's a dupe.

vernal crater
#

Hello I found a vulnerability in try hack me. It is critical problem.

frail compass
vernal crater
#

Ok

tacit kernel
#

New channel fingerguns

cloud violet
lavish hollow
ancient bolt
#

ha sorry

heady raptor
#

is SuitGuy the Mod of this channel? kekw

vocal folio
#

No, he hunts down anyone who posts in here

#

That's what bug hunter means

frail compass
cobalt quiver
#

The message was the problem

visual sphinx
#

I'd guess a non-native speaker found an exploit on the site

magic arrow
#

How would someone get started in this field?

ruby skiff
#

Google

#

Get some skills

quaint bronze
#

Excellent list of bug bounty write-ups

fallen palm
#

Also it's a good idea to just track current bug bounty programs/trackers and just look at the bugs being found today

fallen palm
#

https://portswigger.net/web-security https://www.hacker101.com/ https://tryhackme.com/ is what helps me. But im new so don't go on my advice. I found some bugs but got discouraged quite quickly by the "another researcher has found this bug 7 years ago but we didn't patch it" thing.

normal crescent
#

@marsh falcon
We need new labs, thank you

prisma axle
#

....

#

there’s so much wrong with that message

vocal folio
#

We need new labs, thank you
@normal crescent You could make some

young cloud
#

Two new labs released today.

#

😮

ocean valley
#

hi did you ever had this bug ? In room "Learn Linux" you can't respond to an answer because fields are not shown ?

vocal folio
ocean valley
#

woops sorry

fallen palm
#

hi did you ever had this bug ? In room "Learn Linux" you can't respond to an answer because fields are not shown ?
@ocean valley yes, had the same

lavish hollow
#

Go to #site-support and type Hi my tryhackme name is: [Insert THM NAME] and I'm having the task bug on the learn linux room. Ashu* will help you when he is back :)

fallen palm
#

Ow cool, thanks!

restive egret
#

hi did you ever had this bug ? In room "Learn Linux" you can't respond to an answer because fields are not shown ?
@ocean valley me too

lavish hollow
#

@restive egret username?

#

on THM site*

restive egret
#

proximity220

#

Not sure if it's a big or it was intended to be like thag

#

bug*

lavish hollow
#

It's being fixed

#

Please be patient

restive egret
#

Yeah no probs

eternal harbor
#

But it's not possible to complete the room
@restive egret I am getting the same error in the learn linux room. Did you find the solution.

restive egret
#

@eternal harbor it's a bug, it'll get fixed soon

merry plume
#

@eternal harbor Ashu can fix this for you, I heard

#

@lavish hollow take over I'm not allowed to give help 😦

lavish hollow
#

Pffft you can help

#

But sure

#

I’m your assistant

#

@eternal harbor @restive egret I’ll need your THM usernames (if this is occurring for you)

restive egret
#

@eternal harbor @restive egret I’ll need your THM usernames (if this is occurring for you)
@lavish hollow proximity220

eternal harbor
#

@eternal harbor @restive egret I’ll need your THM usernames (if this is occurring for you)
@lavish hollow ZeroVuln

lavish hollow
#

Alright, you will be sorted within the next hour

eternal harbor
#

Thank you

eternal harbor
#

Alright, you will be sorted within the next hour
@lavish hollow error still not resolved

lavish hollow
#

Mhm staff are busy rn sorry. I'll give them a ping but there's nothing I can do on my end

eternal harbor
#

ok i am wait

lavish hollow
quick bramble
#

Oh! I just posted there. Thank you so much.

final torrent
#

hey guys i'm in this bug bounty program and i can't sign up because it is blocked in my country if anyone can help me with this and create an account for my testing will be appreciated

#

DM me if you can

young cloud
#

A VPN may be able to sort that out, however I would check with your laws to see if circumventing web restrictions is illegal or not.

final torrent
#

A VPN may be able to sort that out, however I would check with your laws to see if circumventing web restrictions is illegal or not.
@young cloud i tried VPN but it is amazon cloudflare blocked

#

i don't think it is illegal

young cloud
#

If your country is blocking it it’s for a reason.

#

¯_(ツ)_/¯

final torrent
#

it is for stores like wallmart and bestbuy i think thats why i can't use it

ruby skiff
#

If your country is blocking stuff its because the law states that you can't. As a result we can't really give advice

worn bone
#

Also try using Tor

vocal folio
#

@worn bone PG13 please.

vocal folio
#

@gloomy stream That doesn't seem like responsible disclosure if it is a bug

gloomy stream
#

where can user report that? @vocal folio

vocal folio
#

Email the admins

#

Delete the post here

gloomy stream
#

Deleted!!! @vocal folio where can we find email details? thm

vocal folio
gloomy stream
#

👍 👍 👍 👍

opal spoke
#

can anyone provide me burpsuite pro keygen

merry plume
#

That's illegal

#

So, no.

north jackal
opal spoke
north jackal
#

My pleasure 😌

wooden quail
#

Do I have to officially register somewherefor testing the application in a bug bounty program?

vocal folio
#

What application?

wooden quail
#

I mean general domain

vocal folio
#

Don't attack stuff without permission

wooden quail
#

Yeah so the domain has a bug bounty program do I need any further permission?

ruby skiff
#

Well read what their program says and direct questions to them.

#

Generally most services will have a non production service which you can play with (I.e Facebook)

merry plume
#

Does THM have a specific ToS for bug bounty?

vocal folio
#

Don't active scan, don't do anything that will affect other users. Probably more.

ebon tapir
#

brute force? 👀

fallen palm
#

How to start bug bounty pls help me

#

Step by step

vocal folio
#
  1. Get good at web hacking
#
  1. Sign up for a private program
#
  1. give up when you realise it's not a get rich quick
fallen palm
#

Thanks bro

vocal folio
#

Please don't call me bro

#

Please don't call me bro

#

Just a "thanks" would have been fine

fallen palm
#

Oky

#

Have a good night

ruby skiff
fallen palm
latent tree
sharp yarrow
#

hey guys, anyone good at enumeration?, I've got a couple of questions pls

north jackal
#

I guess you can ask them directly :D

indigo hollow
#

hey guys, anyone good at enumeration?, I've got a couple of questions pls
@sharp yarrow you can ask here, known one will answer you 🙂

eternal glade
#

how can devloped tryhack room

sonic rover
alpine panther
#

Hey there so i was looking around a website and saw that they were using Wordpress. So me (very board) i ran WPScan and found 5 usernames. Should i email them for a possible bug bounty (they don't officialy have bug bounty) or should i just forget it?

Im pretty new to bug bounty and im not too sure on the Swedish bug bounty laws (i'll read up on them). So what should i do?

prisma axle
#

That’s pretty low level I wouldn’t submit you would probably just get a grumpy security team

#

if you can take those usernames and do more with them to get a higher vulnerability then you could consider submitting

#

however I would not be scanning a website which you don’t have explicit permission to

#

and if they have said verbally they have a bug bounty it doesn’t matter you need written permission before doing anything

alpine panther
#

yea

young cloud
#

Can find user names by simply clicking around long enough.

lavish hollow
#

May I ask what company/whatever this is related to?

#

Because you need written permission to perform bug bounties I believe. Not all*

prisma axle
#

If you can’t specify this may not be the best place to ask

lavish hollow
#

If you're messing around on someone else's website I do not want to be apart of it.

#

Nice.

brisk rover
#

It's 100% legal

ebon tapir
#

So you just found something in a (bounty) program. got no clue what to do with what you found. Asking others without proper details(and now deleting messages 🤦‍♂️ )

brisk rover
#

They have their own responsible disclosure

lavish hollow
#

And you can't disclose it to us?

brisk rover
#

No

lavish hollow
#

It seems really really sketchy.

brisk rover
#

I am just asking if someone can explain

#

Nothing more, I don't want somebody to do work that can be done by me

#

But it's okay

#

I'll ask somewhere else

#

If you think that I am a black hat then you got it wrong. It's not worth it and will never be!

frail compass
#

It seems really really sketchy.
@lavish hollow Not really, he wants to claim the bounty (in case it's not a dupe). So it does make sense. If you can provide some more context @brisk rover someone might be able to better help you 🙂

brisk rover
#

Thank you @frail compass

frail compass
#

i am not familiar with those topics so I am not entirely sure

thorn parcel
#

also if it's a private program you can't really disclose much publicly

brisk rover
#

You are the one that can help!

#

No problem @frail compass

lavish hollow
brisk rover
#

At least you're are trying to help

frail compass
#

^^, we all try to help, i think it was some misunderstanding

brisk rover
#

I am just reposting my question:
Anyone has experience with Algolia Api Keys? Found an Algolia Search Api key and ID as well as a suggestion key in the source code. I've readed the docs, saw that the keys are not allowed to be publicly accessable but I couldn't get any further.

frail compass
#

probably worth just being a tad less defensive would've been better, but we live and learn :), just clarify stuff in case someone has the wrong idea 😛

brisk rover
#

Yea indeed thank you @frail compass

frail compass
#

no problemo, glad we cleared the mist

#

have a look to see what that key might be used for

brisk rover
#

The others were thinking that I am doing blackhat stuff on a disclosed api key come on guys..

#

I've readed the documentation already

frail compass
#

can you query the api using that key?

brisk rover
#

The whole api key section

#

Hold on

#

Yep

frail compass
#

see if it has full blown permissions

#

like remove and stuff like that

brisk rover
#

It makes a request to a specific script/endpoint with the id and the key

#

It's an endpoint

frail compass
#

and see if you can query an endpoint that you don't normally have access to

#

does the webapp have a user/admin interface and do you have access to any of them?

brisk rover
#

Only user

frail compass
#

hmm, try accessing something until you get 403

#

see if the key can be used to access that part

brisk rover
#

I guess it may have admin access, backend is in java

frail compass
#

let me ping someone and see if he has any knowledge of this

#

@bitter remnant any experience with this

brisk rover
#

Okay I'll do that! Thank you man! I apprectiate it!

frail compass
#

no problem

brisk rover
#

I will provide a screenshot

young cloud
#

Did you replace the values there?

brisk rover
#

I have covered the keys and the id

#

yes

young cloud
#

oh ok

brisk rover
#

If no limit is set ofcoars

vocal folio
brisk rover
#

Thank you Ninja

#

The same vulnerability as with Google Maps API Keys when they are not configured correctly

bitter remnant
#

I'm not an API keys guy, but I can say the following. Algolia keys almost tend to have no impact at all, and usually isn't taken into account by most triagers. It IS taken into account if you're able to provide a working PoC. I recommend looking at this: https://github.com/streaak/keyhacks#Algolia-API-key Try searching for a param similar to those given in the payload example. This payload, as mentioned by the author, is simply used to show the possibility of a XSS attack. If I'm being honest, it's something you shouldn't target. There aren't many resources for Algolia key exploitation, as there is for any other non high priority bug, unless you are able to manipulate it, show user impact, and a working PoC. The payload given might help, but probably won't do much. Remember, I'm not too experienced, this is just based off of what I've seen. If you're a beginner trying to mess around with these keys by all means go for it, but stuff like this which is usually counted as a P4 at best definitely requires some skill to pull off and escalate. idk, once again, I don't work with these keys. I've seen this case a number of times in multiple repos for public programs, so I'm guessing it might help. Now, after seeing the Cash Overflow vuln yes it definitely might be a valid vuln, due to misconfiguration.

#

Once again Cash Overflow is DoS, so just remember to look over the program scope

brisk rover
#

Thank you so much @bitter remnant ! First time I found this in the source code

bitter remnant
#

lmao sure. I usually start off with GitHub repos so that's great! Keep me updated!

brisk rover
#

And I tought maybe it does have some impact like Cash Overflow so I started to search for some resources and I ended up at the documentation

#

No blogposts from security researchers at all, but thank you!

bitter remnant
#

Haha yeah, I didn't see much too when I came across stuff like this first. Solely based on my short time of experience with this stuff lol.

brisk rover
#

At least I learned something new! Thank you

shut ice
#

how did you guys get started doing bug bountys?

lavish hollow
#
  1. Get good at web hacking
  2. Sign up for a private program
  3. give up when you realise it's not a get rich quick
glad tide
#

hello, i am new here i want to learn hacking?

opal prairie
#

me too

glad tide
#

can someone answer to me and jin #4465.

fallen palm
#

@glad tide wrong room

still jasper
#

@glad tide usually that's a #general question but a good place to start is from TryHackMe which teach you the fundamentals and can progress to become more advanced

glad tide
#

@still jasper thanks

sharp yarrow
#

hey guys, I'm trying to exploit an XSS vuln
the issue in short : when injecting an arbitrary parameter to the url and giving it a value,
the url is echoed unmodified in the response body within a tag's attribute
for instance :
https://example.com/?arbitrary=whatever"><img src=x onerror=alert(1)>
this payload is getting placed inside meta tag's attribute
but the payload is urlencoded in a way that prevents me from escaping the HTML context
anyone could help pls?

compact axle
#

Are you allowed to test on whatever website that is

sharp yarrow
#

Are you allowed to test on whatever website that is
@compact axle yeah

lavish hollow
#

Have you googled encoded payloads that can help you

sharp yarrow
#

yeah I did, but the problem is that the server is not decoding the payload
ex: <img%20src=x%20onerror=alert(1)>
gets echoed without decoding the %20 to whitespace

frail compass
#

Try spaceless payloads

sharp yarrow
#

tried that but no luck

#

@frail compass

#

I'm guessing it's unexploitable, or I'm just missing something
but even <svg/onload=alert(1)> didnt work

frail compass
#

if you can't do xss try doing something else like changing colours of the pages

#

or try DOM based

sharp yarrow
#

can u give some examples

frail compass
#

payload all the things is your friend

sharp yarrow
#

ok I'll try check that out

#

thanks for help 🙂

frail compass
#

no problem

sick roost
#

i looked for bugs for a bit but didn't find any

obtuse rock
#

Guys i want to get started in bug bounty..

#

Can anyone help

frail compass
#

there are plenty of books to get you started and places to develop your skills

#

it's not a thing you just throw a nmap scan/nessus and you get it done.

vocal folio
frail compass
#

^ that too

#

and the webacademy or however is called from burp

obtuse rock
#

I am solving CTF on tryhackme
Earned 3 badges too

sick roost
#

i feel like with bug bounty i'll never get past recon

#

just spider a site and learn its endpoints and understand whether they touch dbs, include stuff, etc.

#

test for sql, xss, lfi, find nothing repeat

prisma axle
#

Bug bounty is so much more

#

You need to identifying your full scope and look at all their assets rather than just the main one because others have probably already scavenged the heck out of it

#

I would recommend checking out hat training or one of his other shorter talks and understand methodology

sick roost
#

thanks a lot 🙂

eternal garnet
#

bug bounty is so confusing

#

ive been doing networking for years and bug bounty seems to be focused on web pages more

prisma axle
#

That’s exactly what it is

#

It’s just crowd sourced web app pentesting

eternal garnet
#

ohk so i need to focus on web app pentesting , thanks

#

i got told that if a hacker masters python, he can basically hack alot without pen testing experoence

vocal folio
#

I mean, python is just a programming/scripting language

#

Knowing python doesn't make you a master hacker

#

People think it does, they're wrong

tough garnet
#

🐍

native snow
#

But python do help when you stuck at something and it shows an error like for ex: error on line 20 and it takes while to solve it if you do not know it! Knowing it is good but mastering it would be much like a choice!

prisma axle
#

I disagree bug bounty can very easily be done without python

#

if you have all the python knowledge in the world would you still be able to automate sqli?

#

you have to understand sqli as well

native snow
#

what if you are using automated tools and you get error on line something because of package or something, google helps but it is all about time you spend to solve that thing!

vocal folio
#

Yeah, but python alone won't make you a master hacker

prisma axle
#

what if you are using automated tools and you get error on line something because of package or something, google helps but it is all about time you spend to solve that thing!
@native snow that’s using a tool not mastering python

#

any script kiddie with a keyboard can use a tool

#

you don’t have to understand the python behind it

native snow
#

using a tool and getting an error of python and solving that! that's what I'm talking about not mastering but knowing it, is good!

prisma axle
#

That wasn’t what the conversation was about though that’s where the confusion came from

native snow
#

Sed, Sorry though!

heavy idol
#

Python's use in programming comes from it being a fairly easy language to learn because it's consistent and easy to read. Being able to automate things about your job saves time and that's the goal of learning Python. You want to learn how to automate because it might save you time and ensure consistent results. Knowing Python doesn't make me a master hacker, it just gives me another tool I can use to make my future job easier.

sonic rover
#

Hey people, silly question, i looked through some bug bounty programs and i found that it is really common to find that CSRF is out of scope, anyone knows why?

prisma axle
#

because social engineering is basically always out of scope and csrf typically needs the help of it

#

its basically just controlling a privileged user

sonic rover
#

Oh i see

#

Thanks for answering 🙂

eternal garnet
#

From my experience, Python is good to create undetectable Payloads, alot of metasploit and veil framework payloads are recognized by anti virus, so if you master python, then you master payloads and also you will know how to communicate with servers via python codes

vocal folio
#

I mean python payloads are picked up too

#

Just ask our own Elf

prisma axle
#

you clearly dont understand the concept of how an AV works

ruby skiff
#

Failed

vocal folio
#

AV works a lot like the moderators here. If you do sketchy things, we assume you're sketchy

ruby skiff
#

Anything can be detectable if detected by signatures or known behaviour or the heuristic modules

sonic rover
#

From my experience, Python is good to create undetectable Payloads, alot of metasploit and veil framework payloads are recognized by anti virus, so if you master python, then you master payloads and also you will know how to communicate with servers via python codes
Python is a programming language, it's not magic, i saw earlier you saying that python is good to hack, and it is because its easy to get into it, but what matters is what you can do with it, and also some metasploit payloads are written in python.

eternal garnet
#

@ruby skiff yes thats true, but can a pen tester reach the level of expert hacking without knowing coding, look at the virus stuxnet and the spyeye trojan, so what im trying to say is to become a state hacker , we definitely need to master a language , would anyone agree?

ruby skiff
#

Who wants to work for the state.

vocal folio
#

In order to write your own malware, you need to be able to write code?

#

That seems... out of scope but kind of self explanatory.

eternal garnet
#

@ruby skiff ok not the state, but hackers at that level

#

that can simply breach government networks

ruby skiff
#

Well, that's very out of scope for this channel. And it's sketchy as all hell. So I'm gonna steer away from this convo

eternal garnet
#

@vocal folio how else can malware be written, im not aware

vocal folio
#

What

eternal garnet
#

@ruby skiff lol im just a drop out kid , but i am amazed of there work,

#

and i want to learn the right way, imagine walking in the wrong direction for 3 years just to find out i had to walk the other way

ruby skiff
#

As I said, I am steering away from this convo. Please do not @ me anymore

eternal garnet
#

ok

prisma axle
#

@eternal garnet please read the context of the conversation as well as the channel that you are speaking in. I would also advice not talking about hacking for a nation state like that as I seriously thought you were a bad actor and still do. Just be careful of what you say so you don’t get kicked out of here

young spoke
#

Ditto ^

#

And to turn this educational:

ruby skiff
#

Malware even if backed my a nation state is bad.

young spoke
#

You ain't gonna get anything done with anything near the high-level that is python

ruby skiff
#

That's the educational bit

young spoke
ruby skiff
#

And what CMN said

rose pecan
#

yeah this definitely isn't bug bounty related

#

bad

unreal horizon
#

Malware even if backed my a nation state is bad.
@ruby skiff
To be fair, any malware is bad

ruby skiff
#

Very true mate

tough garnet
#

👀

strong apex
#

Gotem

azure echo
#

what's up

tough garnet
#

what's up
Up is the direction diametrically opposed to the force of gravity. 😁

lavish hollow
#

We get it you like science smh

#

I’m kidding 😄

tough garnet
#

Everyone likes science!!

lavish hollow
#

Hell yeah!

tall scroll
#

Hey guys i need guidance with starting bug bounty i am good with python programming but dont know how to start with bug bounty.

lavish hollow
#

James gave a guide

#
  1. Get good at web hacking
  2. Sign up for a private program
  3. give up when you realise it's not a get rich quick
tall scroll
#

Ok i am good with web security too

#

What kind of private programme are we talking here ?

#

*program

lavish hollow
#

I’m guessing a programme that’s private but you might want to google

#

There’s tons when you type “private bug bounty program”

tall scroll
#

Ok thank you

slim bolt
#

guys is this channel a general bug bounty channel or THM has a bug bounty thing?

ebon tapir
#

Both 🤔

vocal folio
#

Bug bounty discussion chat for all things related to bug bounties

eternal garnet
#

@prisma axle sorry what do you mean by bad actor, im just qurious and have questions, i can verify my identity if you like to prove im just a normal student:(

#

Guys, to become good a bug bounty, what courses do use recommend 🙂

lavish hollow
#

1. Get good at web hacking
2. Sign up for a private program
3. give up when you realise it's not a get rich quick

#

So you'd probably want to look into web hacking

storm herald
#

i need an analsyis/ network admin/ reverse engineer / digatial forenses help
like i installed an obvious do not install this will fuck ur shit up malwared out hacked new high end video game title and didnt do anything to it for about 6 months, when my laptop was getting to where it could have hurt its hardware and started to look at everything
and its been a nightmare
like ive done resets across multiple devices so many times
like i have the most crazy looking .pcap files
other wifi's in the area have duplicates running in the range of my pc
its fucked
like this has got to be some real deal hardcore pwnage
like im so pwned. my router login page is now gone. i discoverd that it had custom java script loaded into and has 3 wifi ids acossiated with it

ruby skiff
#

First of all, wrong channel. Second of all, well, you've learned why piracy is bad as well as the fact it's stealing. Third of all, please mind your language. Try #general.

lavish hollow
#

hex rule 15

solemn yoke
#

what is this room made for

sonic rover
#

well, talking about bug bounties

ebon tapir
#

Bug bounty discussion chat for all things related to bug bounties

hollow drum
#

hi guys.. can anyone please tell me how to learn bash script? Any good resources or something?

lavish hollow
#

Not really for bug bounty

hollow drum
#

oh sorry.. it was for automation, btw

fallen palm
#

hi guys.. can anyone please tell me how to learn bash script? Any good resources or something?
@hollow drumjust try to make a script of your own choice and without using the internet

opal spoke
#

can anyone help with downunder ctf

#

?

hollow drum
#

@hollow drumjust try to make a script of your own choice and without using the internet
@fallen palm but i'm a noob with no scripting experience

tough garnet
#

You're never actually going to learn anything if you don't try it.

compact isle
#

What are some enumeration resource for a heroku endpoint?

young cloud
#

nmap

granite dust
#

X509v3 Basic Constraints: critical
is this vulnerability ?
which tool is best for Improper TLS protection ?

still jasper
#

Not sure but I searched this up and it might help @granite dust

brisk rover
#

Hi guys! Do Gigya API Keys need to be private or is it okay to find one in the source code? I found one as a value of a parameter of a javascript file and when visit it and I remove the key from the parameter I get an error (invalid api key instead of the script). And in that file I also found an ssoKey. The documentation (developers.gigya.com) doesn't seem to tell if it needs to be kept secret or not

ruby skiff
#

API keys are supposed to be a secret that only the client and server know. Like Basic authentication, API key-based authentication is only considered secure if used together with other security mechanisms such as HTTPS/SSL.

brisk rover
#

And what if there are 2 types of keys? Secret and just an api key?

#

Does that mean that the api key is allowed to be disclosed in the source code or not?

ruby skiff
#

API keys should be kept secret as I said.

#

As they are unique

#

But usually wouldn't class as a bug bounty as needs social engineering

brisk rover
#

Thank you!

#

I won't report it --> no impact

lavish hollow
#

Social engineering? Depending on the company can’t you use fuzzing tools to determine what input the API needs

vocal folio
#

Some of the methods look... destructive

lavish hollow
#

It may as well be but having a level of certainty will allow you to choose what method you take

#

API fuzzing is just brute forcing mainly, and a friend of mine who uses an API has a blacklist feature which uses an algorithm to detect patterns and similarities in what is being entered to the API, as well as a lockout feature after a specific amount of tries.

Having this information allows you to proceed carefully.

vocal folio
#

Jabba

#

I don't understand what point you're making

#

APIs have documentation. This is a key for a third party API which has public docs.

lavish hollow
#

My point is that social engineering isn’t needed

vocal folio
#

You should NOT be fuzzing anything

lavish hollow
#

Yeah it’s bad hehe

#

Oh I wasn’t aware it was a public api

vocal folio
#

Social engineering? Depending on the company can’t you use fuzzing tools to determine what input the API needs
@lavish hollow Interacting with the API wasn't really brought up

lavish hollow
#

I was under the impression that as Hex said “Social Engineering” he was hinting that was the only method of using an API

#

Unless my fatigue is making me completely miss the point of the discussion and stupidity* kekw

ruby skiff
#

I left that out so they didn't go and do it

lavish hollow
#

I mean they wouldn’t get far

upper rover
#

can anyone send me the tryhackme bug bounty page link?

lavish hollow
young spoke
lavish hollow
#

Lmao

young spoke
#

rE

#

ahaahaa

upper rover
#

yeah this one. Thanks @young spoke

lavish hollow
#

:(

young spoke
#

Aha!

upper rover
#

😆

lavish hollow
#

I see how it is.

young spoke
#

xD I win this round Jabba

brisk imp
#

anybody know about a way to exploit xss in referer header? the site does not filter or encode the value before rendering it but all browsers url encode it so im having a hard time exploiting it

hybrid orchid
#

Maybe curl?

brisk imp
#

how so?

#

will the js acually run then?

tacit kernel
#

The Referer request header contains the address of the page making the request. When following a link, this would be the url of the page containing the link. When making AJAX requests to another domain, this would be your page's url. The Referer header allows servers to identify where people are visiting them from and may use that data for analytics, logging, or optimized caching, for example.

See security considerations: https://developer.mozilla.org/en-US/docs/Web/Security/Referer_header:_privacy_and_security_concerns

#

You would need something to evaluate the JS in the referer header which isn't likely unless the refered URL is in itself containing an XXS vulnerability, but this would just be forwarding to a malicious payload and will not count as an exploit on the original refering site

craggy onyx
#

guys i am beginner in bug bounty so ay chance i can get references or any courses you suggest for this kind of field?

prisma axle
#

hacker101 and the talks given by Jason haddix can be a great place to start @craggy onyx

craggy onyx
#

okay thanks!

dense prawn
#

hacker101 and the talks given by Jason haddix can be a great place to start @craggy onyx
@prisma axle being a web developer, is a prerequisite before going to the bug bounty??

ruby skiff
#

No @dense prawn

vocal folio
#

No but it helps

junior helm
#

hi all, new to this server (and networking in general).. just out of interest how much do good bug finders get or is it more for the kicks?

vocal folio
#

Depends on the platform, program, and severity

#

It's not a stable source of income

ruby skiff
#

Depends on all those things. Don't rely on it as a source of income

#

It's very much like the lottery

tacit kernel
wary vortex
#

Anyone know where I can find a template for a contract that a company won’t sue me for the bug I found? They want to work with me, but I wanna be safe

tacit kernel
#

You'll need a memorandum of understanding

#

It's a document outlining the agreement between two party's, but it's not legally binding

#

But it's a good way to outline the agreed engagement etc...

#

Further legal documents required can be discussed with a solicitor for large clients but if your planning on engaging as a business you will need insurances you can discuss in due process

#

It depends on how deep you want to go

#

Usually this is overkill for a freelance client and an agreement will do

prisma axle
#

Hey I would not work out contracts yourself theres a company who fights for security researches rights let me find them real quick

wary vortex
#

@tacit kernel are there templates for such an agreement?

teal elm
#

can anyone send me the sample report of any bug bounty ?

tacit kernel
fresh shell
#

Any advice for an absolute beginner bout to start ....

still jasper
#

Read writeups, read books, do some research

#

and most importantly

#
  1. Get good at web hacking
  2. Sign up for a private program
  3. give up when you realise it's not a get rich quick
fresh shell
#
  1. Get good at web hacking
  2. Sign up for a private program
  3. give up when you realise it's not a get rich quick
    @still jasper Any Free Practice website at first?
hybrid orchid
fresh shell
#

Yaa that I got it but any other places?

vocal folio
#

HTB, portswigger academy

obtuse lake
#

#bug-bounty message

Youtube is a source but not always a reliable one, but twitter is always a good place to find people that are like minded, as is the obvious Discord servers... but read up on bits figure out what you want to gain at the end of it, are you doing exams or just for shits and giggles?

fresh shell
#

HTB, portswigger academy
@vocal folio thank dude

eternal garnet
#

Guys since this is a bug bounty channel , what should I learn to become good at bug bounty other than learning JavaScript

modest vector
#

Look up the OWASP Top 10. It has the most common vulnerabilities covered. @eternal garnet

eternal garnet
#

@modest vector thanks dude 😁🙋

eternal garnet
#

Guys we’re can I learn sqlmap

compact axle
#

Google ?

graceful cairn
#

sql injection room

vocal folio
#

IIRC many bounties don't allow sqlmap?

drifting flume
#

sqli room x2

eternal garnet
#

@vocal folio ahh I never knew that

vocal folio
#

Always read the scope

#

Otherwise you can get in trouble...

#

Like, a lot

eternal garnet
#

Ahhh thanks man

prisma axle
#

I vote adding phishing and social engineering to the tryhackme scope... I wanna phish skidy

#

I have the perfect idea for a vector

vocal folio
#

"Get 40% off your AWS bill today! Jeff Bezos hates this one simple trick!"

young cloud
#

"Why you need to learn AWS discounts NOW!" - NetworkChuck

prisma axle
#

I was thinking of either an AWS bill or a DO outage

#

maybe a cloud flare outage

ruby skiff
#

DigitalOcean not working properly? Try this one simple trick!

drifting flume
#

I vote adding phishing and social engineering to the tryhackme scope... I wanna phish skidy
@prisma axle I never seen a scoope with phishings before...

prisma axle
#

It’s almost always out of scope however there is one that does

compact axle
#

Also, you have to add your credit card like most "trial" services, and they more times than not try to charge you for something

native trail
#

Idk why iposted this on here fml sorry moving it

wheat canyon
#

!hoonk

#

!honk

marsh falconBOT
#
TryHackMe
***HONK HONK HONK***
graceful cairn
ruby skiff
vocal folio
#

@grim stag no invite links

wheat canyon
#

Oh shoot

south tapir
#

Anybody there need help

still jasper
#

Just ask what you need help with and someone will help you

merry plume
#

!rule 13

marsh falconBOT
#

Rule 13: When asking for help/tech support please perform research to your fullest ability. Mods and Community Mentors have the right to refuse helping those who have not done troubleshooting/research on their own first. Clearly phrase your questions as we (fortunately for all parties involved) cannot read your mind. Please include the room, task, and question number in your question if possible.

Although we are a a learning platform, we politely ask that you respect the competitive nature of newly released challenges. As such, no hints for new challenge boxes should be given immediately after a release, unless specifically allowed by the content creator.

merry plume
#

don't forget 😉

dapper nest
#

hey guys I'd like to ask a question about web cache poisoning. I don't understand what "unkeyed header" means. does it refer to the headers that web server just doesn't look at, when deciding whether to send the response from cache.

burnt silo
twilit kite
#

hi

mossy island
fair nymph
#

Does anyone know out of curiosity if pentesterlab teaches sql injection well enough for example or is the content given just challenge based?

boreal sail
#

!honk

marsh falconBOT
#
TryHackMe
***HONK HONK HONK***
brittle hare
#

I found a bug in ms teams

#

If I enter into a meeting and leave it , it will still show people that I am in the meeting

grim widget
#

@brittle hare Without any security implications, that's pretty useless

brittle hare
#

But bruh it’s a big issue cause people will think the people is still online

#

Even tho they aren’t

#

And even time issue also

#

If I text in teams

#

The next msgs the time is earlier than me

#

How is that possible??

lavish hollow
#

I mean you can report it

#

But I’m sure bug* bounties are more related to security risks or something really ground breaking

#

( Correct me if I’m wrong )

#

Also you’ll need to see if you can replicate it on another account because it sounds really vague and I’m sure many people have left and joined meetings before?

frail compass
#

^

fallen palm
#

!honk

marsh falconBOT
#
TryHackMe
***HONK HONK HONK***
coral kraken
#

Anyone has a script that installs most used tools for bug bounty

lavish hollow
#

Install Kali Linux

coral kraken
#

Already installed

fallen palm
#

What tools are you missing?

lavish hollow
#

You’re only limited by your knowledge, if you find a potential exploit you need to know what you need to exploit it

#

Well that’s my opinion anyway

grim widget
#

Well that’s my opinion anyway
@lavish hollow Fully agree

frail compass
fallen palm
#

Hi

#

İm want learn bug bounty

#

İm read some article about bug bounty

#

So im learn half html5

#

And learn half Python

#

Loaded kali linux in the my pc

#

what should i do now

young cloud
#

Keep learning for a while.

fallen palm
#

okay but what is it

#

I will be glad if you help

still jasper
#

I'm quite new to bug hunting and got invited to a private program and I did some LFI and it changed the RID value within the source code when I did /..ls?=false i'm not sure if that does anything but then I came across something which was a reporturl and this is what came up when I got directed to the directory and i'm not sure if I am able to do anything with it FL(nginx,NoCookies)|name=ruxitagentjs|config=domain%3D<programname>%7CreportUrl%3D%2Frb_bf98738ejy%7Capp%3D3300639e6ec22919%7CfeatureHash%3DICA27SVfhjqrux%7Cvcv%3D2%7Crdnt%3D1%7Cuxrgce%3D1%7Cbp%3D3%7Ccuc%3D6og6s1z8%7Cdpvc%3D1%7Cmd%3Dmdcc1%3Dcpnum%7ClastModification%3D1602760231903%7CdtVersion%3D102012009048458022%7Ctp%3D500%2C50%2C0%2C1%7Cuxdcw%3D1500%7Cvs%3D2%7CagentUri%3D%2Fruxitagentjs_ICA27SVfhjqrux_10201200909654722.js|featureHash=ICA27SVfhjqrux|version=|buildNumber=10201208945073022|lastModification=1602760231903

hollow drum
#

hi guys.. where can I find sensitive information in a .git folder, if it is publicly available?

lavish hollow
#

Do you have explicit permission that you’re allowed to do this?

hollow drum
#

it's a bug bounty program

lavish hollow
#

So you’re on a private program?

hollow drum
#

yup

lavish hollow
#

I’m just interested because you’ve come here before googling which makes me question your skills

hollow drum
#

no I've tried searching.. but I couldn't find how to look for sensitive data. some of the results are too complicated for me.

#

i'm a noob, btw

tough garnet
hollow drum
#

thanks man

manic mango
#

Hay guys anyone here

vocal folio
#

Yes.

rotund saffron
#

Yeah

graceful cairn
#

🌾

vocal folio
#

I believe you should be told how to authenticate

#

This status is sent with a WWW-Authenticate header that contains information on how to authorize correctly.```
#

Yes the server could do it by IP address

#

It'll be some serverside config

#

I doubt it'd be a single IP on the blocklist

fallen palm
#

maybe you're in the same CIDR class as an employee? idk

vocal folio
#

Probably subnet addressing instead of regex

#

regex totally the wrong solution

fallen palm
#

yeah, regex and IP suck to combine

brisk rover
#

Something like this right 0.0.0.0/24?

fallen palm
#

for a class C, yeah

vocal folio
#

I tried to replicate the misconfiguration and found a nice solution which didn't work
@brisk rover I don't think it's exactly a misconfiguration?

#

There's APIs to see if an IP belongs to a hosting provider or Tor exit node

#

Then you can make life annoying for those people because they're not likely to be legit users

#

yeah, I never said it wasn't

#

Not really

tacit kernel
#

So this looks more likely to be the case of tor exit nodes being blocked

#

I also have never know a bug-bounty program require such a configuration.

#

So why do you need to tunnel through tor?

#

If it's working without tor, then you have access correct?

#

So what's the catch?

#

So you're able to access a website when you're not using a VPN or tor, and that's considered a bypass?

#

It sounds to me that it's just filtered by blacklist rules

#

Be more specific with your explination or provide a URL and test case

vocal folio
#

Is it a school website?

brisk rover
#

No

#

A company which has a responsible disclosure

tacit kernel
#

What's the URL?

brisk rover
#

Via dm

tacit kernel
#

DM me the URL then

brisk rover
#

Suitguy, man, I don't know what's wrong with you, but you are clearly thinking that I'm a black hat

#

But that's okay

wheat canyon
#

👀

fallen palm
#

lol recently started and made 500 the other day

fallen palm
#

lol recently started and made 500 the other day
@fallen palm really!! i'm new to all this

ruby skiff
#

It's a bug bounty

drifting flume
#

lol recently started and made 500 the other day
@fallen palm How you did that? lol

fallen palm
#

Yeah

#

You Find a reliable source to sign up for to start bug bounty then there's something called A bounty board where they have companies asking for help with certain things and if you find what they're looking for and you need to make a really good report describing everything and how can it it affect the company and then you submit but you need to provide evidence as well

#

If you have anymore questions feel free to DM me

#

@drifting flume @fallen palm

lavish hollow
#

I don't want to DM

#

But I am curious of what vulnerability you found, if you don't mind me asking

#

👀

fallen palm
#

Account breaching vulnerability

vocal folio
#

Account takeover?

fallen palm
#

Essentially

#

@fallen palm check your dm

drifting flume
#

I mean
How to find a bug at your first day on bug bounty
To normal people take months

fallen palm
#

for big ones

#

i found a very minimal one

#

took me till sunrise

#

now there is one that is $20,000 on the bounty board now that will take months

#

i got paid very little $500

#

for finding a decent sized vaun its about $1,000

#

@drifting flume

drifting flume
#

Which plataform did you use?

fallen palm
#

hacker1

drifting flume
#

Thanks !!!

fallen palm
#

really reccomend it take the small jobs first

#

like i did

#

they don't usually take long

drifting flume
#

Hackerone is really competitive
But of sure is the big one

fallen palm
#

lol

fallen palm
#

Hi

wraith pewter
#

hello guys

#

can anyone tell me bug bounty(related) rooms ,to improve skills

fallen palm
#

Hello there @wraith pewter

#

Please dont post in other chats

#

For bug bounty related stuff, keep it to this one

wraith pewter
#

anyone

fallen palm
#

Please be paitent

prisma axle
#

@wraith pewter burp, juice shop, zap, authenticate, ssrf, OWASP top 10, ZTH web, ZTH web 2, Upload Vulns, Web Fundamentals, Inclusion, web scanning, sublist3r,

#

I dont know thats just a few on the site that might help get you into the flow of bug bounty

#

theres tons of other web challenges on the site as well

vocal folio
#

anyone
@wraith pewter literally web. Take the web path if you want.

rugged cradle
#

how to get started in bug bounty,, I new vulnerablities but I am bad at finding bugs..

#

*knew

hidden widget
#

Have you Googled?

rugged cradle
#

ofc

faint crown
rugged cradle
faint crown
#

@faint crown thanks ...
@rugged cradle you're welcome dude

rugged cradle
#

😃

wraith pewter
#

Anyone tell how does CVE is useful to bug bounty

merry plume
#

well

#

a cve is an exploit

#

and bug bounty is about finding exploits

prisma axle
#

no there isnt a lot of connection between bug bounties and CVEs, you can find CVEs as a result of a bug bounty program or you could use a CVE to exploit a specific application the program is using (must be in scope) but is very rare because of scope, updates etc. for the most part you wont use CVEs in bug bounty

modest vector
#

You can learn a lot from reading CVE entries. It shows the various vulnerabilities found for a particular piece of software/vendor, how they are reported, weighted by CVSS score, research related to a vulnerability, related proof-of-concept exploits, and the different vulnerability types that exist. A good site to do research: https://www.cvedetails.com @wraith pewter

wraith pewter
#

Tq

#

Could u give one example how to exploit with cve

#

Links,demo or something

vocal folio
#

It will vary massively depending on the CVE.

prisma axle
#

There’s lots of rooms on thm that highlight cve you can search in the hacktivites page for ‘cve’

sterile karma
#

how should i get started with bug bounty?

prisma axle
#

y’all are really gonna make me want to make a blog post on getting started on bug bounty aren’t you

vocal folio
#

I have a summary somewhere

#

1. Get good at web hacking 2. Sign up for a private program 3. give up when you realise it's not a get rich quick

drifting flume
#

y’all are really gonna make me want to make a blog post on getting started on bug bounty aren’t you
@prisma axle Finally you notice it !!!

rose pecan
#

@vocal folio you're forgetting about
25 closed for dupes
103 Will Not Fixes
and
927 Not Applicable

prisma axle
#

don’t worry spooks a little salty from him staying up till 2 am doing bug bounty then the company saying nah we good fam

modest vector
#

817 non-exploitable findings, not defects. Oh Bug Bounty, the art of not paying out.

prisma axle
#

so I will be stealing that and making it a blog post

lime ginkgo
#

hello

#

hi

prisma axle
#

hey, do you have a bug bounty topic or question?

green mist
#

!help

vocal folio
fallen palm
#

discord pays so little in bug bounties

fickle heath
#

Does self-xss need to be either stored or reflected or can it just be none of those 2

vocal folio
#

There's your categories.

analog crest
#

I clicked in hear thinking you guys had posted bounties. Lol

prisma axle
#

There are bounties for thm posted

strong crag
#

Anyone got some good resources to learn Nuclei, or should I just start exploring and building my automation based on the github documentation?

fickle heath
#

Guys I have a question
If a client sends 2 csrf tokens, but they are different: is this then still double submit validation serverside ?
or must they be equal ?

strong crag
#

hard to tell without actually looking at the code, but they might be 2 csrf tokens for 2 different validations, and that's why they may be different

sharp flame
#

anyone here wants to be my mentor on bug bounty where i follow along and learn I dont want bounties i just want to learn and i learn best by seeing and working along with someone

still jasper
#

This is how I learned the basics

ruby skiff
#

@sharp flame Why do you wanna do Bug Bounties?

sharp flame
#

so that i can learn more just learn better working along with others and i enjoy pentesting and i feel it could help me advance in the field and secure a job in the industry

#

thanks blackout

hollow urchin
#

hello who is admin ?

vocal folio
#

@hollow urchin ?

hollow urchin
#

i found a bug in the platform

#

who report this ?

#

how*

vocal folio
#

Is it a bug or a security issue?

hollow urchin
#

sorry my english is so bad

#

maybe security issue

vocal folio
hollow urchin
#

thanks

#

uwu

dapper saffron
#

@fickle heath if there is two csrf tokens in request then try to send one and see if request go through without any errors

trail idol
#

I'm not sure if this has been posted or if this is the correct area to post this, sorry in advance. Feel free to delete or move the post if necessary. I just stumbled across this and figured it was worth a mention.

https://www.samsung-qledecode.com/

granite ravine
#

Well, this is another thing about QLEDecode

#

It's a 7z

#

But with password

#

Also decoded the file name bm9tdXNpY2J1dGl0J3N0aW1ldG9kYW5jZQ with Base64 and it came out to nomusicbutit'stimetodance

#

Found from reddit.

trail idol
#

@granite ravine nice. The password shouldn't be too hard to crack

granite ravine
#

Apparently it is, as twitter and reddit people say

iron shuttle
#

Anyone here who can help me with an android app issue??? I'm testing it and found something need help regarding that

prisma axle
#

Can you give some more specifics

#

does the app have a bug bounty or responsible disclosure, what is the vulnerability generalized, can you weaponize it for PoC, would It be considered a low hanging fruit and not even worth submitting?

rugged cradle
#

!help

hearty warren
#

argh getting so close to finding a way through exploiting one of the exploit on this bug bounty site.

#

can someone help me break this barrier?

prisma axle
#

@hearty warren sure can you just explain here some of the steps you’ve taken and what you’re stuck on without giving away the bounty itself obviously

hearty warren
#

its much easier to show

prisma axle
#

Can you show it here without leaking too much?

hearty warren
#

is it ok to share http request from burp? there is three consecutive requests.

#

it doesnt have sensetive information

prisma axle
#

yeah

mystic atlas
#

Portswigger Academy

hearty warren
#

so basically after sending the request to sign in. i think what is happening is it redirects me back to the login page because it cannot find the email. This is annoying because i can technically get unauth bypass. The way to go from here is two ways:

#
  1. maybe the WAF blocked the requests 2. SQL injection on the email address.
lament nacelle
#

hello im working on a ug bounty atm and i found a kraken-test subdomain kraken is in scope but would kraken-test be in scope as well?

still jasper
#

Does the policy say anything about it being out of scope?

lament nacelle
#

It does not say anything about kraken-test being out of scope

still jasper
#

Then it should be fine

lament nacelle
#

Sweet thank you for your help @still jasper 😁😁🙏

young cloud
#

Well, it depends. Does the program have a wildcard subdomain listing?

#

If not, subdomains are probably out of scope.

#

Really is best to err on the side of caution and go with what IS stated, rather than what isn't.

lament nacelle
#

it does not have a wildcard subdomain listing.

#

i see where your coming from @young cloud thank you

young cloud
#

If it were me I wouldn't touch it in that case. You're welcome.

vocal folio
#

I'd have thought you could ask?

young cloud
#

Ask the company/target?

#

I doubt they would do a case by case approval with the amount of people there are in those public programs.

prisma axle
#

depends on the security team some are super duper chill

paper bobcat
#

hey I am trying to inject SQL into a website for finding bug. when I write ( ' ) at the end of the url it's return error code 500 so is this website vulnerable to SQL injection ?

by the way thanks in advance

young cloud
#

Research error code 500.

#

Could mean a world of different things.

wanton mica
#

Hey, I am new to bug bounty,
Can anyone already doing bug bounties teach how to go on hunting for bugs, I just want a person to collaborate and learn with

blissful merlin
#

@wanton mica DM..let's talk

low crest
#

yea pls me too i wanna learn bug bounty as well

pine scroll
#

same

quaint bronze
brazen coyote
#

@paper bobcat its not always for sure tbh
but you should try more than just ' in order to spot SQLI

#

also once you get a different web page once you add ' there are a lot of possibilities that is vuln

paper bobcat
#

@brazen coyote I have added more sql payload many of them put 500 error and some put 403 forbidden

brazen coyote
#

@paper bobcat the 500 error code says internal server error?
and the 403 says forbidden?
that means that it uses a waf

paper bobcat
#

oh I see so is the web not vulnerable ?

brazen coyote
#

@paper bobcat either find some cheatsheets that bypass them or check other params or use sqlmap with certain tamper scripts
its not certain if it is vuln or not

paper bobcat
#

ok bro thank you very much @brazen coyote

brazen coyote
#

@paper bobcat np happy to help

tranquil kindle
#

@brazen coyote I have added more sql payload many of them put 500 error and some put 403 forbidden
@paper bobcat Note that
Error 500 means Server request failed and Error 405 means Client request failed =this might be due to bad url

#

oh I see so is the web not vulnerable ?
@paper bobcat lol every site is full of vulnerabilities sir

brazen coyote
#

@tranquil kindle ι think but i am not sure tho 500 might be the "internal server" error and 403 is forbidden

tranquil kindle
#

@brazen coyote Exactly sir

#

NOTE:Tho sir in most cases any request concerning 4xx are not usually forbidden they might be due to incorrect syntax and can't be fulfilled.

hybrid orchid
#

4xx are client side errors. 5xx are server side errors. Could be any number of reasons for either of them.

#

418, for example, indicates that the server is a teapot

prisma axle
#

Hmmm

#

I have a new mission in life as well as room idea

hybrid orchid
#

If it's making a webserver that responds to everything with "I'm a teapot", beat you to it

merry plume
#

Why didn't James utilise this for the Mad Hatters Tea Party?

vocal folio
#

Because it breaks stuff and it's concerningly unsupported

prisma axle
#

but teapot James

remote coyote
#

@tranquil kindle

trim nexus
#

Sqli dropping ?

low crest
#

where can i start to learn buh bounty? cause im new anyone u can tell me and patiently teach me pls dm me

quartz aspen
#

where can i start to learn buh bounty? cause im new anyone u can tell me and patiently teach me pls dm me
@low crest port swigger's academy teaches web focused attacks, as well as lots of the rooms here

low crest
#

port swigger free right>

quartz aspen
#

mhm

prisma axle
#

also hacker101

last flare
#

The server response content-type header is JSON. you found a reflected parameter. is it exploitable? if yes, how?

heady raptor
#

imma hunt some bb right now.

#

i am gonna get a cve like mayor

fickle shale
#

hey guys, fairly new to the channel. I have signed up for THM - can someone help me with a list of rooms on THM for practising bug-bounty skills? I have searched using the bugbounty tag and it returned only a couple of rooms.
cheers! 🙂

young cloud
#

The web-app pentesting path is a good place to start.

mossy island
fickle kite
#

Quick question regarding encoded data...anyone got a second?

#

I'm trying to intercept some data being sent via burp suite and everything thus far has been base64 encoded JSON data. I'm running into an issue with one request where the request looks to be base64 encoded but uses "compression=lz64" at the end. Is this just simpely sending the compressed data string for decompression on server side?

prisma axle
#

I havent encountered that but I would assume so

fickle kite
#

yeah I'm wracking my brain trying to understand if I can even decompress / decode the data...I don't think I can

brave kestrel
#

hello everyone

limpid umbra
#

Hello!

lament nacelle
#

Hello everybody I hope your all doing good and staying safe 😁 I have a question if someone wouldn’t mind answering. I started using zaproxy on my target but now I’m getting notifications from xfinity saying they blocked an attack from my machine. Now I know what I’m doing isn’t bad so should I use a paid VPN to get around the notifications?

lavish hollow
#

Hello @lament nacelle, I hope you have permission to do this 😄
I'm not perfect but if you're being detect through using a zaproxy webcrawler, I'd recommend using Burp Suite if zap is being blocked, depending on your use

#

Oh wow I completely misread the question

#

I mean you can try a paid VPN but most companies do not block permanently from accessing the website.

#

If it's a bug bounty then make sure you're within the guidlines

lament nacelle
#

I’ll have to reread the rules of engagement but it’s weird getting those with other people living with me they get them too I’d just like it to end but still be able to continue learning big bounties

ruby skiff
#

If your router is blocking it. You can disable that feature at your own risk. Or allow exceptions. You'll need to Google it

fickle kite
#

I was just about to ask if it was a router issue

lament nacelle
#

The issue is these almost scary notifications from xfinity saying they blocked an attack from my machine and there needs to be further action. It’s obviously a way to try and scary me but I’m not doing wrong I got the target from bugcrowd 😂😂 I’d just like to see if anyone had experience using a VPN while conducting a bug bounty. I’m sorry I should’ve worded this better 😅

lavish hollow
#

@lament nacelle I'm not 200% sure but I believe you need written permission to attack a website. 🙂

fickle kite
#

is xfinity the target of the bounty?

lament nacelle
#

Yes I have permission. I’m using xfinity as my internet provider and their sending me notifications when I start using zap on my target. I’m using realfself as the target of the bounty.

#

I think I’m going to just try it and if it works ill be good but if not I can get a vps 😁 thank you guys @lavish hollow @fickle kite @ruby skiff

frail compass
#

you can always get in touch with your ISP to ask for less restrictive access

modest vector
#

This is a good example illustrating that permission also is required from the source network from which attacks are staged.

mellow abyss
#

I did not see the web app pentesting path

fallen palm
#

Wrong channel

mellow abyss
#

Oh i mean in thm

fallen palm
mellow abyss
#

Thanks.

tough pond
#

what should I do

still jasper
#

Do they not have an email you could send it to?

tough pond
#

No

#

and knowing my luck

#

I'll get arrested

#

because of the sheer amount of data

#

I can send you a sample if you want

still jasper
#

That’s most likely the case you could potentially end up with fines and no that’s ok

tough pond
#

or if you hop in vc

#

I can explain it

#

Nah I think not

still jasper
#

Don’t share it with anyone