#bug-bounty
1 messages ยท Page 8 of 1
Skidy msged me and said he will be helping me out privatly in a few hours
but i wont be around
Yea ok letโs just not discuss anything further
-mute @tough pond I will talk to you in a moment. - TryHackMe discord
๐ Muted SoFacy#9117 for 1 day
๐ ๐ ๐
Sorry in advance for this question...(I'm still learning)...has anyone had a netcat session listening...and a connection was established from a random ip?
I sent a payload while doing some bug bounty stuff...and had a listener open for 2 days...I gained a connection but from an IP that looks to be a Chinese website...not even close to the ip scheme used by the bug bounty client...I closed the connection when I found that it wasn't the target site...but what does that mean?
thats normal
bots scan the entire internet
any bug bounty hunters active?
I am a newbie to bug bounty and I am kinda scared for the same. Can someone point me in the right direction?
How should I start in Bug Bounty?
Even I want to start with bug bounty.
me too haha
iโm kinda new to this whole infosec thing, what exactly is a bug bounty?
is it exactly what it sounds like or is there more to it
Sounds like an easily google-able question ๐
Lots of companies have a bug bounty programme where they basically publish a scope of what you can and can't attack in their infrastructure, then let anyone who wants to do it attack.
If you find something you often get paid, but it's far from stable money.
may i know which room is related to bug bounty scenarios so that we learn bug hunting practically ?
Check out the web fundamentals path ๐
oh okay so it is what it sounds like, thanks!
Hello guys
is there any bypass to bypass origin check in CSRF
How to start in bug bounty
Learn web hacking
Then sign uo for private programs
Then get disappointed when you realise that it's not a secret tk getting rich
And all your bugs get marked as duplicates
Any recommendation
TryHackMe is good
@teal totem I am also starting to enter bug bounty. So i joined tryhackme
Hello guys, need help, I found some hard-coded cryptographic keys in an target what to do with that, it looks something like this
private static final byte[] 7r38r = {12, 74, 81, -80, 32, 101, -47, 72, 117, -14, 0, -49, 70, 25, -12, 54};
How to create wordlist based on theme ?
What do you mean?
There are some ctfs running on a particular cartoon themes
So how to create wordlist based on that cartoon themes ?
For password recovery
Crunch, cewl , namely
I am fine with the tool
But the names in the wordlists I am worried about
The names should be created as per the cartoon characters if it is a cartoon based theme
So then what do you want / need help with?
@limber flicker just for cartoons names and theme based word list
@weary axle yeah.
Hey guys! Anyone interested in joining me to try bounties together?
Iโm fairly new to bug bounty and would like to learn more about it by joining or creating a team and sharing resources.
@torpid dawn
I am also new. We can try together ?
Yeah. Iโll DM you.
Here Buddy. I'm New Too
Can I Join You Guys?
I'm fairy new too, would definitely be interested in joining you guys
Feel free to dm me to @summer fractal @void axle @torpid dawn @limber flicker
can some one help me with this : i found this by little digging site from outside.
idk what to do with this but it seems interesting to me , if i can extract some kind of data , or any thing
You should check original ajax request first. 
I'm interested in shadowing some bug bounty hunters if anyone would be kind enough to screenshare on a day they're bug hunting. Level 1 or 2/10 noob here but I'm looking to learn fast.
Iโve never heard of bug bounty shadowing but the best option you would have is looking through bug bounty write ups sometimes once NDA is gone hunters will release a writeup / report @fallen palm
ya if it's not dynamic enough to be something that i could watch via screenshare then i'll just check out static write ups. Thanks @prisma axle.
I guess I was thinking bug bounties were time sensitive as in the companies only payout for a 12-24 hour window or something
Nah
there's a single "k" on the old nmap room
on top of the website, so its not the room's content
im also new and lost i would like to get some help can i join?
@unreal horizon #room-bugs
Where can I apply to companies to become a bug hunter? What is the process? What are the rules?
you can try your luck with services like hackerone, bugcrowd, intigriti etc.
they are places for companies to advertise their bug bounty programs and for a bit more streamlined bug reporting process where you don't have to go through random support people
the rules depend from program to program so be sure to read them and the scope of it
@golden zephyr you can join
hey yall, im still fairly new to hacking does anyone have any advice for getting into bug boutnies
Start with Web Fundamentals Path on TryHackMe
THM has some good stuff you can use to start, you can also go through hacker101 on hackerone to get started
Thank you guys so much! i will be sure to check these out. I already been experimenting with someof the THM rooms lately
hi
Can anyone suggest some XSS write up please
Thereโs a lot on NahamSec Github page https://github.com/nahamsec/Resources-for-Beginner-Bug-Bounty-Hunters/blob/master/assets/blogposts.md
@torpid dawn can i join you guys too?
Oh there is nothing better than some clean documentation.
anyone wanna help me out on getting started with bug bounties
if you can you can send me a dm
pls
@candid bridge i can help you with the resources
@dapper saffron id love to check them aswell
i just saw that someone shared nahamsec github repo which have cool and enough resources for anyone to get start with bug hunting, if you need more then feel free to dm me and i will provide you more.
you can also join nahamsec discord channel which is all about bug hunting
thanks i will do that
!rank
Can you help me too
hello guys, can someone help me out .. ive known ethical hacking and i wanna learn python scripting for hacking as well as bug bounty hunting.. how do i begin practicing it
@lyric dock yeah feel free to ping me up here or in dm for any kind of help related to bug hunting
me too please
ask what you need
Hello Guys, I just got my Sec+ and interested in web pentesting. Do you advice try my luck on bug bounty? What things should I learn first?
hello guys, i actually new to bug bounty can anyone guide me that how can i start. what can i do at my initial phase
any one need help in starting bug bounty ib me will provide you material
yes please
i think you should focus on learning yourself bro you are just level 1 rn
Recently I started studying bug bounty. Not even a whole week ago to be fair... but I think i can already give some tips for starters too...
- "Jason Haddix methodology" on youtube is DEFINETELY something you need to check
- Basic knowlegde of network/kali/python (or any other language you can use for scripts)
- Read a lot. Theres plenty of books out there with tons of information
- Just start somewhere. There's some websites like tryhackme.com, pentestinglabs, hackthebox....
- Be consistant
books like?
a guy in a video mentioned those points i dont remember his name tho
and how could you do that all in a week bro
what books have you read till now
when i was starting i downloaded a bunch of books i didnt read much of em more like any of em
I didnt read any of those entirely. I use them to consult on something im needing atm... Im working on learning the basics and doing researchs
alright mate
Im a complete noob. But curious af
@ivory solstice Black Hat Python and Violent Python books are the way to go.
Google: Portswigger Academy. It's from the writers of The Web Application Hacker's Handbook, and the makers of Burp Suite.
^
Portswigger Academy is the best source for web vulnerability studying
It's both theoretical and practical
Hacker101 as well
So, I'm interested in try to submit bug bounties on hacker one. Can people point me to things I should read? My biggest fear is, how do I know I'm going to find something when I try to hack a commercial website like Facebook or Google? I don't want to probe around for hours and find nothing. Has that ever happened to anyone? I guess I don't have this fear for CTFs because I know the machine is meant to be hacked and there's a solution.
there are lots of different resources, hackerone has Hacker101 as well for teaching
you can also check the #resources channel as well
You really don't know if you're going to find anything
Even on smaller bounties, private programs
Bug bounty is not guaranteed. It's not a stable source of income, and the reward does not directly correlate with the work you put in
Private programs are going to be better, but they still don't change that much
Yeah i am agree with that
There is alot of competition in bug hunting and its only stable if youโre willing to spend countless hours / day
But still you can make good money and put good experience on your cv/resume
I don't want it for the money, I just want street creds for my resume so I can find an actual job ๐ , but I don't have 20 hrs/week to spend on it outside of work and find nothing.
That's the risk you take
Private programs reduce that risk as there are less people looking etc
What is meant by private programs? Is that not on hackerone?
is anyone up for helping me do recon on a bug bounty? just need the practice, i heard collabs were a great way to do things if your a noob
Invite only
Ahh but then how do I get an invite? I have to be good on a public program right? LOL
Some of the platforms have little CTFs that you do that opens up some private programs
you can get private invites by having a positive ranking (reputation).
either by participating in public programs and getting bounties and /or by completing CTFs in hackerone
are there any good sub domain finders besides sublister, im kinda having trouble with it
amass
wow its working great, thanks a bunch
Hey guys I'm new to bug bounty.
Can anybody help me to become a bug hunter. I dont know where to start can anybody plzzz help me.....
You need to learn web hacking
From there, you need to manage your expectations from bug bounty. Don't expect to get rich.
I use nikto for that. Works great imo. Gives you a list of possible vulns at the same time
Anyone who wants to get into bug bounty with the thoughts of getting rich quick, your dreams are going to get shot down so hard its not even funny
hey guys any good tips for bug bounty
trying to get into it to level up my web app skills
dont care about the money
Did any one got bug today?
I'm guessing you got the wrong room Joker
I feel like there's this air of bug bounties netting you alot of money. I believe even Jason Haddix states in his methology video that a passioned individual could net 5k - 15k each month. (could be i misremember and it's from a different bug bounty beginner video). But that sounds like A LOT of money. and seeing how most people in the community aren't earning that kind of money by a long shot it's kinda weird how the sentiment gets thrown around
This is inevitable.
๐๐๐well said..
The ones who make that are in private bug bounties, are 10-15 year veterans, and are pedestaled by the Bug Hunting platforms as join-bait. Most people make no money in the first 6 months at all. The ones that do are either already skilled in web application and web framework testing, or lucky incidents that get their 5 minutes of fame.
https://youtu.be/YU4QBjg703U Best video on the topic, the cyber mentor made one as well.
Why only a handful of security researchers and bounty hunters make it and how can you be one of them?
Free coding platforms:
https://freecodecamp.org
https://edabit.com
https://codewars.com
Free books:
https://www.py4e.com/book.php
https://www.golang-book.com/books/intro
https://books.goalkicker.com/BashBook/
Recon in Cyberse...
Yeah that makes sense. It's a shame because probably a lot of people will get dissapointed when they don't get instant results and stop improving their skillset all together
thanks for the vid ๐ it was a good, quick watch
It's okay to use it as an exercise of engaging with real corporate enterprise targets, and getting used to things like: scope, findings/defects, reporting, mitigation, etc..
I'm glad corporations now allow you to hack them, money or not. 20 years ago, it was not the case. You go to jail. =[
Sounds like the path for anyone to be top in any industry.
Of course
A lot of struggle a lot of hard work, failure after failure
And persevering through it all for the long term
How do you know that there's nothing to find versus you're just stupid/still a noob? LOL Is the 2 years recommended "practice" timeframe accurate?
TFW I did a report and the company doesn't want me to publish a write-up
But I'm credited
And got specific merchandise for the service I found it via
Lol
Not entirely
Know Victor Gevers? He's reporting for 22 years now
I mean you can evade it if you knew what you were doing...
I had no idea what I was doing back then ๐
whats the importance of using screenshot tools in bug bounty, and can it make a big difference in recon on a website?
In reference to recon specifically and I assume youโre talking about something like gowitness it can be used alongside other tools like amass as httprobe and dirbuster to quickly identify anything of interest
Apparently if you search for Victor Gevers in China, you can't find his name
You still do mate, bug bounty is very specific with very specific restrictions and scopes and a majority of companies donโt have a bug bounty program
Do bug bounty hunters use OWASP ZAP to find XSS ? or do they prefer it doing manually ?
It's all different really, some prefer to use Burp, ZAP and/or other tools or some might prefer to do it manually
I see, thanks
Hey has anyone used zseano's website: Bugbountyhunter.com, to learn and get some hands-on practice?
zap will get our ip banned
oh tk โค๏ธ
anyone here has ever found a bug?
yes
thats amazgin
amazing
then you guys clearly can answer this right?
what should i learn to have the slightest change of finding a bug?
and gimme a link for bug bounties plz
Learn web hacking
can you be a little big more especific?
@sly tulip I'm just starting out too but try reading "Real World Bug Hunting" by Peter Yaworski
tahnks
thanks*
Very good book will most likely finish it tonight
thank you
Anyone has any good resources to learn android hacking? Except the owasp top 10?
Im interested in android bug bounties but all im doing now is learning java
Idk what else i should be learning
kotlin
hii
Hey
what's up
Do you have a question about bug bounties?
Sometimes yes
i also want to but i am confuse when to start or am i ready for it
This is a good start Nahamsec updated this yesterday during his stream
thanks man
@still jasper Now I know where I saw your profile before Lol ๐ thanks for your help
Nahamsec ๐ I subscribed to your stream yesterday
@still jasper Hell yeah!! Thanks! ๐
Naham I'm gonna give you pin powers in this chat, have fun from there lol
@quaint bronze 
Is it worth going through a targets acquisitions, even though the domain name isnt the same, is it still in the same scope as the target? if all that made sense.
because im seeing some other people do it
make sure you read the scope, if you have questions on it reach out to the company posting the bounty
@golden wigeon alot of people have acquisitions in their methodolgy such as Jason Haddix but it can depend on scope some are strict some are pretty lax.
Nahamsec ๐ I subscribed to your stream yesterday
@still jasper yes me too
Hey @tawdry horizon if you would like to i would be extremly thankful for any tips on how to begin with bugbounty ๐ just hmu if you want to ๐
Why not look at some of his videos where he specifically gives tips? if you wanted to ask something more specific that would make sense but you asked him a generic question that he has already answered multiple times
To think I came to ask how to get started and I see this haha.
Thanks for the link.
And of course thanks to @tawdry horizon for putting it together.
(As a general rule, for the record, it's probably not the best idea to ping the big names just because you share a server. Some are fine with it, and they'll make that clear ๐)
hi, guys i want some binary exploit challenges for beginner/intermediate if you can give me
@tiny briar there are some resources pinned in #resources
@vocal folio thanks, didn't see that, sorry
is there any good domain ip address finder tools? i know ANS is one
nvm i think amass just gave some
I really want to earn 10k finding a RCE lol
Haha good luck dood
as long as it's not important, spoofing and ends up paying way less
If youโre gonna only try and chase money you wonโt get far
Works for the top 8 millionaires over at HackerOne. Nothing wrong doing Bug Hunting for money whatsoever. You dont have to do everything free.
yeah but often you don't get what you deserve
Yes thatโs the 1%, never said there was anything wrong but doing bug bounties for money is what causes downfall in hunting for bugs
Haha ok dood let me know when you become a millionaire
I dont know, I seen a reward for 10k earlier and thought nice.
More like .01%
Ok go ahead and try to get it and then lmk
Will do
Iโm not trying to crush your dreams but the people getting these large bounties work for days and have been doing this forever
Even the millionaires will say donโt chase money
Itโs not a get rich quick scheme
Mate I'm not being serious Haha I threw a lol on the end. Chill
Your both thinking too much into this.. chill out
it definitely didnโt seem as though you were joking and I donโt want you to have heightened expectations
I mean you just added something pointless to this chat then if youโre joking
๐ด๐ด
You say you were joking but then decided to say it worked for the top people donโt seem like a joke
I was answering your question about chasing money. #ImOut
โ๏ธ
A website I am bug hunting on has their HappAxis2.jsp open publicly with so much info, anyone knows if there is anything interesting to look for in there?
It has a lot of information about the machine
Any services and versions
you could also just submit it as a finding
But save the info first
yeah already saved it as soon as i got it
Services page and the admin page are deleted or changed
Guess ill just submit this for now
any smaller bug bounty websites other than hackerone? I feel out of my league.
lol
nm just scrolled up
You have other websites like bugcrowd and Intrigi
Looking for companies with responsible disclosure that isnโt listed on big bounty sites can be a strategy
guyssssssssss
What
lol sorry i thought i was in that server
@prisma axle that's why I was looking around. I feel like I could look at smaller businesses. I'm not going to bug bounty all the crypto projects or mobile apps.
Do the H101 CTFโs get invited to a private program that way thereโs less competition
Hmmm
After spending 4 hours to find a bug, I got to know that the page was out of scope. My bad
๐๐๐ I got know that after submitting.
Xss
hello
adb install UnCrackable-Level4.apk
do you know use genymotion
i can't execte app
how to running?
That looks like a challenge rather than a bug bounty related thing @thick lotus
yes
This is the bug bounty channel.
hello anyone hacking for vector
xss/html injection
I am hacking on a target. I can really use some help. I need some gentle hints.
Can you give more information and context so we can help @dense sigil
Hey.. Attached the image for reference.
Anything I put in search box It is encoded once.
Have you considered that it might not be vulnerable to XSS?
Yes. Thought of this hypothesis.
Maybe.
I will be okey once I validate this.
I want to validate this. I am trying harder.
What's in the source code?
It's much easier to prove by contradiction than it is to prove by exhaustion
I'd suspect it's just put in exactly what you entered
Eg it's much easier to prove that it is vulnerable than it is to prove that it most definitely isn't vulnerable
And I suspect that it will encode < and > if you enter those manually
Meaning the only way you're getting XSS is if you're entering attributes for an element that's already there
Show us the source code for the 0 results found... part?
And without encoding the search string?
yeah.. I tried to encode the input once. It again.. it gave encoed output. .
I am unable to get screenshot of the same.. because strangly.. whenever I give these kind of inputs.. It takes forever to load.. and sometimes 504 Gateway Time-out
Try different encodings for the < and >. Try double encoding, Try just putting a " or ' and checking the source to see if it breaks(This one got me a recent BB on thm). Just because < and > don't work, doesn't mean it isn't vulnerable.
yes. I will try that.
The OWASP site has a fair bit of information on filter evasion too.
as does payloadallthethings
hey thanks. I will try this.
Hey, anybody mind mentoring me on bug bounty-ing? Been meaning to get into it, but don't know where to start
This is a good start
BugBountyHunter is a platform created by zseano designed to help you learn all about web application vulnerabilities and how get involved in bug bounties & begin participating from the comfort of your own home.
hi
Hey
ฤฑ want to get in to bug bounty , ฤฑ' m solving web rooms but something is not right
ฤฑ need to learn how web works, whats going on behind, but ฤฑ dont know where to start
how should ฤฑ study
I would recommend checking out YouTubers such as Nahamsec, STOK, LiveOverflow, The XSS Rat and check the link up above
thank you
@honest cave check out https://github.com/nahamsec/Resources-for-Beginner-Bug-Bounty-Hunters
I pout this together to help people get started
there'll be an update going out soon ๐
But the update will also bring sad news "Will not be maintained" ๐ญ
@sudden dragon only some pages. I think eventually Iโd have to restructure it
Thatโs a fair point. Looking forward to the pushed update nonetheless, added a few blogs to my rss you showed on stream.

Please redirect me if this is the wrong place, but could I report a potential issue with a room and the provided instructions?
Please disregard, I found the room bugs chat.
Anyone familiar with avastโs bug bounty program here? Iโm fastening my first ever bug report on a recent and unexpected finding. Currently moving into assessment phase at the moment. Wanted to know if there were any success stories from here for this sort of work beforehand.
"Sort of work" - as in bug bounties or specifically related to anti-virus*
Specific to avastโs program. I found their public web portal for bug bounties very approachable. I wanted to see if anyone here has worked with them previously to some degree of success.
and btw anyone knows if when you are doing it (bug bounty) do you need to be stealthy or you can be "loud"?
ok
Some programs prefer you to do it manually than to rather use automated tools but you can use automated tools
Just donโt make it where it will end up causing a lot of traffic for the site
most companies hate using automated tools because they cause needless alerts
just use them sparringly
thank you
Hello i am new in hacking and i am interested in bug bounty and i don't know where and how to start :)
in tryhack me i found this server
any advice for me ๐
Iโd say check pins for the resource from Naham sec
you can refer to this
it would help full to you as newcomer
is there a discord group for bug bounty discussion or group for discussing strategies ?
Especially, beginners.
This channel ๐
Hey guys, I'm new to the cyber security field(moving from development sector) and I try do my best regarding knowledge and understanding of things, I watch a lot of tutorials, I try with the THM rooms and I do my research for anything new I see. So if any of you has a place in a team for me, please send me a DM, I'd love to find company for bug bounty and learning as it gets things more fun and enjoyable.
what the useful plugins for burp pro for bug bounty?
If you look at the pins Nahamsec has a beginner repo and it has burp extensions on there I would recommend checking them out
@still jasper I heard there is a good paid vulnerability scanning burp extension available?
Hey people :)
After I put in "autofocus onfocus="alert() it looks like this in the inspector
<input id=" bla" type="bla" value="" autofocus onfocus="alert() " >
but it's not working.
Any ideas?
Can I not escape the double quotes or what is happening?
Help appreciated :)
Are there good resources where I can catch up on this and deepen my understanding?
Hello everyone,
I found a website without SPF record but to report that they mentioned that you need to give a poc of mail landing in inbox. But to send emails when I use online free tools they land in spams. Anything that you guys can suggest to send mail so that it don't land in spam.
Hello, I am a beginner in bug bounties and looking for a partner to collab and do bounties. If someone is interested, message me.
@potent gorge im up for it but im also a beginner
hey guys i wanna start in bug bounty and i have a question i wanna start bug bounty as a hobby that will also make me money but idk how much i will get paid for bug bounty or if even i will be getting paid
anyone here whos done bug bounty for a while can you help?
I've not done any Bug Bounties, but I know enough to know that it's a pretty tough industry to make a living from. You'd need to find the available bounties on a bug bounty website - You can't just start hacking and hope you get paid.
As for how much.. The company offering it will have it's own requirements, parameters and reward structure.
ik thats its pretty tough thats why i was asking if anyone with experience could help me out
but tbh i dont even know i really wanna start but at the same time i wanna stick with what im doing now
Any paths on THM reccomended which can help our journey in Bug bounty?
The web path
thanks @still jasper .. is this one?
Level 4 - Web
OWASP top 10 https://tryhackme.com/room/owasptop10
Inclusion https://tryhackme.com/room/inclusion
Injection https://tryhackme.com/room/injection
Vulnversity https://tryhackme.com/room/vulnversity
Basic Pentesting https://tryhackme.com/room/basicpentestingjt
Juiceshop https://tryhackme.com/room/owaspjuiceshop
Ignite https://tryhackme.com/room/ignite
Overpass https://tryhackme.com/room/overpass
Year of the Rabbit https://tryhackme.com/room/yearoftherabbit
DevelPy https://tryhackme.com/room/bsidesgtdevelpy
Jack of all trades https://tryhackme.com/room/jackofalltrades
Bolt https://tryhackme.com/room/bolt
Learn about and exploit each of the OWASP Top 10 vulnerabilities; the 10 most critical web security risks.
Walkthrough of OS Command Injection. Demonstrate OS Command Injection and explain how to prevent it on your servers
Yep those are the ones
Does anyone have a suggestion which target I should choose? I want to find my first bug and feel like I am lost in the ocean, because of the huge number of programs on hackerone. Thanks for the help (btw: any bugs I can focus on? something "easy" to find? I am not expecting to find a critical bug, I just want to find my first one)!
The most common bug you're most likely going to find is XSS
These are the most common vulns
haha
this are the MOST impactful and rewarded that doesnโt mean that you will always find them as other hunters have picked a lot of the big bounties raw
either go for smaller targets with those vulns or go for the bigger targets with lesser known or more specific vulns
Does anybody know a way through which I can find how much money a certain CVE has earned the researcher that discovered it?
+1
would also love to know this
Search on the CVE number for articles mentioning it. Many don't have that information publicly mentioned, for various reasons.
Hello
Hello everyone I test xss in site my payload is printing here , is there any bypass
i don't know I used this payload I saw in payload all things
Do you know HTML and JS?
How can i use in this case
a little bit
I recommend getting some more experience before try to do XSS
Because I don't think you understand what's quite clearly wrong with your payload there
yeah you mean my payload Not closed
@manic mango Before firing any payload for xss try the simple <h1>Hello</h1> and if it works then proceeds with <script> or others.
Christmas crisis if i edit cookies in firefox i got 302 but burp can run why๏ผ
Hey bro! You can start in this website: https://hackerone.com/bug-bounty-programs
Discover the most exhaustive list of known Bug Bounty Programs. Start a private or public vulnerability coordination and bug bounty program with access to the most talented ethical hackers in the world with HackerOne.
For advent of cyber2? #778305825797177374
hmm i wanna join bug bounty too but i am beginner
have you started researching? there are at least a thousand guides online on how to get started?
yeah like joining some platforms
Hello people
Do you know if a post form is exploitable when there is a CSRF Token in the header?
I came across it yesterday and you can just replace the token with another valid one but I wonder if you can do anything with it.
Hey, thanks for the answer.
I can exploit it using burp and then just swapping the token because it is not tied to the user session.
But how do you exploit this in reality? You cannot just change the header info, can you?
You know of any good resources where I can read up on that topic?
@summer crown 'exploit it' what are the trying to do with it?
Like using one user account to change password or email of other
If you get blocked by your ISP by performing a legal (underscore LEGAL) pentast, just contact them and explain the situation
Although it's not very likely to happen
Can someone tell me how you would avoid legal issues with sites like these? https://www.24sessions.com/responsible-disclosure
At 24sessions, the security of our systems is a top priority. Learn how to help us in case you do discover a security vulnerability.
Seems way too hard to not fall in some trap while testing their site.
Perhaps I am wrong?
I suggest sticking to known bug bounty programs with safe harbor until youโre more comfortable
disclose.io is a collaborative and vendor-agnostic project to standardize best practices around safe harbor for good-faith security research.
You can also check out this to help identify best practices
@azure gulch Sorry for ping,
Remember this bug? Adding yourself as friend. I've found same on a bb website, just confused should I report this or not!
If yes, Idk what prob the impact would be! Thanks!
Ps: Again sorry for pinging you!
@obtuse rock #thm-community-media if it's an approved writeup.
Hey.. This doesn't look like security bug.
I will suggest to look around for critical bugs.. Think about how it impact CIA triad.
Exactly, Was thinking of the same. Thanks man!๐
1.) donโt ping admins please unless needed
2.) skidys away
3.) this channel is for general discussion of bug bounty
4.) thatโs just a bug with no real impact
5.) the team is aware
Alrightttt, Gotchaaa!
hello guys iv ben working on a program and i have encountered an adf page is it worth to put time on it?
and if yes what can i do exactly im fairly new
Every time i connect to host: nc -vvv host.local i get different DNS information: DNS fwd/rev mismatch: host.local != dns.another.local \n host.local [192.168.x.x] 80 (http) open IP is same but i get different DNS. Is it some kind of load balancing?
@fallen palm Please respect rule 9, this seems highly unethical
Oh. Didn't know that, thanks for letting me know !
hello guys
Do I need to learn the full javascript language for bug bounty?
No it's not needed but it's nice to understand how to read code from JS and how it works
Hi,
Iโve got a deserialization bug on an aspx website that server is based on plesk
I cant use powershell. I can just send cmd commands using deserialization bug and see the response in dns requests.
The target owner wants a understandable poc like creating txt file or etc.
I cant enumerate c:\inetpub in the server to find the proper place to create a file or make a poc.
Is there any segustions?!
A method to enumerate folders and find place for poc?
Or an other type of poc that is understandable for simple user?!
Or anything else?!
I appreciate your help
What bug bounty platform is the target listed on?
to bypass cloudflare you are very likely to look at a 0day. however you might want to use shodan to find the website's real ip if it is hidden somewhere
@prisma axle ^^ is that something Shodan can do?
maybeeee?
Here @merry plume
There are a few ways. Like checking the name of the favicon or the hash value of it
see suppose you are doing a penetration test against a site (full permission)
you use any tool (like ZAP) and showed them reports
will they accept it ?
Running Zap and showing ppl reports is not a pentest.
it's not even bug hunting.
it's not even compliance verification
IIRC anything zap picks up will be incredibly low hanging fruit
it depends on the plugins you use too
I think that applies to all automated scanning really
If you're even allowed automated scanning
I'm also wondering if there is a reliable way to know which plugins a certain website is using? I was looking at old reports on hackerone (this one https://hackerone.com/reports/365271 ) and found this report which was awarded a lot of money for a vulnerability in a plugin the website was using. I couldn't find any good tool tho or is that impossible without having the source code?
A critical flaw in Basecamp's profile image upload function leads to remote command execution. Images are converted on the server side, but not only image files but also PostScript/EPS files are accepted (if renamed to .gif). This is probably due to ImageMagick / GraphicsMagick being used for image conversion, which calls a PostScript interprete...
my best try at it was to use wappalyzer extension for the browser which looks reliable from the few tests i used. It tells us the backend and the frontend languages/frameworks. Then see which functionalities the website offer (like datetime handeling and image related functionality) and see which plugins are most commonly used to get these functionalities using the technologies that the website uses. Then look for CVE's for those.
Is there any way to exploit GraphQL with introspection disabled?
Why not, if you know or can guess the schema
Take a look at what calls are issues on that graphQL service from the application. Sometimes you might have some interesting queries that you may want to check if you can get information disclosure out of.
without introspection you kind of end up relying on a bit of recon and proxying calls to figure out the schema / queries.
if the graphQL does provide information on your user, try and see if it has IDORs that let you access other users information
Hello can any one please tell hoe to test xss when you find these type of results :
I have walked through many sites like this , payload reflects on the page but i dosent fires, what the reason behind this.
the input is probably filtered so it isn't an actual tag
Did you try closing strong tag ? @low dagger
Yup it only reflects same like this one
If anyone has done the SSRF with whitelist based input in port swigger web academy, then pls dm me, I have a doubt
Or just tell me how does the # in urls actually work, like yea ik it works as an anchor and if the web app doesn't support it then the contents after # are just ignored but say I am embedding username#@url/somepage then it goes to username/somepage, but username/somepage@#url doesn't work, pls explain why
@paper night thats a lab specific question.That lab support embedded cred. Like username@stock.shop.org (eg.) ,,also it rejects # so u need to double encode it so it perform search query on that username (u can use localhost there) and then access /somepage.
The later one wont work bz there # is acting as query terminator for username so query will block username/somepage direct but can access by username#@domain/somepage (follows embedded cred format)
oh i c, can u refer me to the rfc?
If I have found a bug in some organization and they have validated that but not fixed yet can I share my findings without making the asset and vulnerability visible?
Depends on your contract
Okay thanks @lavish hollow
i want to inject sql injection in a website which is protect by cloudflare i inject all basic sql injection but i can not bypass so what should i do?
Generally speaking, while there are WAF bypasses it's not traditionally worthwhile to try to evade them
Thatโs a lot of injection
Especially cloudflare, a cloudflare waf bypass is gonna be super notable
Could try to find the actual IP behind cloudflare
I am a beginner in bug bounty could anyone pls guide me the right study material to be studied (for free) and the rooms which are available in tryhackme answers are welcome thanks in advance...
+1
Web fundamentals
Uhh
I don't think I can get a room list because it's a subscriber path
But look for things that are web-related
anyone wanna collab doing hands on bug bounty and learning (beginner)
if theres someone dm me
i'm noob....
Hi noob, I'm dad
hi dad, i'm noob

hello
Hey
!docs verify
idk where to start in bug bounty can someone pls guide me ๐
Check the pinned messages
hi every one
Hiii
umm... i have the basic-est basic question.
HOW DA HECK I CHOOSE AN ENGAGEMENT?
you mean a program?
welllllllllllll... choose one you understand the scope and allows you enough things to poke. Then enumerate a bit and see if it interests you.
H1 and bugcrowd should have plenty for you to search around...
stay away from programs that have bad reptutations of closing bugs without explanations or not replying forever
if they have disclosed reports, take a look at the kind of reports that have been disclosed and figure out if their tech matches your skillset (or use shodan for that)
the list goes on, but go through a bunch of targets that have programs with RoE that you are willing to accept.
hello tell me
Just ask, someone will help you when they can
ya anon_me
just ask. ask ask. ask away
(Good luck, they got yeeted)
does h1 require a lot of knowledge or a beginner is able to start picking some programs?
I would watch their videos first so you get an understanding
Then do the H101 CTF's and get invited into private programs
Also dont forget to do H101 grinch ctf its pretty good
where can I find it?
I loved the THM advent
It will be moved to h101 soon but for now u can try rest h101 ctf
I will try then ๐
When we fuzz all the endpoints in target tab in burp it sends a lot of requests so can this crash a site or lead to DoS?
Hey guys
So recently I found a bug in web app where the same pin is given to a user if he does forget password, I triedmultiple times from a browser, then it's incognito then a different device with same external IP and then a different device with different external IP and all times I get the same pin for forgot pw so what can be the impact here
M writing a report to the firm but I cant think of an impact of this bug
Does it change once you actually reset it? It might be cacheing it for performance reasons until it's actually used
@ionic prism yea it does, but shouldnt it give different new arbitrary codes whenever the user does reset pw, and then terminate those previous unused pins?
The PIN should definitely expire eventually, though I could understand if they just re-send the same PIN if you try to do a reset within the window of time before it has expired? ๐ค That could help prevent a UX problem like clicking the submit form button twice and then getting two codes and not being sure which one to enter
That said, if it's been a few hours/days/etc and the PIN hasn't changed, that's a cause for concern because it should expire
the thing u say makes sense for the same external IP but i tried with different external IP's but it gives the same PIN
Just to clarify, since I realized I made some assumptions: is the password reset flow something like:
- Enter Username (or Email) on password reset form
- Email with PIN and link is sent to account owner
- Account owner has to follow the link, enter the PIN, and then enter a new password
- Account owner is shown the login screen and has to log in again
Or is it different from that?
I should also say, in the name of transparency: I'm a newbie with security stuff, though I've been an application developer for the better part of a decade. So, I'm not necessarily an expert on this even though I have had to work with stuff like authentication in the past and have read up on best practices ๐
different
its like
- Enter registered email of the account
- Code sent to email
- Enter Code from email
- Change pw
- Login again
Iโm going to tell you right now that theyโre probably just going to reject it unless you can find some kind of PoC or exploit to show impact
-undelete -a
Up to 10 last deleted messages (last hour or 12 hours for premium):
43 seconds ago (Sat Jan 9 18:50:39 2021) Raman_MG#8864: Hi
@daring rune Hi
Hi chat
I found endpoint in subdomain which allow me to upload pics
Want to make asp.net shell ? Any idea ?
@last elm there are plenty of resources online for how to make any kind of shell
also just because you can upload pics to an endpoint doesnt mean anything
does it have filters? client-side or server-side? does it allow you a way to execute those files / view them? do they have a WAF?
Its typically not as easy as just oh I can upload pictures
I got you
Thx buddy ๐ช๐
Hi Everyone any best book for bug hunting. 
Using burp suite scanning found a Reflected XSS. But browsing the vulnerable URL does not reflect anything.
I opened the chromium with disabling protection chromium --disable-web-security
The browser maybe filtering the request ... right?
Are you also sure it's a security bug?
It is a cross bug or something, i dont know the names ()
It is in Google drive with google classroom
With the permission access type error
IDK what to say... ๐ฆ
Ok and how is that a security bug?
I found a Try Hack Me bug
What to do next?
!docs bug-bounty
Read this link ^^
Ok thanks
Just make sure, it's a security bug.
Yaps, that's right.
I thought I found a security bug in Facebook, but it appears facebook let the passwords don't be exact at all (skipping some letters, mayus, numbers) lol
This may not be the right platform to ask but can some recommend web exploitation resources that I might be helpful to a beginner?
Ps- I'm clueless about it. A bit familiar with burp and wireshark
I'm trying to explore bug hunting
Check out OWASP and portswigger
Sweet. Thanks
i have a doubt regarding subdomain takeover can anyone help me clearing this out...
I have seen reports for "subdomain.example.com" this type of subdomains in hackerone and other bug bounty platforms and know that this is eligible but if there is "subd.subdom.subdomain.example.com" this type of domain which an attacker can takeover..is also counted in subdomain takeover attack ?
When TryHackMe reply my email report?
It depends when one of the staff are online and are doing the emails
spaghetti aglio e olio, and some spicy sausage for dinner.. yum
unibic can you explain to me what a subdomain takeover is ?
so if you have a nameserver for the zone *.zone.example.com and achieve access, then you can create as many subdomains as you wish
Any idea how to bypass waf lol ๐
you want us to check whether this is a legit bug?
you know if it is, someones gonna steal it and claim the money right?
i would highly suggest deleting your bug and doing your own research ๐
@terse moat Have you had permission to do that
Please note that responsible disclosure means you should be responsible about disclosing things.....
follow program guidelines at all times
you can get in trouble otherwise ๐
can anybody recommend a guide for getting started with API testing, for somebody who already tests web? basically want to get up to speed on API-specific tools, bugs to look for, etc. will move this to the resources channel actually, probably a better place
Yes, a subdomain can be split into several words, so don't worry about that. BTW also www.mysite.com is considered a subdomain. The question is if there's an actual possibility to take over the subdomain (here is a good place to read more about that: https://0xpatrik.com)
It's basically a misconfiguration vulnerability caused by a CNAME entry which points to an external service which is no longer there (and so can be taken over by an attacker).
For example, if you find a subdomain which used an S3 website bucket to show its content and used a CNAME to show that content within the site context as a subdomain (thus showing the subdomain URL and not the bucket URL), you could possibly claim that bucket name if it no longer exists. This would allow you to de facto control that subdomain.
So roughly this would mean first enumerating a web site's subdomain and then testing for the possibility of takeovers via an HTTP request (there are several basic tools that can you help with this). This 2nd step depends roughly on (a) understanding if there's a CNAME entry behind that subdomain's DNS (which can be generally tested using the terminal command 'dig A subdomain.website.com' and looking for a CNAME entry to an external service) and (b) reviewing the HTTP response from the subdomain/service to check for a possible response text that could indicate an unclaimed service (e.g. in Amazon this would be 'The specified bucket does not exist').
Here's a good place to start reading about this vulnerability: https://github.com/EdOverflow/can-i-take-over-xyz.
I can't begin to comprehend how things like this exist when the service is no longer maintained... That level of abandonment should be criminal
It's actually one of those misconfiguration vulnerabilities, like internet-open DB ports, that are potentially very risky (e.g. cookie theft might be possible if the subdomain is in the site's cookie scope) and relatively quite common and easy to exploit :/
I just mean that if I set up a service, and send it to a landing page somewhere.. then decide to stop using that service, then i should probably pull the record out of the zone file... It seems common sense. poor sysadmin work
Then .. much too often the vulnerabilities are just that, capitalizing on the product of lazy admins.
Hello...
When TryHackMe staff response my email report? Now 3+ Days my email has not received a reply
Please be patient they will answer it when they can. If they do not respond in 7 days, send a follow up email.
Okay thanks for the information
Hi. I need some help. While testing a web app, I found they're using a load balancer or some reverse proxy. So I focussed on Host header. Adding my Burp Collab on Host header gets me a DNS request in my Collab. But the response is a 503...
I tried some private IPs ranges but getting 503 only.
Any recommendations I can try which I missed?
Any one here I can ask about anti csrf bypass? I am running through burp with macro fetching the csrf token and changing the token for every new request, it works however I when I run the request with intruder with the dictionary provided and still no success. It is a lab so I donโt think brute forcing should take longer than 15min? I must be missing something.
Hello, I want to ask that , Is it okey to use metasploit in bug bounty ? For example let suppos someone has found an old version of Apache running is he/she allowed to exploit that using msf payloads or he /she has to just report that update server software to new version. (Thanks)
I think it depends on the situation. Are you asking whether to hack it or to report it?
Hello fellow bug hunters ๐
New here. I'm not entirely new to cyber and coding etc. But 0% into bug bounties. I suspect that's exactly what I am wired to do, so I'm here, diving into this world ๐ค
Yes, should I just report it or exploit it and then send the poc
Hello I want to ask that why companies don't pay for rate limiting vulnerabilities in there authentication mechanism.
They are like we know are aware of this thank you sir
At the end of the day, it's their program.
Guys, need help to bypass Authorization
any ideas?
Hey so question, for bug hunting, is it a good idea to report miscellaneous bugs found that aren't in scope but helpful for the company along the way?
Depends on the company @still scarab
If itโs not in the contract I would avoid going there. If you accidentally break something and you were not supposed to be there youโll be in a lot of trouble.
If it isnt in scope dont waste time there simple rather than focus on asset in scope so ur effort is rewarded if u submit a valid bug.
Hey, i found something on a site, I wanna make sure if it should be considered bug or not before reporting.
If we do curl to example.com/ , it shows 400 request along with awselb/2.0
Which isn't visible otherwise
@tall slate what is the impact of the bug matters.
It's like information disclosure. I tried to do some research on awselb 2.0 but didn't find much
I read that thread
It might not be reported on example.com
As per the thread
It seems to be information disclosure
If you show what's disclosed and can prove the impact then I guess you could report it
Isn't the server and it's version disclosed?
Actually it's only the 2nd bug I found so confirming
Not someone who knows how to write good reports haha
Reported.
@still jasper it got accepted as informative
good job!
hi guys I want to ask, is it possible to trigger xss inside html tags meta? I found a parameter where the value or data input will be returned to the attribute meta tag content="Here" but I don't know how to trigger it, I have done many event handlers but the results are not there
I believe that's because it's very limited to browsers. It's practically useless, but for testing purposes, I believe it only works in Safari. Don't take my word for it though
Finding your first in scope bug in a real world setting feels amazing :D
I'm just wondering how they'll respond to it next, lol
should you be using a vps for everything from recon to testing? just learned about akamai.
congrats! how long have you been bug hunting in general?
Bug Bounty tools:
https://youtu.be/ZTZdsoCWMrQ
new premium user on tryhackme , trying to learn bugbounty ๐ , would appreciate room recommendations
Web Hacking Fundamentals: https://tryhackme.com/module/web-hacking-1
In this module, we'll be exploring the basic components of the modern web including both the basic protocols used, as well as various server components that make up the world wide web. You'll be diving into how to use BurpSuite, a tool which is widely regarded to be at the heart of web hacking. Additionally, you'll learn how to perform basic enu...
yea currently using this room , ty ๐ , any other rooms to try after that?
Learning pathway Web Fundamentals: https://tryhackme.com/path/outline/web
thank you ๐
i heard that aws no longer allows security testing. can you/anyone elaborate on the topic a bit?
you can pentest your own machines
you cannot use it to pentest others
you can attack your OS
you cannot attack the lcoud
im referencing bug-bounty specifically and i've had a number of people explain akamai will ban your ip if you don't use a vps. Also, the book Real World Bug Hunting mentions this as well...
idk what those books say, but I passed an AWS cert about ~10 days ago and I had to study specifically what AWS does & doesnt allow with pentesting
You cannot attack others with AWS, that is 100% against their ToS. You can attack your own software on your own AWS instances ๐
If you are being attacked by an AWS instance, contact their security team who will destroy the attackers
not concerned with aws specifically because i already know they don't allow testing and there are a number of others that do.
just asking if vps is a must for bug bounty recon/testing, because i've been gathering from multiple sources its neccesary.
can you answer this? :))
XSS is very very very good at bug bounties, far better than I am ๐
Thanks, I didn't know he was on this server! I follow him on youtube.
He also did an AMA on the reddit about bug bounties ๐
THM reddit?
Found it. Sweet AMA, but no mention of VPS tho haha
That section is a gold-mine
Hey @robust crescent it depends ๐ the only thing really required for bug bounties is a browser imo but if you want to do recon or make a reverse shell back to somewhere a VPS sure is handy ๐ค it can also be used for any out of band testing that you need to.
Sorry for the shameless self promo but maybe this helps as well https://youtu.be/xOMLqIN7gfc
Virtual private servers are very useful in bug bounty's, let's explore some use cases and go over which VPN to get.
Affiliate link will follow: https://www.linode.com/
You can now Buy me a block of cheese:
https://www.buymeacoffee.com/thexssrat
Patreon:
https://www.patreon.com/TheXSSRat
Instagram:
thexssrat
Follow me on twitter to be notifi...
@merry plume What are the rules for notifying AWS that a pentest of your own resources is going to occur? Can you do an external pentest, or does it have to originate within the VPC?
Thanks so much for the response, UNC! Keep pumping on the awesome youtube content! Definitely feeling closer to feeling comfy with the concept. Definitely plan on doing recon in the future. On that note, am I pretty much totally good as long as i stay within scope and use a VPS?
Of your own resources? None so long as you're pentesting the security of the cloud. You can externally pentest iirc
Some programs require you to keep it low and slow on the automatic tools, always read the scope page ๐ค I tend to keep my requests to 1req/sec if the target says โno automatic scanningโ. That being said, recon does not tax your target perse if you are for example doing subdomain recon by waybackmachine
yeah, we needed to submit a PenTest plan to Amazon few years ago. but the rule has now been abolished.
https://aws.amazon.com/security/penetration-testing/
Since we're on this AWS topic, do you guys know if it is legal to set-up an EC2 instance to proxy my traffic while performing recon?
why would it be illegal lol
I mean not a lot of reason for it if youโre being chill in your recon or use a vpn
A good question for Amazon. Legal conditions change all the time. Best to get it from the horse's mouth, so to speak. ๐
Hey all, yeah I'm very interested in getting into bug bounties but I'm afraid I will just be wasting my time since I know most bounty hunters searching are more knowledgeable than me and have had time to exploit. Any suggestions? How hard is it?
Don't expect to make money from it
That's what I thought
I make tiny bits of money doing qmee surveys and playing games on mistplay
I expected it might be harder to find funds out if bounties
*of
Private programs are better, but you're not likely to get rich off it. Depending where you are and the cost of living, it might pay for stuff tho
Please don't post the same thing in multiple channels. The other two have been deleted.
As has this one because it's in the wrong place and it's been posted a good 20 times
@fossil sail Specifically, Rule 3.
oh i apologize thank you!
You should also verify, after reading the rules
Hey everyone!
I found open-redirect on a website's reset-password page, I can change the Host to atacker.com & it will redirect there + email which user will receive will contain attacker.com/user/token.
Now, I want to take a video of this & send it to the security team, but can anyone help me out on how can I capture cookies in my terminal, or from 000webhost?
When I insert Host:<attacker.com>, the user gets redirect to https://attacker.com/user page. So, I am a bit confused on how to capture cookies & show them on my terminal.
A reply would be greatly appreciated.
Are you able to do the attack through burp? It'd also might be easier for them to see and replicate. It'd also show cookies etc
Why when we do a command injection we use two pipe symbols and not one?
email=||whoami>/var/www/images/output.txt
and for example email=x||ping+-c+10+127.0.0.1
One | is for piping output of first command to second. On other hand, || means OR, i.e 2nd command will execute if 1 st one gives error.
Plz correct me if wrong xd
& - run in background
&& - execute 2nd after 1st execution finish
| - pipe 1st output to 2nd as input
|| - execute 2nd if 1st gives error
oh i see because this was the challenge i had to solve was.
Use Burp Suite to intercept and modify the request that submits feedback. Modify the email parameter, changing it to: email=||whoami>/var/www/images/output.txt||
Now use Burp Suite to intercept and modify the request that loads an image of a product.
Modify the filename parameter, changing the value to the name of the file you specified for the output of the injected command: filename=output.txt
Observe that the response contains the output from the injected command.
So im assuming we are piping "whoami" to the email command then piping it to /var/www/images/output.txt so we can read it?
> is used to redirect the output
Like
whoami> a.txt
This will create a file a.txt containing output of whoami
Yes
Im just curious about the pipe at the end of the command.
What are we piping that to?
Are we piping it to /output.txt?
Yep I am able to attack through Burp, that's how I intercept the request.
how do i get into bug bounty?
what shd i focus on
and where can i learn
learn and practice
โค๏ธ
hello
hey
what do you mean?
on tryhackme are you in the hacker one bug bounty room
Oh yea
What do you need help with?
the second question
Is that even released?
The room got accepted today
Where else do you need to submit flags to in-order to win prizes and private bug-bounty invites?
It's not out yet
thats the question
Accepted, or released?
If you read it it says 20th feb
Because if it's not released, don't ask for help please
oh
It said accepted in the queue
so i cant answer the questions
No
In this module, we'll be exploring the basic components of the modern web including both the basic protocols used, as well as various server components that make up the world wide web. You'll be diving into how to use BurpSuite, a tool which is widely regarded to be at the heart of web hacking. Additionally, you'll learn how to perform basic enu...
thanks
@still jasper what should i do first (i do have premium so i can do all rooms)
Go from top to bottom
ok
Check the pinned resources
Check out Portswigger labs, pentesterLabs and OWASP
Do some H101 CTF's
is owasp zap good for vuln finding?
Yep but don't rely too much on tools because they can give you false positives
Okay thanks
hello guys, Is hacking a wordpress site only through a theme plugin? or is there something interesting? Please let me know
What do you mean by hacking here?
pentest
What are you trying to accomplish here?
RCE from the dashboard? Hack in without access to the dashboard?
I just want to know if the person here when doing the bug bounty and finding subdomains/domains using wordpress is just doing a wpscan scan to get a list
Because when I found a wordpress site, I just did a scan using wpscan
Yes you can list plugins using wpscan.
Ok nice thanks
There are more things you can do with wordpress though. And listing the plugins really isn't much of a pentest.
Apart from that what? do bruteforce to admin page? what if you find a vulnerable plugin?
sorry i don't know much about wordpress
ok i understand a little, thank you๐
Beware though, some programs are more nitpicky than others and might refuse automated scans and attacks (which includes tools like wpscan, sqlmap, and similar)
I mean I just said it's feasible
I know, I know. Just sayin' ๐
What CTF is this?
Website called leonardcyber.com

Good luck wish u the best
-warn @last elm Asking for help with interview CTFs is unethical and arguably fraudulent
โ Warned DoSec101#5909
:sus:
@ebon tapir ... yooo๐โโ๏ธ
@al have you checked the revslider exploit for wordpress yet?
Any1 here wanna collab??(bug bounty on hackerone)
Hi chat
Now i found subdomain when i open it , it redirect me to admin login page
And i typed normal username(name of the company) and pass same
And it opend with me dashboard
Should i report it and what severity ? + what name of this vuln ?
Its private BBP i test now .
As you recently asked a question relating to an interview and you're now asking something fairly straight forward, I'm going to retract my comments.
Look at the rating scale for bounties and previous bounties submitted
Look at program policy bz some program dont accept the bug of bruteforce or guess,,also try to chain this with other vuln.,look through plugins,themes see if u can get RCE,see data of other user etc,,if it does then since the impact is high ur report will be accepted
Thx for you chat โค๐ช
I already report it and they now reviewing the report
imagine if it was as simple as <h1><script>alert(document.domain);</script><h1> all the time
..... ๐
Import-Module Gib-EnterpriseAdmin.ps1
Hahaha!
hello has anyone reported bugs via openbugbounty.org?
you could try doing some nmap scans first
I'm really interested in the field but I can't seem to find any good learning material
I've no prior knowledge about it
That seems irresponsible
ok
Learn web hacking
same lol
i recommend networkchuck if u wanna get started with some hacking
!website
explore the target site, see how it works, see what you can interact with, check for any subdomains or weird api endpoints. enumeration enumeration. learn how what ur attacking works and how you can break it. lots of good web vulns to explore in the web exploitation learning path
ohhkayyy
I also recommend Portswigger labs
Portswigger labs is such a good resource and will help anyone new to web out exponentially, their site helped me master SQLi
i just did their sqli stuff and its great, i'd suggest doing the challenges where you need to use automation in python though
What is "spring.datasource.password", found it on a github of a company (bug bounty), just wanted to know what it is and if its worth reporting?
I know error and vulnerability types but I dont know where and how to find the vulnerability
You'll want to learn web hacking then
Where? Websites
How? If you know what a vulnerability is, youโll know how to find it
If you donโt know however, do the Portswigger labs and the OWASP TOP 10 room on THM
thx
Do you have any experience with TryHackMe?
Any hacking experience?
I'd suggest learning how to do this stuff first, and then maybe going into bug bounties
thx
!docs free-path
Do these challenges and you'll learn a lot
thank you so much
I can't use virtual machine because my system properties
Operating System
Windows 8.1 Pro 64-bit
CPU
Intel Pentium P6200 @ 2.13GHz 62 ยฐC
Arrandale 32nm Technology
RAM
3,00GB Dual-Channel DDR3 @ 532MHz (7-7-7-20)
Motherboard
Hewlett-Packard 1413 (CPU 1) 62 ยฐC
Graphics
Generic PnP Monitor (1366x768@60Hz)
Intel HD Graphics (HP)
Storage
465GB Hitachi HTS547550A9E384 (SATA ) 33 ยฐC
I have 3gb ram
like a joke
yeah it's not too much, you should buy a Raspberry PI and install Kali there or get more ram, or a new computer
@bronze mulch u can use liveboot
I have i3 2nd gen, with 2 gig ram. So i used to use liveboot
It will get job done
how
thx
some titles for premiums
no, these titles are free
but you can buy VIP if you want
What's wrong with the room?
.
It is free...
I cant see video
But everything is explained
Videos are subscriber only, not the rooms.
okey
okey
Great
@hybrid orchid
Banned
Hi guys,
I'm new on this, want to start a career on bug bounty's, but don't know where or how to start...
Check the pinned resources, do the web stuff on TryHackMe and Portswigger labs
I'll just throw in as Blackout mentioned really good resources. Aiming to go into bug bounty is really difficult as a beginner, the people you see doing really well have put years upon years in to make it look so easy. Most people are lucky to make $500 per month from bounties
I'd be amazed if I made $50 hahahah
Took me 1 year to get my first 2 bugs
That's still some noticeable progress
I'm not trying to scare people away from bounty but it really isn't as easy as it looks on Twitter
Thanks๐
^^ People will rely too much on tools and copy and paste payloads
The big bugs come from finding ways to bypass wafs
Finding bug bounties that aren't on hackerone etc too is a good way to find programs where all the low hanging fruit hasn't gone.
truth be told there's plenty of bugs on public programs on h1
people just get stuck in the mindset of "My payload from payload all the things didn't work, nothing here"
or rely too heavily on scanners
true true
I did something
at least the free ones
and how can ฤฑ try myself
about bug bounty
I have this
this is like a ctf but to use it I must know xampp but ฤฑdk xampp
There's a hosted version for you.
thx
So actually bug bounty is to search for bugs in website and web application? Do you first need permission from the creator/owner?
In web apps, mobile apps and etc
Oh mobile apps also๐ค
If it's not yours, you need permission. Just go by that rule.
There are platforms that allow you to hack on them legally as long as you follow their policy
Interesting, but how you can find bugs in mobile apps? With kali linux or with your mobile
Oh ok
By learning swift I would imagine
Yeah
with ios anyway
There are tools that allow you to take apart application etc.
So you can't search for bugs on every website
Nope
Ah ok
Only ones that have programs or you have permission
So actually I need to search for bugs via hackerone per example
Ah ok ty
If you want to then yea, hackerone has a lot of big programs on there
such as snapchat, tiktok, facebook etc
What are the possible ways to attack CMS based web application
Hi all
Hii
Hi, quick question:
In Hackerone, how can I make sure I have permission to probe and try to bug hunt? I've been shy about bug hunting because I don't think there is enough information on Hackerone about legal implications
Each program has their own policy and scope
I don't want to test agressively because of this
Thanks, I'm aware of my scope of work, but I may make noise so
Don't rely too much on tools as long as you keep in scope you'll be fine
That's that
Programs who don't want u to make noise or use automated tools will say so
Do you guys anonimize yourselves as you try things or just head on?
I have a vpn, some may use a VPS some may not use either
Not really, I use a VPS, I'll use a VPN if they automatically block me/limit me or w/e
A lot of programs will tell you if you're testing on H1 to create an account and use H1username@wearehackerone.com email
@wintry hemlock If youโre really worried about legal stuff just make sure the program has safe harbor and a clear scope and youโll be fine
Yeah, that's what's kept me on the fence
I reached out to an engineer of the company and told me it's okay as long as there's no lateral movement etc
๐๐
hey guys I am new in this chat serveur
Hey everyone, is their anyone willing to collaborate on some bounty programs with me (Hackerone)
@native token Hey brother, sorry for the bug (pun intended), but what helped you become a bug bounty hunter and start looking for bugs ? Do you have a background in cyber security or programming ?
Yo, I only really do bug bounty once in a blue moon, but background wise I work as a pentester and have done for around 6 months now ๐
Hi all! Anyone with Yogosha account here? (Collab pls I want to report a security issue on a program that use Yogosha, kindly DM me please)
Can you make decent money as a Pentester enough to where you don't need to do bug bounties??
pentesting pays really well yes, I only really do bug bounty when I'm bored, have an abundance of time on my hands or just testing a technique/tool
Define "really well " lol
Enough to pay the bills and live comfortably. Not really sure how else to define it
That's awesome, maybe I'm beating myself too much over this bug bounty stuff
I think I'm sticking with my cyber sec path
I have a really cynical view point on bug bounty, though I can be successful in it. it's a lot of effort for potentially no payout.
Not to talk crap about them but they aren't healthy for people starting out in this field as people go into it after seeing people on Twitter/Social Media posting "LOOK AT ME I MADE $$$$$ FROM BUG BOUNTY" when in reality that only happens on a very rare occasion. Bug bounty is literally going over webapps with a fine tooth comb to find what pentesters missed. If a company has a good testing team, there won't be much
That being said pentesters are also restricted on time depending on the client or scope, so it isn't uncommon for them to miss the insane and obscure stuff
Interesting point of view. There is a lot of hype on social media about this stuff. After reading your thesis I think I am safe to stick with my cyber sec path and the eventually look at bug bounty later for extra income
How long have you been learning in this field? If you don't mind me asking?
Going on for 2 years
I'd probably say don't stress trying to get into bounty though, it's not easy in the slightest and people only post the earnings on social media. They don't show the hundreds of hours that went into getting that payout
There's a big jump going from THM/HTB into bug bounty/industry to say the least
Appreciate your professional insight on this. It's perfectly clear what I should do now ๐
