BBR - Bug Bounty Resources 🧵 Profile Banner
BBR - Bug Bounty Resources 🧵 Profile
BBR - Bug Bounty Resources 🧵

@bbr_bug

4,554
Followers
24
Following
117
Media
289
Statuses

Resources | Resources | Resources

Joined November 2022
Don't wanna be here? Send us removal request.
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
Bug Bounty Report Thread 🧵 Topic : Account Takeover via Disclosed Session Cookie Report Info : had accessed a HackerOne Security Analyst’s HackerOne account. Bounty : 20,000 $ #bugbounty #infosec #bugreports Look 🧵 :👇
10
86
303
@bbr_bug
BBR - Bug Bounty Resources 🧵
6 months
bypass alert ==> [alert][0].call(this,1) #bugbounty #bugbountytips #bugbountytips
Tweet media one
Tweet media two
1
59
266
@bbr_bug
BBR - Bug Bounty Resources 🧵
6 months
If you find Web frameworks like Symfony, add '/app_dev.php/_profiler/open?file=app/config/parameters.yml' to the wordlist, and you may get juicy data. Enjoy!" #bugbountytips #bugbountytip #cybersecurity #ethicalhacking
Tweet media one
3
54
251
@bbr_bug
BBR - Bug Bounty Resources 🧵
6 months
~IDOR Worked for me 100 times
Tweet media one
1
52
232
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
Bug Bounty Reports in Threads 🧵 #bugbounty #Infosec Bug: Unique Rate limit bypass Organization : Unknown Bounty : 1800$ More : 👇
6
64
221
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
Bug Bounty Reports in Thread 🧵 Bug : GitHub For Bypassing Filtration oF HTML tags [ Part - 1 ] #bugbounty #infosec Bounty : $10000 Thread 🧵:👇
4
63
212
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
Top 25 SSRF parameters 📃 • ?dest={target} • ?redirect={target} • ?uri={target} • ?path={target} • ?continue={target} • ?url={target} • ?window={target} • ?next={target} • ?data={target} • ?reference={target} • ?site={target} #bugbounty #infosec More 👇
11
71
203
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
Bug Bounty Report in Thread 🧵 #bugbounty #Infosec Bug : Bypassing Google’s authentication to access their Internal Admin panels Organization : Google Bounty : $13,337 Check Out Thread 🧵 :👇
3
43
196
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
Bug Bounty Reports in Thread 🧵 #bugbounty #Infosec Bug : OAuth 2.0 Open Redirect Leak of authenticity_token lead to full account take over. Organisation : Twitter Bounty : $1400 Read More : 👇
5
50
180
@bbr_bug
BBR - Bug Bounty Resources 🧵
5 months
The powerful checklist for doing bug bounty or pentesting assessment It's @owasp based checklist and has 500+ Test Cases
Tweet media one
0
52
186
@bbr_bug
BBR - Bug Bounty Resources 🧵
5 months
Files Containing Juicy Info inurl:"/.vscode/sftp.json" #bugbounty #bugbountytips #bugbountytip #cybersecurity #ethicalhacking
Tweet media one
2
31
181
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
Bug Bounty Reports in Threads 🧵 #bugbounty #Infosec ➡️ Bug : Stored XSS in Shopify ➡️ Bounty : $1000 Read For More : 👇
3
24
158
@bbr_bug
BBR - Bug Bounty Resources 🧵
10 months
BBR - Bug Bounty Resources 🧵 Pentesting Web checklist The document is about pentesting web applications. It discusses :- • Reconnaissance, • Web Attacks, and other checks.
Tweet media one
0
47
151
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
Bug Bounty Reports in Thread 🧵 #bugbounty #Infosec Bug : Facebook Group Members Disclosure Organization : Facebook or Meta Bounty : $4500 Read Full Bug Reports 🧵: 👇
4
37
146
@bbr_bug
BBR - Bug Bounty Resources 🧵
5 months
Hunting For API Vulnerabilities
Tweet media one
Tweet media two
1
36
152
@bbr_bug
BBR - Bug Bounty Resources 🧵
6 months
SQLMap from Waybackurls waybackurls target | grep -E '\bhttps?://\S+?=\S+' | grep -E '\.php|\.asp' | sort -u | sed 's/\(=[^&]*\)/=/g' | tee urls.txt | sort -u -o urls.txt && cat urls.txt | xargs -I{} sqlmap --technique=T --batch -u "{}"
Tweet media one
1
34
156
@bbr_bug
BBR - Bug Bounty Resources 🧵
5 months
Authentication Testing !
Tweet media one
1
29
150
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
Bug Bounty Reports in Thread 🧵 #bugbounty #infosec • Bug : Ethereum account balance manipulation • Bug Type : Business Logic Errors • Organization : Coinbase • Bounty : $10000 • Technology : Blockchain or Web 3 Read This Report : 👇
5
40
141
@bbr_bug
BBR - Bug Bounty Resources 🧵
6 months
Add /api/.env to the wordlist, and maybe you will have access to dotenv file environment that leads to exposing SMTP credentials and AWS access key , secret key #bugbountytips #bugbountytip #cybersecurity #ethicalhacking Credits - @NoRed0x
Tweet media one
0
20
139
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
Bug Bounty Reports in Thread 🧵 Type: Blind & Stored Cross-site Scripting (XSS) - Generic Company: localtapiola Bounty: $3,000 Read: 👇🏾
6
37
134
@bbr_bug
BBR - Bug Bounty Resources 🧵
6 months
Payload for XSS + SQLi + SSTI/CSTI ! '"><svg/onload=prompt(5);>{{7*7}} ' ==> for Sql injection "><svg/onload=prompt(5);> ==> for XSS {{7*7}} ==> for SSTI/CSTI
2
22
132
@bbr_bug
BBR - Bug Bounty Resources 🧵
5 months
Top 25 SSRF parameters 📃 • ?dest={target} • ?redirect={target} • ?uri={target} • ?path={target} • ?continue={target} • ?url={target} • ?window={target} • ?next={target} • ?data={target} • ?reference={target} • ?site={target} #bugbounty #infosec More 👇
1
25
136
@bbr_bug
BBR - Bug Bounty Resources 🧵
5 months
Nuclei Template : REFLECTION Potential Cross-Site Scripting (XSS), CORS, Cross-Site Request Forgery (CSRF) attacks, Cache Poisoning and Open URL Redirection, OAUTH Redirection nuclei -t reflection[.]yaml -u target Nuclei Template :
Tweet media one
Tweet media two
1
29
126
@bbr_bug
BBR - Bug Bounty Resources 🧵
6 months
wp-config backup Sensitive Data Exposure: Check for `wp-config.php.bak` endpoint maybe you will get juicy data. enjoy
Tweet media one
0
22
126
@bbr_bug
BBR - Bug Bounty Resources 🧵
6 months
ℹ️ Sending payload within the URL/URI itself can also trigger SQL injection. So don't just focus on the parameters. #SQLInjection #bugbounty
Tweet media one
2
21
124
@bbr_bug
BBR - Bug Bounty Resources 🧵
6 months
Here are XSS Payloads To Bypass Firewall Credit/source- @Pwn4arn
Tweet media one
1
21
117
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
Amazing SSRF Mindmap #bugbounty #infosec Credit : @hackerscrolls Download PNG : Take a look below : 👇
Tweet media one
4
38
114
@bbr_bug
BBR - Bug Bounty Resources 🧵
6 months
We found a Gem Mindmaps to help bug bounty Hunters, pentesters, and offensive/defensive security Professionals
Tweet media one
0
41
111
@bbr_bug
BBR - Bug Bounty Resources 🧵
5 months
List of Burp Extension Useful For Pentesting !
Tweet media one
1
22
114
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
Bug Bounty Reports in Thread 🧵 #bugbounty #infosec Bug Type : Reflected XSS Org : Shopify Bounty : $2000 Read For More 🧵:👇
4
18
106
@bbr_bug
BBR - Bug Bounty Resources 🧵
6 months
Web App pentesting checklist is here.
Tweet media one
Tweet media two
1
25
110
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
A useful one-liner to quickly get subdomains of a DOMAIN: curl -s .… |jq -r .FDNS_A[]|cut -d',' -f2|sort -u #bugbounty #hackerone #bugbountytips
6
37
104
@bbr_bug
BBR - Bug Bounty Resources 🧵
6 months
Found SQL Injection to Account Takeover Manually :) 1. Enter mobile number to login intercept {"mobile_number":"8888888888"} >> 200 {"mobile_number":"8888888888'"} >> 500 {"mobile_number":"8888888888''"} >> 200 #bugbountytips
Tweet media one
0
24
105
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
Bug Bounty Reports in Thread 🧵 #bugbounty #Infosec Bug : Cross-site Scripting (XSS) on HackerOne careers page On : Hackerone Summary: DOM XSS at endpoint , but can not bypass CSP. It's work on IE and Edge. See🧵:👇
4
45
80
@bbr_bug
BBR - Bug Bounty Resources 🧵
6 months
Upload Function Exploit Techniques.📚 #infosec #bugbountytip #cybersecurity
Tweet media one
1
19
86
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
Bug Bounty Reports in Thread 🧵 ✨ Bugs : STRIPE Live Key Exposed ✨ Impact : Companies and other end users Sensitive Information Disclosure. ✨ Organization : Stripe 💵 Bounty : 1000$ #bugbounty #hacking #infosec 🧵:👇
2
33
76
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
Bug bounty Report in Thread 🧵 Type: Open Redirect ORG: Twitter Bounty: $560 Read For MOre:👇
1
18
78
@bbr_bug
BBR - Bug Bounty Resources 🧵
6 months
MySQL Blind (Time Based) Payload List #BugBounty #bugbountytips
Tweet media one
0
11
77
@bbr_bug
BBR - Bug Bounty Resources 🧵
5 months
GitHub Dorking Methodology Credit: @therceman
Tweet media one
0
24
74
@bbr_bug
BBR - Bug Bounty Resources 🧵
7 months
🚨Reset Password Vulnerabilities Testing Method🚨 📥Download PDF . . #bugbounty #bugbountytips #penetrationtesting #password
Tweet media one
Tweet media two
Tweet media three
3
31
67
@bbr_bug
BBR - Bug Bounty Resources 🧵
6 months
Here is Active Directory Pentesting Mind Map: V1: V2:
Tweet media one
0
14
64
@bbr_bug
BBR - Bug Bounty Resources 🧵
10 months
🕵️‍♂️🔍🛠️ The Top Hacker Methodologies & Tools Notes 📝 Concrete5 CMS: Identification, Mass Hunting, Nuclei Template Writing & Reporting 🔗 Link: #bugbounty #infosec #bugbountytip 👾🔒🔧
Tweet media one
0
10
61
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
Bug Bounty Reports in Thread 🧵 Type: Path Traversal ORG: Node.js CVE ID: CVE-2018-3729 Read More: 👇🏼
1
21
57
@bbr_bug
BBR - Bug Bounty Resources 🧵
1 year
Bugbounty Reports in Thread🧵 Bug: Stealing Users OAuth authorization code via redirect_uri Type: Improper Authentication Program: pixiv ( hackerone ) Siverity: High (7 ~ 8.9) Bounty: $2K More👇
1
10
58
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
A cool XXE resulting from an SSRF found on a local company website during a pentest. DMs are open, retweet, and like if you love this style of PoC! 😎 #bugbounty #bugbountytip #bugbountytips #infosec
Tweet media one
2
7
58
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
Bug hunters Methodology v4 ~ @Jhaddix
Tweet media one
1
13
55
@bbr_bug
BBR - Bug Bounty Resources 🧵
6 months
Here is a recon Guide for Bug Hunting. credit/source- @Pwn4arn
Tweet media one
3
6
58
@bbr_bug
BBR - Bug Bounty Resources 🧵
6 months
Web App pentesting checklist is here.
Tweet media one
Tweet media two
1
7
52
@bbr_bug
BBR - Bug Bounty Resources 🧵
7 months
Tweet media one
1
17
47
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
Improper Generic Authentication Bug Reports ➡️ Username restriction bypass with SSL client authentication ➡️ Unauthenticated access {Shopify} : ➡️ Deleting other people's comments {valve} : More Reports👇
3
17
44
@bbr_bug
BBR - Bug Bounty Resources 🧵
6 months
API security checklist Checklist of the most important security countermeasures when designing, testing, and releasing your API
Tweet media one
0
15
46
@bbr_bug
BBR - Bug Bounty Resources 🧵
6 months
Don't tell me that you are not aware about this Cybersecurity GPT in this realm of AI Much more then shown in this image. Link- #AI #CyberSecurity #hackers #GPT
Tweet media one
0
6
44
@bbr_bug
BBR - Bug Bounty Resources 🧵
5 months
Upload functionality testing
Tweet media one
0
9
43
@bbr_bug
BBR - Bug Bounty Resources 🧵
6 months
Tweet media one
0
5
41
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
Bug Bounty Reports in Thread 🧵 Type: Request Hijacking Vulnerability Company: RubyGems Bounty: $1000 More: 👇
1
8
38
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
Complete your Study Plan to become a successful Cybersecurity Engineer :) #cybersecurity #infosec #hacking
Tweet media one
0
13
35
@bbr_bug
BBR - Bug Bounty Resources 🧵
6 months
It's Halloween! Here are 10 overlooked bugs: 🐞 HTTP/2 Smuggling 🐛 XXE via OOMXL Parsers 🐜 SSRF via XSS in PDF Generators 🕷 XSS via SVG 🦟 Blind XSS 🐞 Web Cache Deception & Poisoning 🐛 h2c Smuggling 🐜 2nd Order Sub Takeovers 🕷 postMessage bugs
Tweet media one
0
7
39
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
Steps To Produce : 1-Open your store account 2-Navigate to https://xxx.myshopify .com/admin/settings/general 3. 3-Put your street address xss payload (xss"><!--><svg/onload=alert(document.domain)>) 4-Go to https://xxx.myshopify. com/admin/dashboards/live 5-XSS alert Pop Ups
Tweet media one
2
3
34
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
Pentest Training - Certifications #bugbounty #infosec Categorized :👇-> Take a look ⬇️
Tweet media one
1
10
29
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
Tweet media one
0
15
31
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
Description : WAF cut html tages but when put <!--> before tages we can bypass it :) .
Tweet media one
1
0
24
@bbr_bug
BBR - Bug Bounty Resources 🧵
10 months
SQL Injection in `X-Forwarded-For:` header. Credits: @nav1n0x
Tweet media one
0
4
22
@bbr_bug
BBR - Bug Bounty Resources 🧵
7 months
200+books on info sec  and cybersecurity. Feel free to download any and read. LINK: …
Tweet media one
2
4
22
@bbr_bug
BBR - Bug Bounty Resources 🧵
7 months
Shodan Dorks for bug bounty
Tweet media one
0
5
20
@bbr_bug
BBR - Bug Bounty Resources 🧵
7 months
Types of Malware
Tweet media one
0
3
15
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
• ?html={target} • ?val={target} • ?validate={target} • ?domain={target} • ?callback={target} • ?return={target} • ?page={target} • ?feed={target} • ?host={target} • ?port={target} • ?to={target} • ?out={target} • ?view={target} • ?dir={target}
2
2
13
@bbr_bug
BBR - Bug Bounty Resources 🧵
7 months
Top 30 Cybersecurity Search Engines
Tweet media one
0
2
13
@bbr_bug
BBR - Bug Bounty Resources 🧵
7 months
Tweet media one
0
2
14
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
This proxy acts as their access proxy and gave me access to their internal pages. So, after adding this proxy to my computer I was able to access the admin panel from my laptop browser as well. And Got Rewarded a huge bounty Check Out The Write-up :
1
3
13
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
Thank You For Reading This Amazing Bug bounty Thread 🧵On Rate Limit Bypass Do Follow For more Like This Hope You Like this 😃
1
0
13
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
Impact #bugbounty #Infosec • XSS but can not bypass CSP • inject html code
Tweet media one
1
2
12
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
🏹 How he exploited it? He created a simple script to create 1000 unique security tokens using the previously found endpoint. Imported this token into intruder. Added the header “X-Disabled-Recaptcha: 0” and started the attack. And they awarded 1800$ for this Bypass
Tweet media one
Tweet media two
3
0
12
@bbr_bug
BBR - Bug Bounty Resources 🧵
7 months
Tweet media one
0
0
12
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
STEPS TO RePRODUCE:
Tweet media one
2
1
11
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
Thanks You So Much For Reading This Amazing Bug Bounty On : Accessing Google Internal Admin Panel Hope You'll Like it 👍 Do Follow For More
2
0
12
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
0
0
12
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
@IamRenganathan AI says we will rule on human meanwhile a man take root access on it and said father will always be father. 😂 Lol
1
2
12
@bbr_bug
BBR - Bug Bounty Resources 🧵
7 months
List of Bug Bounty/Crowdsourced Security Platforms
Tweet media one
1
1
10
@bbr_bug
BBR - Bug Bounty Resources 🧵
7 months
Creating the perfect bug bounty automation (via trial and error) Attempt #1 : Bash Attempt #2 : Django Attempt #3 : Golang and the Unix Philosophy Attempt #4 : Cloud Native
Tweet media one
0
0
11
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
What type of Bugbounty Reports in Thread 🧵 You Want ? • Gaint Bounty Type • High Severity Type • Bug Bounty Report of Big Tech Giants • All of these Comment 👇
4
0
10
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
A Bug Hunter had accessed a HackerOne Security Analyst’s HackerOne account. What Happen ? A session cookie was disclosed due to a human error, Which led to the hacker being able to access the account.
1
0
9
@bbr_bug
BBR - Bug Bounty Resources 🧵
7 months
Active Directory Pentesting Mind Map: V1: … V2:
Tweet media one
0
5
10
@bbr_bug
BBR - Bug Bounty Resources 🧵
7 months
Recon Tools for Web Application Pentesting!
Tweet media one
1
1
9
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
Hope You'll Like This My Trick To Show You Bug Bounty Reports in Thread 🧵 Thank 🙏 You So Much For Reading For More Like 👍 This Do follow and hit a like
1
0
9
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
In the xsspoc.txt you can also see that the employee used some kind of intranet website that is not accessible through internet ( https://██████████.tapiola .fi/a2/VerkaFileLoaderWeb/rest/files/30fe1c28-4c4f-4f2c-bb3c-eae59ec7b42c).
Tweet media one
1
2
9
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
POC : IMG Below👇 Payload : POC: lever- #aaa "><script src=""></script>
Tweet media one
1
2
9
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
@Aacle_ @Jhaddix Now you stuck in a big dilemma
0
0
9
@bbr_bug
BBR - Bug Bounty Resources 🧵
7 months
Search Engine for Pentester Cheat Sheet
Tweet media one
0
0
8
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
Steps To Reproduce:
Tweet media one
1
0
8
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
Thank You For Reading This Amazing Bug Bounty Report📄 On XSS Like And Do Follow For More
1
1
8
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
3. Navigate to https://echo .myshopify.com/?theme_handle=xx%27-alert(document.cookie)-%27&style_id=1&style_handle=1&preview_theme_id=<theme_ID> replace <theme_ID> with the ID you just copied.
2
2
7
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
Hope You'll Like👍 This Report On: Open Redirect on Twitter Please Follow and Like For More
2
0
7
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
🏹 How they implemented rate limit security mechanism? On any of their endpoint, there were 2 things responsible for preventing rate limit attacks. 1. X-Recaptcha-Token header • It consists of the captcha token 2. X-Security-Token header • consists of a long value :👇
Tweet media one
1
2
7
@bbr_bug
BBR - Bug Bounty Resources 🧵
2 years
Steps To Reproduce: 1. Install localhost-now 2. run localhost-now in directory of your choice 3. execute following curl command (adjust number of ../ to reflect your system): 4. Result in Path Traversal: 👇
Tweet media one
1
1
7