BOUNTY TIP: Get yourself a nice bounty present by buying giftcards with birthday discounts π! Repeat & recycle your gift cards to generate infinite money. π°π€Thanks, and happy (real) birthday, @securinti! ππ#BugBountyTip#HackWithIntigriti
Alternate data streams sound like this π€― to you?
Well, thankfully we have @almroot jumping in to help, telling us how to leak source code or bypass authentication with that π¦
#bugbountytips π
Local file inclusion vulnerability found but no idea for further exploitation scenarios? Well, try going for a remote file inclusion vuln π₯
@PinkDraconian is coming in to help us out today! πΈ
#bugbountytips π
Ever put yourself into the shoes of a DEV? It's not an easy job and sometimes you forget to remove some dev tools from production code π οΈ
@alph4byt3 is helping us out today with his #bugbountytip! He also has a handy tool to share -> hubs.li/Q01Gc7fQ0#bugbountytips π
Ever dreamed of magically finding SSRF vulnerabilities? π¦
Well, thanks to @Regala_ and today's #bugbountytip, this is finally becoming reality!
#bugbountytipsπ
Everyone uses generic wordlists, so unless you want to find duplicates, create your own! Target based wordlists are easy to compile and often result in easy bounties, even on public programs. Thanks for the #BugBountyTip, @Rhynorater! #BugBountyTips
Finding juicy information is not always a one-step process! π‘
@Random_Robbie helps you with today's #bugbountytip to find your way through the maze!
#bugbountytips π
Have you ever checked the text version of a HTML e-mail for template injection? Always make sure to inspect the original e-mail source for hidden treasures π΅. Thanks for the #BugBountyTip, @honoki! #HackWithIntigriti
Found a potential SSRF vuln but no luck? Don't give up just now! πͺ
@joohoi is helping us out today with his #bugbountytip π§βπ»
#bugbountytips
This is your weekly reminder that you can use any arbitrary amount of 0οΈβ£'s in an IP address to bypass SSRF blacklists. Thanks for the #BugBountyTip, @naategh_! π
The X-Forwarded-For header turns out to be a perfect place to hide your blind XSS or SQL injection payloads, according to @_zulln. Thanks for the tip, Linus! #BugBountyTip#HackWithIntigriti