Filter
Exclude
Time range
-
Near
4 Jul 2025
โš ๏ธ For Educational Use Only ๐Ÿ›ก๏ธ Use these responsibly in legal environments. #EthicalHacking #CyberSecurity #LinuxForHackers #BugBounty #TerminalCommands #InfoSec #HackerTips #HackThePlanet
4
831
Time to pivot our threat modeling and user education strategies ๐Ÿ” 6/ Protect yourself: Donโ€™t download "fixes" from unverified sources Check URLs closely Use sandboxing for suspicious links Educate non-tech users โ€” theyโ€™re the prime targets #CyberAware #HackerTips
2
19
Tune in to our newest release on ๐ŸŽฅ YouTube โฌ†๏ธ๐Ÿ”— youtu.be/gcNroWl49Wc?featureโ€ฆ During the session titled "Tales from a Triage" at BSides Ahmedabad0x05, @CharlieW_T3X4N shared top tips for writing reports that truly connect with readers! He highlighted the power of seeing things from your readerโ€™s perspective, communicating clearly, and using strategies to boost your report acceptance rate โœ…โœ๏ธ ๐Ÿšจ Early Bird Sale Alert! ๐Ÿšจ Book your discounted tickets today ๐ŸŽซโœ… ๐Ÿ”— bsidesahmedabad.in/passes/ #bsidesahmedabad #infosec #TalesFromATriage #BugBounty #ReportWriting #cybersecurity #EffectiveCommunication #SecurityResearch #VulnerabilityDisclosure #HackerTips
3
6
1,092
Social engineering: the human element of hacking. Never underestimate its power. #HackerTips #CyberSecurity
4
6
433
๐Ÿค” Question of the Day: How to approach restricted bug bounty programs with a single site in scope? Many ask me, "How do you discover issues on bug bounty programs with only one target site in scope? What sets you apart?" While most shy away from such targets, I employ a few extra strategies that help me uncover more issues. Here are the top 5 approaches I use on these targets: 1๏ธโƒฃ Check for Mobile Apps: Even if the mobile app isn't in scope, it's worth inspecting. I've found many programs with Android apps not explicitly listed in scope, yet they call the same in-scope APIs or target sites. This reveals overlooked endpoints, leading to more reported security issues. 2๏ธโƒฃ Subdomain Takeovers: Unless explicitly excluded, programs often accept these issues, even when they've specified only the root domain as in-scope. 3๏ธโƒฃ Analyze JavaScript Files: Install and analyze all JS files, including archived ones. The goal is to identify as many endpoints as possible, including legacy ones that may still be active, presenting numerous opportunities to find security issues. 4๏ธโƒฃ Mobile App API Endpoints: Install all versions of mobile apps and extract endpoints from the Java source code. This reveals endpoints used across various releases, uncovering many testable endpoints and potential security bugs. 5๏ธโƒฃ Explore Premium Features: Consider obtaining a paid account on these services. Free trial schemes or money-back guarantee packages are often available. Treat it as a $50 investment to explore premium features. You'll be amazed at the possibilities a paid account can open up for finding bugs. Takeaways: Don't give up on restricted targets; there's more beneath the surface. Think creatively, and explore areas others might overlook. You'll be surprised by the results! ๐Ÿš€๐Ÿ’ก #BugBounty #Cybersecurity #HackerTips #InfoSec #BugBountyTips #SecurityTips #InfoSec
14
43
286
33,710
๐Ÿšจ#opensourcesecurity release alert๐Ÿšจ asnmap v1.0.6 is out! Try it out today to grab #CIDR ranges from Organization names, #ASN numbers, IP addresses, and Domain names today! #bugbountyhunting #ossrelease #hackertips
15
2,611
25 Nov 2022
#HackerTalk: todo lo que necesitas saber sobre el proceso para unirte a la comunidad de #CyScope y cรณmo crecer dentro de nuestra plataforma de #bugbounty! #bugbountytips #hackertips #ethicalhacking #hacking
2
3
LDAP injection auth bypasses 1. * 2. *)(& 3. *)(|(& 4. pwd) 5. *)(|(* 6. *)) 7. admin)(&) #LDAP #auth #bypass #HackerTips
2
[HACKER TIP] Top Burp Suite Extensions: 1- Turbo Intruder 2- J2EEScan 3- Autorize 4- Active Scan 5- Collaborator Everywhere 6- Param Miner 7- JSON Beautifier 8- Upload Scanner 9- Freddy 10- Logger #bugbounty #hackertips #BurpSuite
1
4
[HACKER TIP] Top Burp Suite Extensions: 1- Turbo Intruder 2- J2EEScan 3- Autorize 4- Active Scan 5- Collaborator Everywhere 6- Param Miner 7- JSON Beautifier 8- Upload Scanner 9- Freddy 10- Logger #bugbounty #hackertips #BurpSuite
9
105
361
[HACKER TIP] If you ever find LibreOffice is being used for file conversion there is a potential SSRF that you can exploit by injecting your payload in the XML. #bugbounty #hackertips
3
17
77
[HACKER TIP] If you are testing Open Redirect but there is a blacklisted character, you can test it with a chinese dot to bypass it or any other Unicode Character. example: redirect_to=////evilใ€‚comย  #bugbounty #hackertips #openredirect
3
41
181
[HACKER TIP] If you are trying to do an SSRF with XXE but some XML entities are blocked, you can try using XML parameter entities. #bugbounty #hackertips #XSS
19
93
[HACKER TIP] If you came across SSTI in a go application, it is worth trying the following payload {{define "T1"}}<script>alert(1)</script>{{end}} {{template "T1"}} to achieve XSS and bypass HTML sanitization. #bugbounty #hackertips #XSS
101
261
[HACKER TIP] If you find a blind error based XXE but out-of-band interactions are blocked you can use a system DTD and redefine an entity that is declared within that DTD. #bugbounty #hackertips
1
13
34
[HACKER TIP] Don't forget to check the subdomain records, and if it is pointing to a service (such as Github Pages .. ) that has been removed or deleted. You can takeover this subdomain if you follow these steps๐Ÿ”ฅ Thanks @BenaliSemah for the tip ๐Ÿ™ #bugbounty #hackertips
5
49
[HACKER TIP] If you got an SQL injection in MSSQL you can elevate the severity of the bug by getting an RCE By enabling xp_cmdshell and then you can execute commands by typing EXEC xp_cmdshell 'Command Option'; Credit: @H4MA_TN #bugbounty #hackertips @YogoshaOfficial #OSINT
1
1
[HACKER TIP] If you got an SQL injection in MSSQL you can elevate the severity of the bug by getting an RCE By enabling xp_cmdshell and then you can execute commands by typing EXEC xp_cmdshell 'Command Option'; Thanks @H4MA_TN for the tip ๐Ÿ™ #bugbounty #hackertips
3
35
139
[HACKER TIP] Donโ€™t forget to test if โ€œnullโ€ origin is reflected in Access-Control-Allow-Origin header since some developers always use it for local development and tests. You can obtain the null origin and exploit it using a sandboxed iframe. ๐Ÿš€ #bugbounty #hackertips
6
17