Filter
Exclude
Time range
-
Near
@0xTobi retweeted
Bug Bounty & Web Security Course 🐞💥 Learn reconnaissance, Burp Suite, SQLi, XSS, SSRF, CORS, File Inclusion, Security Misconfigurations, VAPT Automation, and Vulnerability Reporting. 📥 Drive Folder: drive.google.com/drive/mobil… #BugBounty #WebSecurity #Pentesting #EthicalHacking #BurpSuite #SQLi #XSS #SSRF #VAPT #CyberSecurity
1
40
167
4,902
chinwi12 retweeted
3
6
82
2,013
Ethical Hacking Roadmap Step 1: Learn Networking & System Basics Step 2: Master Linux & Command Line Step 3: Understand Web Fundamentals Step 4: Start Hands-On Practice (TryHackMe, Hack The Box) Step 5: Learn Reconnaissance & Scanning (Nmap) Step 6: Master Web Attacks (SQLi, XSS, IDOR) using Burp Suite Step 7: Learn Exploitation & Privilege Escalation Step 8: Understand Security Fundamentals Step 9: Study Cryptography (Basics & Practical Use) Step 10: Practice in Labs & CTFs Step 11: Get Certified (OSCP, CEH) Step 12: Start Bug Bounty or Pentesting Role Pro Tip: Think like an attacker, practice daily, and focus on real skills over just tools.
1
5
104
The chain: SQLi got them onto the corporate network. Worthless on its own. They spent ~6 months pivoting to the segregated payment network.
1
SQLi is when a user types database commands into an input box i.e login form and tricks the app into obeying them or giving out the database when using the terminal... Two major tools are involved in this sqlmap & burp suite (in some cases you might not even need burp)
What is SQL injection and how can you prevent it ?
1
4
87
App was behind akamai: I tried duplicate parameter, One loaded with junk of 64kb and other with payload and finally time based sqli🙂. #bugbounty #bugbountytips #Bugbounty #Bugbountytips
2
32
863
I'm in.....where is the sign up form (or do I need to SQLI to get an account?)
1
25