Sh_O_A1b's profile picture. Ethical Hacker | Security Researcher | Bugcrowd |Hackerone | Stock Investor | Crypto/NFTs Geek | Entrepreneur | MBBS | 🇦🇪🇵🇰

Sh O Aib

@Sh_O_A1b

Ethical Hacker | Security Researcher | Bugcrowd |Hackerone | Stock Investor | Crypto/NFTs Geek | Entrepreneur | MBBS | 🇦🇪🇵🇰

Joined June 2018
Similar User
siratsami71's profile picture. Independent Cyber Security Researcher

@siratsami71

saurabhsanmane2's profile picture. 🇮🇳  | Security Researcher | Bug Bounty Hunter

@saurabhsanmane2

Debian_Hunter's profile picture. Bughunter  | Poet  |  DM is always open for questions and help ~

@Debian_Hunter

walidhossain010's profile picture. Web app tester || Everything is vulnerable! || https://t.co/pReiIkBOum For pentest: DM! 👆

@walidhossain010

MrSharmax_'s profile picture. https://t.co/0WDWm0DA8n | https://t.co/uONxZLwyeZ  | India♥️

@MrSharmax_

spencer_5cent's profile picture. Bug bounty hunter from 🗽live in 🇹🇼

@spencer_5cent

sushantdhopat's profile picture. Just do epic hacks. Hunting bugs coffee. Living the doepichack dream.

@sushantdhopat

dewcode91's profile picture. Bug Hunter🐞

@dewcode91

PD_5ive's profile picture. Top 100 on @Bugcrowd                                   
https://t.co/Jccxy7iQXO

@PD_5ive

JerryShah33's profile picture. | Penetration Tester | 🐞
| Digital Forensics | 🔎
| Threat Hunting | 🚨
| CISP | eJPTv2 | eWPTXv2 | CPTC | Database Security for Cyber Professionals | CAP

@JerryShah33

itsz4x's profile picture. Security Researcher | Bug Hunter 🐞
                 Let's hack hack and more hack ☠️

@itsz4x

AbhishekKarle3's profile picture. eCPPTv2 | CAP | Pentester | Ethical Hacker | Information Security Enthusiast

@AbhishekKarle3

K0ngS3ng's profile picture. Student Hacker| Bug Bounty

@K0ngS3ng

sa1tama0's profile picture. Independent Cyber Security Researcher

@sa1tama0

gkhck_'s profile picture. $NST

https://t.co/8PLcRmjQ2U

@gkhck_

Pinned

I earned $1250 at @Bugcrowd Tip: Log into account -> URL requested by web app-> site.com/sso/session/sy… -> xxx cookie set-> modify xxx-> sess. cookie set to xxx -> sent to victim-> Victim cookie is set by attacker-> Victim auth cookie-> Attacker logs in using cookie #bugbountytip

Sh_O_A1b's tweet image. I earned $1250 at @Bugcrowd
Tip: Log into account -> URL requested by web app-> site.com/sso/session/sy… -> xxx cookie set-> modify xxx-> sess. cookie set to xxx -> sent to victim-> Victim cookie is set by attacker-> Victim auth cookie-> Attacker logs in using cookie
#bugbountytip

Sh O Aib Reposted

Add the file `wp-config.php.txt` to your wordlist, and you might discover some juicy data. Enjoy! 😏 #bugbountytips #bugbountytip #cybersecurity #ethicalhacking

NoRed0x's tweet image. Add the file `wp-config.php.txt` to your wordlist, and you might discover some juicy data. Enjoy! 😏                                                        

 #bugbountytips #bugbountytip #cybersecurity #ethicalhacking

Sh O Aib Reposted

Extracting Credentials From Windows Logs : practicalsecurityanalytics.com/extracting-cre…

binitamshah's tweet image. Extracting Credentials From Windows Logs : practicalsecurityanalytics.com/extracting-cre…
binitamshah's tweet image. Extracting Credentials From Windows Logs : practicalsecurityanalytics.com/extracting-cre…

Sh O Aib Reposted

Tip:- Do wayback on root domain then get endpoints and add it to your list and fuzz on subdomains or other roots.. $ ~ waybackurls root.com |cut -d "/" -f 4-|sort -u > endpoints.txt #bugbountytips #bugbountytip #bugbounty #hackerone #bugcrowd #h1

111xNagashy's tweet image. Tip:-

Do wayback on root domain then get endpoints and add it to your list and fuzz on subdomains or other roots..

$ ~ waybackurls root.com  |cut -d "/" -f 4-|sort -u > endpoints.txt

#bugbountytips #bugbountytip #bugbounty #hackerone #bugcrowd #h1

Sh O Aib Reposted

Google Dorks - Code Leaks 💧 site:pastebin. com "example. com" site:jsfiddle. net "example. com" site:codebeautify. org "example. com" site:codepen. io "example. com"

TakSec's tweet image. Google Dorks - Code Leaks 💧

site:pastebin. com "example. com"
site:jsfiddle. net "example. com"
site:codebeautify. org "example. com"
site:codepen. io "example. com"

Sh O Aib Reposted

Subdomain Takeover Detection with Subfinder & Nuclei -new wordpress takeover detection for nuclei template subfinder -d target -o target && nuclei -t wp-xyz-takeover[.]yaml -l target #bugbountytips #bugbounty github.com/schooldropout1…

's tweet image. Subdomain Takeover Detection  with Subfinder & Nuclei 

-new wordpress takeover detection for nuclei template

subfinder -d target -o target && nuclei -t wp-xyz-takeover[.]yaml -l target

#bugbountytips #bugbounty

github.com/schooldropout1…
's tweet image. Subdomain Takeover Detection  with Subfinder & Nuclei 

-new wordpress takeover detection for nuclei template

subfinder -d target -o target && nuclei -t wp-xyz-takeover[.]yaml -l target

#bugbountytips #bugbounty

github.com/schooldropout1…
's tweet image. Subdomain Takeover Detection  with Subfinder & Nuclei 

-new wordpress takeover detection for nuclei template

subfinder -d target -o target && nuclei -t wp-xyz-takeover[.]yaml -l target

#bugbountytips #bugbounty

github.com/schooldropout1…
's tweet image. Subdomain Takeover Detection  with Subfinder & Nuclei 

-new wordpress takeover detection for nuclei template

subfinder -d target -o target && nuclei -t wp-xyz-takeover[.]yaml -l target

#bugbountytips #bugbounty

github.com/schooldropout1…

Sh O Aib Reposted

Automate xss and sqli vulnerabilities finding #bugbounty #bugbountytip

momika233's tweet image. Automate xss and sqli vulnerabilities finding
#bugbounty #bugbountytip

Sh O Aib Reposted

Nuclei Template : REFLECTION Potential XSS, SSRF, Cache Poisoning, Open URL Redirection & OAUTH Redirection nuclei -t reflection[.]yaml -u target Credit: @gudetama_bf #BugBounty #bugbountytips

RootMoksha's tweet image. Nuclei Template : REFLECTION

Potential XSS, SSRF, Cache Poisoning, Open URL Redirection & OAUTH Redirection

nuclei -t reflection[.]yaml -u target

Credit: @gudetama_bf 

#BugBounty #bugbountytips
RootMoksha's tweet image. Nuclei Template : REFLECTION

Potential XSS, SSRF, Cache Poisoning, Open URL Redirection & OAUTH Redirection

nuclei -t reflection[.]yaml -u target

Credit: @gudetama_bf 

#BugBounty #bugbountytips
RootMoksha's tweet image. Nuclei Template : REFLECTION

Potential XSS, SSRF, Cache Poisoning, Open URL Redirection & OAUTH Redirection

nuclei -t reflection[.]yaml -u target

Credit: @gudetama_bf 

#BugBounty #bugbountytips

Sh O Aib Reposted

Tip:- Add to your wordlist: auth/jwt/register auth-demo/register/classic auth-demo/register/modern My First P1🥳 #bugbountytips #bugbountytip #bugbounty #hackerone #bugcrowd #h1

111xNagashy's tweet image. Tip:-

Add to your wordlist:

auth/jwt/register
auth-demo/register/classic
auth-demo/register/modern

My First P1🥳

#bugbountytips #bugbountytip #bugbounty #hackerone #bugcrowd #h1
111xNagashy's tweet image. Tip:-

Add to your wordlist:

auth/jwt/register
auth-demo/register/classic
auth-demo/register/modern

My First P1🥳

#bugbountytips #bugbountytip #bugbounty #hackerone #bugcrowd #h1

Sh O Aib Reposted

A curated list wordlists for bruteforcing and fuzzing - by gmelodie github.com/gmelodie/aweso…

7h3h4ckv157's tweet image. A curated list wordlists for bruteforcing and fuzzing - by gmelodie 

github.com/gmelodie/aweso…

Sh O Aib Reposted

Gotta say man I like the payload, Hope you dont mind I add it to my Github Xss payloads area github.com/shadowByte1/xss


Sh O Aib Reposted

If you're into generating subdomains quickly 🚀 check out this website: husseinphp.github.io/subdomain/ #bugbountytips #bugbountytip #BugBounty

0xHussein's tweet image. If you're into generating subdomains quickly  🚀
check out this website: husseinphp.github.io/subdomain/

#bugbountytips  #bugbountytip #BugBounty

Sh O Aib Reposted

localbackup.log


Sh O Aib Reposted

Super Blind SQL Injection- $20000 bounty | Thousands of targets still vulnerable by priyanshu shakya  Payload: User-Agent: "XOR(if(now()=sysdate(),sleep(5),0))XOR"  #bugbountytips #bugbounty #sqli  medium.com/@pranshux0x/su…


Sh O Aib Reposted

What is everyone using for blind XSS these days?


Sh O Aib Reposted

In April, @samwcyo and I discovered a way to bypass airport security via SQL injection in a database of crewmembers. Unfortunately, DHS ghosted us after we disclosed the issue, and the TSA attempted to cover up what we found. Here is our writeup: ian.sh/tsa


Sh O Aib Reposted

1-Subdomainer(contain sudfinder,amass whois mode,amass passive mode,crt/.sh,GitHub,gobuster,knockpy,) 2-chaos(Archived Data) 3-frogy(wayback,bbot,subfinder,findomain,crt.sh) 4-assetfinder (certspotter,hackertarget,threatcrowd,wayback ,bufferover,facebook)

111xNagashy's tweet image. 1-Subdomainer(contain sudfinder,amass whois mode,amass passive mode,crt/.sh,GitHub,gobuster,knockpy,)
2-chaos(Archived Data)
3-frogy(wayback,bbot,subfinder,findomain,crt.sh)
4-assetfinder (certspotter,hackertarget,threatcrowd,wayback ,bufferover,facebook)

Loading...

Something went wrong.


Something went wrong.