Eib

810 posts

Eib banner
Eib

Eib

@eib_____

The World is Yours # Bug Bounty Blog @ https://t.co/ccm9ey1x1r

Beigetreten Ağustos 2024
425 Folgt82 Follower
Angehefteter Tweet
Eib
Eib@eib_____·
I just achieved one of my 2025 goals by gaining my first private invite on Bugcrowd ✌️✌️✌️
English
0
0
7
623
Eib retweetet
shakquraa
shakquraa@shakquraa·
POV: You found a Firebase misconfiguration, but the conversation gets misconfigured instead💀
shakquraa tweet media
English
0
1
1
65
Eib retweetet
Web Security Academy
Web Security Academy@WebSecAcademy·
You're up against a SSRF filter that only allows approved domains, and you've tried the IP encoding trick from yesterdays tweet. The next step? Look for an open redirect! allowed-domain[.]com/redirect?url=http://internal-server/admin The SSRF filter sees a request to an allowed domain, but the server might just follow the redirect to the internal address, bypassing the filter. Try this, and more, in our SSRF labs 👇 portswigger.net/web-security/s…
English
0
5
26
1.6K
Eib retweetet
Web Security Academy
Web Security Academy@WebSecAcademy·
Your SSRF filter blocks 127.0.0.1 and localhost. That's okay! Try these: 2130706433 (decimal) 017700000001 (octal) 127.1 (shorthand) 127.0.0.0 (with subnet tricks) 0x7f000001 (hex) They all resolve to localhost. Many blacklists don't catch all of them. Try this technique, and plenty of other SSRF techniques, in our free SSRF labs! portswigger.net/web-security/s…
English
2
10
141
5.6K
Intigriti
Intigriti@intigriti·
Who's your inspiration in the infosec community? Could be a researcher, author, speaker, or even someone from your team, mention them below! 😎
English
35
1
42
7.5K
Eib
Eib@eib_____·
@rez0__ Thank you
English
0
0
0
84
Eib retweetet
YesWeHack ⠵
YesWeHack ⠵@yeswehack·
Still trusting Python built-ins to keep you safe? 👀 This research shows how pitfalls in os.path.join, urljoin, pickle.loads and PyYAML turn simple logic into real vulns like Path Traversal, SSRF and RCE 👇 yeswehack.com/learn-bug-boun…
English
0
4
22
2.2K
Eib retweetet
STÖK ✌️
STÖK ✌️@stokfredrik·
It’s my day off.. And why is it so hard to just do nothing!?
English
11
2
56
5.5K
Eib retweetet
Mastery Quotes
Mastery Quotes@MasteryQuot·
Throughout your life you will encounter tedious situations, and you must cultivate the ability to handle them with discipline.
English
3
17
88
2.3K
Eib retweetet
Illex
Illex@pcuco92·
The Spring Boot Actuators can expose some sensitive informations like env vars, heap dumps, configs, and internal metrics And sometimes, with simple bypass tricks we can find them: actuator/env;.. ;/actuator/env actuator;/env actuator/env%00 actuator/env; ..;/actuator/env static../actuator/env actuator/health/..;/env #bugbounty #bugbountytips #cybersecurity
English
2
38
192
9.4K
Eib retweetet
33 Strategies of War
33 Strategies of War@33StrategiesBot·
Instead of internalizing a bad situation, externalize it and face your enemy. It is the only way out.
English
0
17
126
2.9K
Intigriti
Intigriti@intigriti·
what's your most used bug bounty tool? 😎
English
37
0
65
14.2K
Eib retweetet
33 Strategies of War
33 Strategies of War@33StrategiesBot·
Pick your battles carefully. Danger comes from trying to surpass your limits.
English
1
13
119
3K
Eib retweetet
33 Strategies of War
33 Strategies of War@33StrategiesBot·
In order to separate yourself from the pack, to harness a speed that has devastating force, you must be organized and strategic.
English
0
11
118
2.6K
Eib
Eib@eib_____·
I went after the wrong rabbit hole today 🙃 Just wasted 5 hours 😪
English
0
0
1
8