KAsh Security

379 posts

KAsh Security banner
KAsh Security

KAsh Security

@KAshSecurity

Cybersecurity | Bug Hunter | CompTIA Security+ | OSCP Loading... | Searching for interesting tools | DM if you know any cool projects, NO sponsorships

Joined Eylül 2021
626 Following399 Followers
KAsh Security retweeted
Will Gates
Will Gates@WllGates·
Bypass open redirection whitelisted using chinese dots: 👀🔓🔍 %E3%80%82 Tip: Keep eyes on SSO redirects 😉🔀 credit: @adrielsec #bugbounty #bugbountytips
Will Gates tweet media
English
2
52
263
15.3K
KAsh Security retweeted
Bug Bounty Insights 🪄
Bug Bounty Insights 🪄@bbr_bug·
Web App pentesting checklist is here.
Bug Bounty Insights 🪄 tweet mediaBug Bounty Insights 🪄 tweet media
English
1
6
48
3.4K
KAsh Security retweeted
Gudetama
Gudetama@gudetama_bf·
SQLi time based from WaybackURLs Part 1 waybackurls testphp.vulnweb.com | grep -E '\bhttps?://\S+?=\S+' | grep -E '\.php|\.asp' | sort -u | sed 's/\(=[^&]*\)/=/g' | tee urls.txt | sort -u -o urls.txt #bugbountytips #bugbounty
Gudetama tweet media
English
2
42
181
11.8K
KAsh Security retweeted
Coffin
Coffin@lostsec_·
POSSIBLE HEADER INJECTION POINT WHERE YOU CAN TEST PAYLOADS :) #BugBounty #bugbountytips
Coffin tweet media
English
3
34
144
7.2K
KAsh Security retweeted
N$🌟
N$🌟@nav1n0x·
Another day, another #SQLInjection. This time, it's in the User-Agent header, leading a full database takeover. Keep testing SQLi on everything and everywhere... #SQL #SQLinjection #BugBounty.
N$🌟 tweet media
English
24
131
937
78.9K
KAsh Security retweeted
Coffin
Coffin@lostsec_·
ADVANCE CRLF INJECTION ;)
Coffin tweet media
English
0
12
87
5K
KAsh Security retweeted
Coffin
Coffin@lostsec_·
BUG HUNTING METHODOLOGY BY COFFIN ;)
Coffin tweet media
English
8
121
540
34.5K
KAsh Security retweeted
Justin Gardner
Justin Gardner@Rhynorater·
I've made over 100k on SSRF vulnerabilities. They aren't always as simple as pointing it at localhost or AWS Metadata service. Here are some tricks I've picked up over the past 5 years of web app testing:
Justin Gardner tweet media
English
45
950
3.3K
449.4K
KAsh Security retweeted
N$🌟
N$🌟@nav1n0x·
I just added an extra property 'is-site-admin':true, and voilà, I became one of the site admins.🤣🤣🤣🤟🤟#bugbounty
N$🌟 tweet media
English
26
95
620
53.9K
KAsh Security retweeted
Américo
Américo@americosmjr·
If your target scope is small: Dive into the main JavaScript files. I spotted an open redirect in just 5 minutes this way, earning just €100 Tools I use: • Hakrawler for extracting JavaScript files. • LinkFinder for endpoint discovery in JS files. Check the links bellow ↓
Américo tweet media
English
12
76
355
24.9K
KAsh Security retweeted
VAIDIK PANDYA
VAIDIK PANDYA@h4x0r_fr34k·
Daily Notes : Day 34 Phone Number Parameter Explotation It's possible to add strings at the end the phone number that could be used to exploit common injections (XSS, SQLi, SSRF etc…. ) Check Link and image Reference: book.hacktricks.xyz/pentesting-web…
VAIDIK PANDYA tweet media
English
1
21
89
9.5K