Sabitlenmiş Tweet
Prial
390 posts

Prial
@0xPrial
Cybersecurity Enthusiast | Ethical Hacker | Red Team Member at @SynackRedTeam | Exploring the digital frontier, one vulnerability at a time.
Pabna, Bangladesh Katılım Temmuz 2014
332 Takip Edilen2.8K Takipçiler

Hunter x Nepal => @imranHudaA @araselmir @L3onid1s @MdInjamulHaqu @tamjid0x01 @0x0asif @RirRipon @akbar_ohi @ShoponAlom2014
Indonesia

Subdomain takeovers aren't always straightforward! Found an old target with a subdomain pointing to CloudFront, and its Origin Domain was configured with the S3 bucket's website endpoint. Always check beyond CNAME records to avoid missing these. #BugBounty #BugBountyTips


English

@0xPrial But, is it possible now to perform a zendesk takeover as it asks for verification.?
English

Zendesk Takeover for fun and profit 😇
0xprial.com/the-art-of-zen…
#BugBounty
#BugBountyTips
#TogetherWeHitHarder
English

Zendesk Subdomain Takeover + Email routing wildcard setup = Any support@target.com email creates a ticket in my Zendesk setup.
#BugBounty
#BugBountyTips

English

@0xPrial @Bugcrowd @BugcrowdSupport Can you guide me for subdomain takeover?? I am stuck and ii am not getting solution or answer of my question. Can I ask you
English

@Bugcrowd Is considering In Scope subdomain takeover as a Basic Subdomain takeover which is a similar priority as RXSS. While attacker can do stored XSS using a subdomain takeover which is considered as P2 priority. Why this discrimination @BugcrowdSupport ?
#BugBounty

English

@gdattacker @Hacker0x01 I agree. In such case @Bugcrowd platform have done great work. They show original report title and when it was reported. This maintain good relationship with researchers and I think @Hacker0x01 can do the same with their platform too 😇
English

@0xPrial @Hacker0x01 Leadpages but atleast the should add report title or share report in case of subdomain takeover to appreciate transparency. Because in many cases the reports are not same in subdomain takeovers but still get duplicate.
English

I earned $2,000 for Subdomain takeover report on @Hacker0x01 ❤️
Tips: Always look at CNAME domain’s historical data 😉
#BugBounty
#bugbountytips
#TogetherWeHitHarder

English

@shohel_96 @Hacker0x01 I use dig to print the DNS records then look st those records for possible takeovers 😇
English

I earned $2,000 for Subdomain takeover report on @Hacker0x01 ❤️
Tips: Always look for CNAME records with NXDOMAIN status 😉
#BugBounty
#bugbountytips
#TogetherWeHitHarder

English

@elh3x @Hacker0x01 Will do detailed writeup on different kind of takeovers 😇
English











