Prial

390 posts

Prial banner
Prial

Prial

@0xPrial

Cybersecurity Enthusiast | Ethical Hacker | Red Team Member at @SynackRedTeam | Exploring the digital frontier, one vulnerability at a time.

Pabna, Bangladesh Katılım Temmuz 2014
332 Takip Edilen2.8K Takipçiler
Sabitlenmiş Tweet
Prial
Prial@0xPrial·
And this is why I love @synack ❤️
Prial tweet mediaPrial tweet media
English
1
0
55
0
Prial
Prial@0xPrial·
Cyber by night, tactical by day 👌😚
Prial tweet media
English
1
1
34
1.2K
Prial
Prial@0xPrial·
Subdomain takeovers aren't always straightforward! Found an old target with a subdomain pointing to CloudFront, and its Origin Domain was configured with the S3 bucket's website endpoint. Always check beyond CNAME records to avoid missing these. #BugBounty #BugBountyTips
Prial tweet mediaPrial tweet media
English
4
7
67
2.6K
Prial
Prial@0xPrial·
New year gift by me to me 🫠❤️ #BugBounty
Prial tweet mediaPrial tweet mediaPrial tweet media
English
6
0
45
1.6K
Aditya
Aditya@ADITYASHENDE17·
@0xPrial Awesome 🙌 grats
English
1
0
3
321
Prial
Prial@0xPrial·
@VECO_Cebu Yes. You can takeover. You just need a account.
English
0
0
0
93
Rishabh Shrivastava
Rishabh Shrivastava@wickedwickv2·
@0xPrial But, is it possible now to perform a zendesk takeover as it asks for verification.?
English
1
0
2
244
DiMaX
DiMaX@dmxjon·
@0xPrial Congrats, is it now possible to take over a subdomain via zendesk?
English
1
0
1
144
Prial
Prial@0xPrial·
Zendesk Subdomain Takeover + Email routing wildcard setup = Any support@target.com email creates a ticket in my Zendesk setup. #BugBounty #BugBountyTips
Prial tweet media
English
3
5
75
2.8K
Prial
Prial@0xPrial·
@Bugcrowd Is considering In Scope subdomain takeover as a Basic Subdomain takeover which is a similar priority as RXSS. While attacker can do stored XSS using a subdomain takeover which is considered as P2 priority. Why this discrimination @BugcrowdSupport ? #BugBounty
Prial tweet media
English
4
0
20
2.4K
Prial
Prial@0xPrial·
In previous days they considered subdomain takeover with proper PoC as P2 High Impact Subdomain takeover but nowadays all subdomain takeovers are accepted as Basic Subdomain takeover. This is not fair!
Prial tweet media
English
0
0
10
1K
Prial
Prial@0xPrial·
@gdattacker @Hacker0x01 I agree. In such case @Bugcrowd platform have done great work. They show original report title and when it was reported. This maintain good relationship with researchers and I think @Hacker0x01 can do the same with their platform too 😇
English
0
0
1
28
Gaurav Kumar(GDATTACKER)
Gaurav Kumar(GDATTACKER)@gdattacker·
@0xPrial @Hacker0x01 Leadpages but atleast the should add report title or share report in case of subdomain takeover to appreciate transparency. Because in many cases the reports are not same in subdomain takeovers but still get duplicate.
English
1
0
1
192
Prial
Prial@0xPrial·
@shohel_96 @Hacker0x01 I use dig to print the DNS records then look st those records for possible takeovers 😇
English
0
0
0
73
Prial
Prial@0xPrial·
@elh3x @Hacker0x01 Will do detailed writeup on different kind of takeovers 😇
English
1
0
6
454