Be5Lmt
19 posts







No quotes No spaces No Parentheses No Semicolons Still SQLi.... Collab with @or4nge16hehe @r9.mody/sql-injection-in-numeric-parameter-int-without-common-special-characters-ae31e15ea3e3?postPublishedType=repub" target="_blank" rel="nofollow noopener">medium.com/@r9.mody/sql-i…
#bugbounty
SQL Injection without these special chars [' "()\/%*&\`] possible? Yep, me and @or4nge16hehe did it. Using only: [ a-z, 0-9, dot, @+- ] Write-up soon #BugBounty #infosec

No quotes No spaces No Parentheses No Semicolons Still SQLi.... Collab with @or4nge16hehe @r9.mody/sql-injection-in-numeric-parameter-int-without-common-special-characters-ae31e15ea3e3?postPublishedType=repub" target="_blank" rel="nofollow noopener">medium.com/@r9.mody/sql-i…
#bugbounty
No quotes No spaces No Parentheses No Semicolons Still SQLi.... Collab with @or4nge16hehe @r9.mody/sql-injection-in-numeric-parameter-int-without-common-special-characters-ae31e15ea3e3?postPublishedType=repub" target="_blank" rel="nofollow noopener">medium.com/@r9.mody/sql-i…
#bugbounty
No quotes No spaces No Parentheses No Semicolons Still SQLi.... Collab with @or4nge16hehe @r9.mody/sql-injection-in-numeric-parameter-int-without-common-special-characters-ae31e15ea3e3?postPublishedType=repub" target="_blank" rel="nofollow noopener">medium.com/@r9.mody/sql-i…
#bugbounty





One-liner command to try 👇 You can test for XSS across all endpoints at once.

🚨🏆 AFCON Final: Morocco vs Senegal! Nigeria have been eliminated by Morocco.







