Dark
57 posts


Just got a reward for a vulnerability submitted on @yeswehack -- Cross-site Scripting (XSS) - DOM (CWE-79). yeswehack.com/hunters/babauca #YesWeRHackers

English

Just got a reward for a vulnerability submitted on @yeswehack -- Cross-site Scripting (XSS) - Reflected (CWE-79).
Waf bypass:
<mctx%2FOnCoNtEnTvIsIbIlItYaUtOsTaTeChAnGe%3Dalert%601%61%09STYLE%3Ddisplay%3Ablock%3Bcontent-visibility%3Aauto>


English

Update:
Now I’m able to trigger an `alert` after bypassing the WAF 😄
This is my first DOM XSS after spending many days learning and practicing. Special thanks to @YShahinzadeh @kobi_hk and all the bug bounty community members who share helpful resources 🙏
#BugBounty #XSS

Ethical Hacker@whithat444
Found a DOM XSS sink via `location.href`. I can redirect to another domain, but I’m not yet able to achieve JavaScript execution. Need help with a bypass. Whoever helps me get successful JS execution gets a 50% bounty split. DM me I’ll share more details.
English

@Jos_eph19 I hate this word “Duplicate” if it reported why they did not fixed it and let us send repeted bugs !
English
Dark retweetledi

Bug bounty hunters are putting AI to work.
Researchers told @WSJ they’re using AI to support everything from recon to analysis and exploitation, with a growing focus on fewer, higher-value findings.
But as Bugcrowd CEO @davegerryjr shared, human insight still plays a critical role in finding deeper, novel vulnerabilities, including “things that people have never seen before.”
Read the full piece: wsj.com/pro/cybersecur…
English

@fattselimi POC is the controler for everything , if the report conatin a good thing send report otherwise find another thing
English

FIRST BOUNTY UNLOCKED 😭🔥
Started my bug bounty journey with a HIGH severity report… still feels unreal 🫡
Months of NA, duplicates, failures & grinding finally paid off 🙏
God’s plan really different sometimes.
@tsxninja200 @defronixacademy @thehacktivator
#bugbounty

English

Stay tuned for upcoming write ups.
😍
#bugbountytips #bugbounty #BugHunters #hackers #hacking #bugcrowd #webtesting

English

@DarkLorSy Yes of course, i always verif every bug claude found manually
English
Dark retweetledi

My first bug bounty after just 1 month from starting learning
Special thank to @0xHun73r @ide9x @hamidonsolo

English
Dark retweetledi

If you found a real bug, and closed as NA/Duplicate/informative and you tried to reach out an got no response, publishing your finding with the users data is not right, remember the goal of working as hunter. We are protecting companies NOT helping blackhats to hack'em.
Move on to another target.
English

A way to start.
got my first submission accepted on @bugcrowd bugcrowd.com/h/{id: "ibrahimwaeel22"} #ItTakesACrowd #bugbounty #cybersecurity #bugcrowd

English










