Davar

41 posts

Davar banner
Davar

Davar

@dvrahmr

Bug Bounty Hunter

Katılım Mart 2022
585 Takip Edilen550 Takipçiler
Davar
Davar@dvrahmr·
The program had two separate double-bounty promotions. It turned out that this bug was eligible for both of them. So they quadrupled my bounty!
Davar tweet media
English
1
1
11
2.2K
Vivek Ramachandran
Vivek Ramachandran@vivekramac·
Any recommendations for a good Bug Bounty management website? I feel Hackerone, Bugcrowd, etc., have a very high setup fee which does make sense for startups. Are there any vendors who have a more pay-when-bug-found pricing? or a very small setup fee (< USD 1K)?
English
27
13
68
22.2K
Davar
Davar@dvrahmr·
SQLMap could not detect this injection while I knew the endpoint was vulnerable. I had heard about Ghauri. I decided to give it a shot; It worked like a charm. #BugBounty #bugbountytips #sqli
Davar tweet media
English
12
37
348
28K
zseano
zseano@zseano·
burp 1.7 was the best version
English
41
15
376
159.4K
Deepak bug_vs_me
Deepak bug_vs_me@bug_vs_me·
Thanks to bug bounty community! 2022 was good, but 2023 would be better New year New opportunities Just live it! Happy new year to all 🎇 #HappyNewYear2023 #BugBounty
English
4
2
45
3.9K
Davar
Davar@dvrahmr·
@DangerEnd3 I am not sure about their disclosure policy, so I prefer to be cautious here. I'm looking forward to get their permission to publish a write-up about it.
English
1
0
1
0
Davar
Davar@dvrahmr·
In November, I found 20 XSS vulnerabilities from a single application, all of which were accepted, and most of them led to the victim's account being taken over.
Davar tweet media
English
16
26
261
0
Davar
Davar@dvrahmr·
@basmatal3t Thanks! I do manually most of the time.
English
0
0
1
0
Davar
Davar@dvrahmr·
@_Aniket_Akhade_ For Reflected I start with filtering out requests that have reflective parameters with text/html content-type in response. There are tons of tools for that. For Stored I do everything manually as it relies on where you can get the injected payload executed.
English
0
0
1
0
Aniket Akhade
Aniket Akhade@_Aniket_Akhade_·
@dvrahmr How you automate your testing flow? For rxss or for anything?
English
1
0
1
0
Davar
Davar@dvrahmr·
@bug_vs_me Thanks brother. The fetch() function in javascript can sometimes do the job. You can call it in your payload to issue an authenticated request on behalf of the victim.
English
2
2
23
0
Deepak bug_vs_me
Deepak bug_vs_me@bug_vs_me·
@dvrahmr Wow great 🙈, any tip for XSS to account takeover when cookies were http only?
English
1
2
13
0
Deepak bug_vs_me
Deepak bug_vs_me@bug_vs_me·
Today i found xss on a private program on @Hacker0x01 So xss only trigger on Mobile browser and not on windows browser because of some windows size issue if i resize windows to 120% xss execute But on Android browser (all) it execute without any user interaction,
English
6
3
76
0
Davar
Davar@dvrahmr·
@inspectiv Great job! USDT payment for the next feature would be awesome.
English
0
0
1
0
Davar
Davar@dvrahmr·
I am working on this BBP and it turns out all the requests (hundreds) are vulnerable to CSRF. Here is how: -All requests have anti-csrf header but it does not get validated server-side, as you can remove the header and still get response from the server. 🧵1/2 #bugbountytips
English
4
12
36
0
Davar
Davar@dvrahmr·
-Change the content-type header value from "application/json" to "application/x-www-form-urlencoded". -Change the format of the body parameters from JSON to regular parameters: {"p1":"v1",} ==> p1=v1& -Create CSRF PoC using Burp Suite CSRF Generator. Done. #BugBounty
English
1
2
15
0