Got XSS on Jira with os_destination parameter , I checked hundreds of other jira targets(same version) for similar bug , no other targets are vulnerable., very strange.
🚨 1st Giveaway of 2024 🚨
Enter a draw to get a chance to win a 100% OFF COUPON! 🔥
✅ Follow us
✅ Like this post
✅ Share this post
🏆 Winners will be announced in a couple of days.
Good luck! 😀
knoxss.me#KNOXSS#XSS#Bypass
Exciting start to 2024! 🚀 Just rejoined HackerOne and already made an impact - reported 5 vulnerabilities in the last 12 hours, with 3 already triaged! 💻 On a mission to hit that 500 rep points milestone, currently standing at 222 #BugBounty#bugbountytips#bugbountytip ✨
One of the mistakes: "Learning 20 programming languages". True, learning a little bit of everything, but never getting proficient at one thing is concerning.
Me: I'll only focus on Python
10 common mistakes aspiring/new pentesters make by @PentesterLabblog.pentesterlab.com/10-common-mist…
Source code disclosure due to publicly available .git endpoint | P1 vulnerability
Always check for endpoints related to /.git
#bugbountytips#bugbounty#bugbountytip
The SubOver tool says "Takeover Possible At" and when I visit "can-i-take-over-xyz" repo I see that takeover is possible when we see "404 not found" and thats exactly what I am getting on subdomain but I am unable to takeover cant find details
(cont) #bugbountytips
Anybody knows how to exploit this --> CVE-2020-5412 Full-Read SSRF in spring-cloud-netflix-hystrix-dashboard
when i visit --> GET /proxy.stream?origin=http://Burp.net I get my own IP
#bugbounty#bugbountytips#infosec#Help#ssrf#cve