Bounty Security

752 posts

Bounty Security banner
Bounty Security

Bounty Security

@BountySecurity

Offensive Web Application Security Software

เข้าร่วม Mayıs 2018
9.7K กำลังติดตาม19.1K ผู้ติดตาม
ทวีตที่ปักหมุด
Bounty Security
Bounty Security@BountySecurity·
Burp Bounty Pro v3.1.0 is out. New: AI Scanner. Sends each request to an LLM with structured context extracted from the response. The AI decides which profiles to launch automatically. A new option alongside Active Scan and Smart Scan, not a replacement.
Bounty Security tweet media
English
2
24
131
10.2K
Bounty Security
Bounty Security@BountySecurity·
👉 New on the blog: Programmatic Scanners in the Age of AI Agents Where AI actually fits in vulnerability scanning and where it doesn't. Cost, speed, reproducibility, hallucinations, and why the hybrid model makes sense today. bountysecurity.ai/blogs/news/pro…
English
0
0
3
443
Bounty Security
Bounty Security@BountySecurity·
@Ramtic233 Hi @john! thanks for your following, in next versión we will fix these issues. Now, you can specify new headers and cookies before you send the urls to scan, with match and replace feature. If you need more information, please let me know.
English
1
0
0
32
John
John@Ramtic233·
@BountySecurity Unfortunately, in the new version, the issues I reported regarding matchtype's content-length and content-length-diff remain unresolved
English
1
0
1
53
Bounty Security
Bounty Security@BountySecurity·
Burp Bounty Pro v3.1.0 is out. New: AI Scanner. Sends each request to an LLM with structured context extracted from the response. The AI decides which profiles to launch automatically. A new option alongside Active Scan and Smart Scan, not a replacement.
Bounty Security tweet media
English
2
24
131
10.2K
eli ♱ 𓆩♡𓆪
eli ♱ 𓆩♡𓆪@adoringthestars·
@BountySecurity Hello. I received the free key from the survey but when I try to activate it it says it’s invalid. I sent an email a week ago and no response.
English
1
0
0
23
Bounty Security
Bounty Security@BountySecurity·
Monday: the biggest update to Burp Bounty Pro since v3.0.0 → A new scanning option that picks its own targets → Everything else stays exactly the same → Full blog post explaining the thinking behind it bountysecurity.ai/pages/burp-bou…
English
1
0
5
616
Bounty Security
Bounty Security@BountySecurity·
A single quote returning 500 doesn't prove SQL injection. Could be anything. But single quote → 500, double quote → 200, triple quote → 500? That's a pattern. Multi-step profiles in Burp Bounty Pro let you chain these checks into one scan. Each step: own payload, own match.
Bounty Security tweet media
English
1
0
26
1.4K
Bounty Security
Bounty Security@BountySecurity·
🏆 Burp Bounty Lab is now officially listed in the @owasp Vulnerable Web Applications Directory. One week after launch. 🙌 100+ vulnerable endpoints. Free. Open source. 👉 burpbountylab.com 📋 #burp-bounty-lab" target="_blank" rel="nofollow noopener">vwad.owasp.org/app/#burp-boun… #BugBounty #OWASP #Pentesting
Bounty Security tweet media
English
2
41
218
9.6K
Bounty Security
Bounty Security@BountySecurity·
These results come from ⚡ 📦 254 default vulnerability profiles 🧠 27 Smart Scan IF-THEN rules 🔗 Multi-step scanning ⏱ Time-based blind detection 🎯 30+ insertion point types Skills + automation = impact 💪🔥 👉 bountysecurity.ai/pages/burp-bou…
English
0
1
4
755
Bounty Security
Bounty Security@BountySecurity·
🐛 We asked Burp Bounty Pro users: what's your best find? 🔴 Path traversal → server takeover 💀 🔴 SQLi → RCE chain 💉 🔴 Chained SSRF 🌐 🔴 HTTP Request Smuggling 📡 🔴 CVE-2021-41773 in prod 🐛 🔴 £5,000 bounty 💰 Real bugs. Real users. 🔥 Yours? 👇 #BurpBounty
Bounty Security tweet media
English
1
17
135
7.6K
Bounty Security
Bounty Security@BountySecurity·
🎯 27 rules. Zero manual work. 🛠 You can also build your own rules: IF → passive profile matches [condition] THEN → execute [active profiles] Your scanner adapts to the target automatically. Right-click → Smart Scan → done ✅ 👉 bountysecurity.ai/pages/burp-bou…
English
0
0
1
361
Bounty Security
Bounty Security@BountySecurity·
🧠 Smart Scan in Burp Bounty Pro: 👁 Passive profile detects a technology 📋 Rule condition matches 🎯 Active profiles fire automatically WordPress detected? → WP CVE profiles 🔥 SQLi params found? → SQLi payloads only 💉 Spring Boot spotted? → Spring checks ⚡
Bounty Security tweet media
English
1
7
49
3K
Bounty Security
Bounty Security@BountySecurity·
I built a deliberately vulnerable web app so you can test your Burp Bounty Pro profiles against real vulnerabilities. 100+ endpoints. XSS, SQLi, SSRF, SSTI, 42 CVEs, GraphQL... It's live and free. Go break it 👇 🔗 burpbountylab.com #BugBounty #Pentesting #BurpSuite
Bounty Security tweet media
English
7
57
221
10.4K