ทวีตที่ปักหมุด
Eib
808 posts

Eib
@eib_____
The World is Yours # Bug Bounty Blog @ https://t.co/ccm9ey1x1r
เข้าร่วม Ağustos 2024
425 กำลังติดตาม82 ผู้ติดตาม
Eib รีทวีตแล้ว

Your SSRF filter blocks 127.0.0.1 and localhost. That's okay! Try these:
2130706433 (decimal)
017700000001 (octal)
127.1 (shorthand)
127.0.0.0 (with subnet tricks)
0x7f000001 (hex)
They all resolve to localhost. Many blacklists don't catch all of them.
Try this technique, and plenty of other SSRF techniques, in our free SSRF labs! portswigger.net/web-security/s…
English
Eib รีทวีตแล้ว

Conversor from @hackthebox_eu features XSLT injection and os.path.join abuse for file write, and CVE-2024-48990 in needrestart (plus a config GTFObin) for root.
0xdf.gitlab.io/2026/03/21/htb…
English
Eib รีทวีตแล้ว

Still trusting Python built-ins to keep you safe? 👀
This research shows how pitfalls in os.path.join, urljoin, pickle.loads and PyYAML turn simple logic into real vulns like Path Traversal, SSRF and RCE 👇
yeswehack.com/learn-bug-boun…
English
Eib รีทวีตแล้ว
Eib รีทวีตแล้ว
Eib รีทวีตแล้ว

The Spring Boot Actuators can expose some sensitive informations like env vars, heap dumps, configs, and internal metrics
And sometimes, with simple bypass tricks we can find them:
actuator/env;..
;/actuator/env
actuator;/env
actuator/env%00
actuator/env;
..;/actuator/env
static../actuator/env
actuator/health/..;/env
#bugbounty #bugbountytips #cybersecurity
English
Eib รีทวีตแล้ว

I just published a new #article on Medium.
How I Earned $76,000 Bounty From a Single Program on @Bugcrowd .
#BugBounty #Bugcrowd #CyberSecurity #EthicalHacking @Hacker0x01 @yeswehack @intigriti
anonhunter.medium.com/how-i-earned-7…
English
Eib รีทวีตแล้ว
Eib รีทวีตแล้ว
Eib รีทวีตแล้ว

I had this on my backlog for a while, but here it is: an article explaining a vulnerability I discovered with @fattselimi years ago.
medium.com/p/i-found-a-ba…
I hope you learn a thing or two ✌️
happy hacking fam 🫶
English
Eib รีทวีตแล้ว
Eib รีทวีตแล้ว
Eib รีทวีตแล้ว

You can master the Linux fundamentals required for hacking in just 7 hours.
We’ve updated the course with @JohnHammond to include the "big three" of text manipulation and editing: Sed, Awk, and Vim.
2 hours of fresh content are waiting for you.

English
Eib รีทวีตแล้ว

Excited to bring Bug Bounty Village back to BSidesSF with @hackinghub_io and @CaidoIO with @Bugcrowd's support! We'll be hosting some live workshops, hands-on challenges, and a CTF!

English





