๐ต๏ธโโ๏ธHere's another secret no one will tell you about: A Simple WAF Bypass for Stored XSS that has earned me $$$$๐ฐ so far!
Stored XSS issues can fetch you rewards ranging from $500 to $7500, depending on the program.
WAFs can pose significant challenges when hunting for Stored
Jayesh Madnani
973 posts
Researcher in charge @ Ethical InfoSec Services | HackerOne Top 10 | hackerone.com/jayesh25
http://hackerone.com/jayesh25
Joined February 2016
- ๐จ Yay, we were rewarded with $20,000 on our @Hacker0x01 submission for a SSRF bug discovered in collaboration with @Shlibness! ๐ฐ๐ ๐ฅณ We uncovered a Critical SSRF vulnerability, turning it into unauthorized access to internal admin endpoints, leading to PII leaks and
- Bug Bounty Tips: Penetration Testing Android/iOS Apps? ๐ฑ Today, I'd like to introduce a valuable open source tool that I frequently rely on: Mobile Security Framework (MobSF), an all-in-one mobile app pen-testing and security assessment tool. It works seamlessly with various
- ๐Secrets no one will share with you - Here's a technique that might grant you access to takeover other users' accounts using "Login with Facebook": Are you working on a target site that supports "Login with Facebook"? Disable email sharing during Facebook login and be ready
- Quick Wins: If you come across an outdated Swagger instance, always remember to test for XSS vulnerabilities. Try these payloads and earn some quick bounties! http://example(.)com/swagger-ui/index.html?configUrl=https://jumpy-floor.surge(.)sh/test.json
- ๐คQuestion of the day: How to Spot CORS Misconfigurations? It is almost year 2024, yet I continue to discover CORS misconfigurations, adding $$$ to my bug bounty earnings each month. Here's my approach to finding CORS Issues: 1๏ธโฃ Nuclei Scan - Identify vulnerable targets with
- Bug Bounty Tips: ๐๐ฐ Here's a simple bug bounty tip for shopping site targets that can earn you some serious $$$$. I've stumbled upon 10+ similar issues on shopping sites that allow guest checkouts ๐. Many overlook these issues because they require placing an order ๐ฆ.
- Hunting on a target with a Salesforce site? ๐ต๏ธโโ๏ธ You're in luck! ๐ There's a high likelihood of stumbling upon a misconfigured object that could yield bounties ranging from $1,000 to $5,000 due to the sensitive nature of the data. ๐ฒ Don't be fooled, many hunters overlook these
- Bug Bounty Tips: Uncover misconfigured Google Drive links, open S3 buckets, Interesting APIs, Secrets, and other sensitive files with JSLuice! ๐ JSLuice is a powerful Go package and command-line tool for extracting URLs, paths, secrets, and intriguing data from JavaScript
- ๐Question of the day: Where to find SSRF Issues? Many overlook testing for SSRF vulnerabilities, thinking they're complex and beyond their capabilities. ๐ป๐ However, these issues can lead to bounties ranging from $1000 to $15000, depending on the Impact. These are the top 5
- ๐Bug Bounty Tips: Using "Waymore" to discover more security Issues๐ In the bug bounty world, having the right tools is essential. While there are many useful ones like waybackurls and gau, let's focus on "waymore" from @xnl_h4ck3r today. It's a handy tool for finding archived
- Bug Bounty Tips: Discovering the Origin IP by scanning your target IP range๐ต๏ธโโ๏ธ When you're hunting on a bug bounty target and WAF stands in your way, here's a powerful technique to uncover the Origin IP by scanning the target's IP range. We'll be using a simple yet effective
- ๐ Bug Bounty Tips: Crawling parameters with Katana for quick XSS/SQLI wins! ๐ When it comes to efficient bug hunting, active crawling can be a game-changer. One of the tools I rely on is Katana, which helps retrieve URLs and parameters for thorough testing against XSS, SQLI,
- ๐ Bug Bounty Tips: Reported 15+ XSS Issues on a broad-scoped program leveraging AEM! ๐ If you stumble upon a target app using AEM, make sure to use these XSS payloads for some quick wins! ๐ฐ 1๏ธโฃ https://target[.]com/1<img src=x data'a'onerror=alert(domain)>.childrenlist.htm














