Ресурсы Bugbounty • Советы • Журналы по безопасности • Рецензии • Обновления об уязвимостях • Заметки • Интеллектуальные карты • Шпаргалки • Контрольные списки • Статьи/блоги • PDF-файлы • Электронные книги •
This channel is part of the discussion
Bug Bounty appears in 3 event pages on TGList"I'm going to bed. Keep hunting. Don't stop until 8am. If you're about to summarise, pause, check the time, and if it's not 8am, don't stop." Claude did bug bounty hunt through the night. Woke up with Claude findings & he deleted test acc for IDOR 🤩
I analysed 313 disclosed SSRF reports from HackerOne. 5 patterns repeat in almost every report. Two different chains lead to full RCE. I turned it into a testing framework you can run on every endpoint. Full breakdown on Medium:
Android bug bounty tips APK unpacking Never assume API keys or endpoints are hidden just because they are inside a mobile application. Use apktool to unpack the APK and then use grep (Linux) or ag (Silver Searcher) to find sensitive strings: #bugbountytips