#bugbountytips

2025-12-12

Hey Fediverse. Can you get @zaproxy to 15k โญ๏ธ?

#OpenSource #DAST #AppSec #WebAppSec #ITSec #CyberSec #PenTest #BugBountyTips

Current Stars 14500

github.com/zaproxy/zaproxy

iShowCybersecurity๐Ÿ›ก๏ธishowcybersecurity
2025-10-11

The payload contains '|/???/\b**\h,' which is meant to confuse WAF rules. Unusual characters are a common evasion tactic.

image by: win3zz

2025-09-17

this is your reminder that if you're using Burp for web app testing, you should be using an extension that lets you use variables in your outgoing requests. variables functionality gives you a single place to update credential, token, and identifier values which improves productivity and reduces false positives. there are a few extensions that provide this functionality and I recommend my extension, Burp Variables, which is purpose-built for it: github.com/0xceba/burp_variabl

#burp #burpsuite #burp_suite #pentesting #pentest #bugbounty #bugbountytips #hacking

Anant Shrivastava aka anantshrianant@anantshri.info
2025-08-22

๏ฟผ Introducing KeyChecker โ€“ a CLI to fingerprint SSH private keys & map them to Git hosting accounts.

We have been talking about this in our classes for a long while, finally automation is present now.

๏ฟผ  Blog: https://cyfinoid.com/automating-a-known-weakness-introducing-keychecker/
๏ฟผ PyPI: https://pypi.org/project/keychecker/

#bugbountytips #ssh #git #github #infosec #postexploitation

2025-08-07

Are you located in the US/EU? Passionate about #appsec? Maybe you follow #bugbountytips or are an avid #ctf player and are ready to take the next step. If so, we're looking for our next #intern, so consider applying today - hackers.doyensec.com.
#doyensec #security #internship #bugbounty

Anonymous ๐Ÿˆ๏ธ๐Ÿพโ˜•๐Ÿต๐Ÿด๐Ÿ‡ต๐Ÿ‡ธ :af:youranonriots@kolektiva.social
2025-07-28

Windows Device Names Still Allow Path Traversal in UNC Paths After CVE-2025-27210 Fix
hackerone.com/reports/3255707

#bugbounty #bugbountytips #bugbountytip

Anonymous ๐Ÿˆ๏ธ๐Ÿพโ˜•๐Ÿต๐Ÿด๐Ÿ‡ต๐Ÿ‡ธ :af:youranonriots@kolektiva.social
2025-07-06
2025-06-24

Whatโ€™s your go-to ZAP feature?

๐Ÿค” Is it:
A) Universal โ€œyesโ€ ๐Ÿ˜€
B) Encode/Decode/Hash (scriptable)
C) Fuzzer
D) Scripting
E) API Import
F) Active Scan

๐Ÿ‘‡ Drop your answer + why. Letโ€™s learn from each other. #CyberSecurity #zaproxy #BugBountyTips

Wen Bin :verified:kongwenbin@infosec.exchange
2025-06-10

๐Ÿšจ Want to start learning ethical web hacking for FREE?

๐ŸŽฏ In this video, I break down 3 websites that offer hands-on labs, structured paths, and gamified learning - perfect for beginners in web application penetration testing and bug bounty!

๐ŸŽ“ Hereโ€™s who made the list:

โœ… PortSwigger Web Security Academy
Learn real-world web vulnerabilities with interactive labs

โœ… TryHackMe
Gamified challenges + guided learning paths

โœ… Hack The Box
Academy modules, practice labs & certifications โ€” all linked together

But I didnโ€™t stop at listing them.

๐Ÿ’ก I shared my professional take on:
1๏ธโƒฃ Their unique strengths
2๏ธโƒฃ What makes each platform great for beginners
3๏ธโƒฃ And where they could improve to become even better

This isn't just another list โ€” they are insights from an active bug bounty hunter from Singapore ๐Ÿ‡ธ๐Ÿ‡ฌ๐Ÿ˜Š

๐Ÿ“บ Watch here: youtube.com/watch?v=_LrpMiAD8rg
๐Ÿ“Œ Timestamps and useful links in the video description

๐Ÿ‘‡ Comment your favorite FREE hacking resources โ€” let's share and help each other grow!

#BugBounty #BugBountyTips #CyberSecurity #EthicalHacking #TryHackMe #HackTheBox #PortSwigger

Wen Bin :verified:kongwenbin@infosec.exchange
2025-06-10

๐Ÿ‘‹ If you're into bug bounty or just starting your ethical hacking journey, this might help.

I made a step-by-step video on how to set up Kali Linux on Docker โ€” with a twist:
โœ… Install and run Kali Linux in a Docker container
โœ… Avoid the "it works on my machine" problem
โœ… Create a custom Kali Linux Docker image
โœ… Set up a file share between host and container

๐Ÿ’ก This is my go-to method when I want something lightweight, fast, and repeatable. It's especially helpful if you're mentoring others or creating walkthroughs, since the environment is always consistent.

๐ŸŽฅ Here's the full tutorial: youtube.com/watch?v=JmF628xGk1A

Let me know if you have used Docker in your hacking workflow โ€” or if you have a better setup!

#kali #kalilinux #ethicalhacking #bugbounty #bugbountytips #docker

Wen Bin :verified:kongwenbin@infosec.exchange
2025-05-12

โ“ How can bug bounty programs โ€ฆ
1๏ธโƒฃ Keep hackers engaged in the long term?
2๏ธโƒฃ Effectively increase the amount of good quality reports that you receive?
3๏ธโƒฃ Stand out from competition and be the program that hackers choose to hack on?

๐Ÿ“ฝ๏ธ In this video, I covered 5 tips that can allow any bug bounty programs to stand out from the rest. If you implement them, you can expect an increased participation from skilled and good hackers (or security researchers) and a consistent stream of valuable vulnerability submissions! Most importantly, are you ready to handle the resulting high quality reports? ๐Ÿ˜Š

๐Ÿซต Hackers, if these tips hit the mark, please share them with your favourite bug bounty programs! Your input could lead to improvements like loyalty programs and direct report submissions (skip platform analysts or triage teams). Let's level up the bug bounty landscape together! ๐Ÿ˜Ž

โฌ‡๏ธโฌ‡๏ธโฌ‡๏ธ

youtu.be/msr-7ZtmLdE

#bugbounty #bugbountytips #togetherwehitharder #hackerone #ittakesacrowd #outhackthemall #bugcrowd #bugcrowdtipjar #hackwithintigriti #intigriti #yeswehack #yeswerhackers #ethicalhacking #whitehat

Five tips for boosting long term engagement in your bug bounty program! Check out the video for more information
Tib3rius :antiverified:tib3rius@infosec.exchange
2025-05-11

Quickest way to reliably find business logic flaws is to change your mindset:

You're not looking for bugs, you're hunting for assumptions.

Somewhere out there, a dev assumed no one would ever do *that*. So be the first person to do it.

#bugbountytips #cybersecurity

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst