The Bug Bounty Hunter

295 Followers
0 Following
318 Posts

The channel 'The Bug Bounty Hunter' is now on Mastodon.

✉️[email protected]

Webhttps://thebugbountyhunter.com
Telegramhttps://t.me/thebugbountyhunter/
Twitterhttps://twitter.com/tbbhunter

Truffle Security is proud to host a new XSSHunter

https://trufflesecurity.com/blog/xsshunter/

Thank you @[email protected] 👏

Truffle Security is proud to host a new XSSHunter - Truffle Security

Truffle Security is proud to be hosting a new XSSHunter, with new features, with the assistance of it's original creator, Mandatory.

Truffle Security

Security Advisory: Remote Command Execution in binwalk

https://onekey.com/blog/security-advisory-remote-command-execution-in-binwalk/

Security Advisory: Remote Command Execution in binwalk

Learn about the security vulnerability in binwalk v2.1.2b-2.3.2 !

ONEKEY

Account Takeover in Canvas Apps served in Comet due to failure in Cross-Window-Message Origin validation

https://ysamm.com/?p=783

By @[email protected]

Account Takeover in Canvas Apps served in Comet due to failure in Cross-Window-Message Origin validation – Youssef Sammouda

How to Directory Brute Force Properly

https://www.youtube.com/watch?v=Eai_ZXXqafw

How to Directory Brute Force Properly

YouTube
The Anti-Recon Recon Club (using ReconFTW)

Recon is important, but some people hate it. I get it. When you're in the zone and ready to pounce on a target, you just want to start hacking. Want the best of both worlds? Quick/complete recon? Without sacrificing coverage? As an offensive security and testing connoisseur, I love recon. But after talking with many other hackers about their flow, It’s always divided. Others absolutely do not enjoy it at all and are way more comfortable getting on a target as fast as possible. So, for those of

jhaddix.com

DOM-XSS in Instant Games due to improper verification of supplied URLs

https://ysamm.com/?p=779

By @[email protected]

DOM-XSS in Instant Games due to improper verification of supplied URLs – Youssef Sammouda

ATO in Canvas Games due to weak cross window message Origin validations ($62,500)
http://ysamm.com/?p=783
Account Takeover in Canvas Apps served in Comet due to failure in Cross-Window-Message Origin validation – Youssef Sammouda

DOM-XSS in Instant Games due to improper verifications ($62,500?)
http://ysamm.com/?p=779
DOM-XSS in Instant Games due to improper verification of supplied URLs – Youssef Sammouda

The 100+ Million Person Data Disclosure

Or, That time I hacked a whole country by accident! I have done consulting gigs all over the world for security testing, and I frequently travel to speak at international conferences. Here’s a story about how I found a vulnerability that could have allowed me to steal the private information of over 100+ MILLION people. This is by far the biggest (in the number of people impacted) hack I’ve ever done… and it wasn’t even for work. Not too long ago I was planning on traveling out of the states for

jhaddix.com
Research | Bypass CSRF Protection w/ XSS - Abdelrhman Allam (sl4x0) - Medium

💡 Most often, this problem is found in the search box, regardless if the files are sent using POST, or send by GET, the return message will be something like: “You searched for ’test’ “ What makes…

Medium