
Bug Bounty Reports Explained
@gregxsunday
Grzegorz Niedziela - a hacker who documents his hacking journey by creating and curating the best content about bug bounty and offensive security.
ID: 3378488919
https://bbre.dev/premium 16-07-2015 09:19:21
2,2K Tweet
49,49K Followers
613 Following

We (Akamai Security Intelligence Group) often see these CSP bypass attempts. Example for googleapis.com w/OOB beaconing/blind XSS References: cspbypass.com github.com/renniepak/CSPB…



🚨HTTP Request Smuggling in lua-nginx-module!🚨 This affects major proxies like Kong GW, OpenResty, Apache APISIX and many more👀 Check it out: benasin.space/2025/03/18/Ope… Big thanks to James Kettle for his awesome research and for answering all my questions! #bugbounty #bugbountytips


New video out with Jasmin Landry! We break down an SSRF bypass against a validation pattern you’ll definitely see again — and show how to land critical without cloud metadata. Enjoy🔥 youtu.be/uoKMhb6juSo


Tested this app a bunch of times and even saw that API... and still missed it 🥲 Great bug Jasmin Landry!🔥

In this episode, Jasmin Landry breaks down how he consistently lands highs and crits - from SSRFs to less common bugs like XXEs and SQLis. Enjoy🔥 youtu.be/0-o3_NumvbI



Bug Bounty Reports Explained Jasmin Landry I love this podcast, and I especially enjoyed this episode. It's an incredible example of perseverance and fighting for your dreams. You come across as very professional and humble Jasmin Landry I hope to improve and one day meet both of you Bug Bounty Reports Explained 🙌🏼

Second order injections feat. Jasmin Landry #bugbounty #bugbountytips #bugbountyhunter

Using match and replace rules for quickly applying polyglot payloads feat. Jasmin Landry #bugbounty #bugbountytips #bugbountyhunter

I’ve watched this video more than once now in the span of 5 days haha made respect for Jasmin Landry and I appreciate you sharing

SQLi still exists in 2025 feat. Jasmin Landry #bugbounty #bugbountytips #bugbountyhunter

Manipulating referer policy when DOM Purify is used feat. Jasmin Landry #bugbounty #bugbountytips #bugbountyhunter

Bug Bounty Reports Explained Jasmin Landry Was able to replicate this and created a lab that mimics this behavior :) github.com/zylideum/refer…

Ashton created a lab to reproduce the bug I mentioned on Bug Bounty Reports Explained’s podcast 👏. The same bug I also mentioned on Critical Thinking - Bug Bounty Podcast 😃

An ATO that doesn’t make sense feat. Jasmin Landry #bugbounty #bugbountytips #bugbountyhunter