Video wird geladen...

Video konnte nicht geladen werden

Zur Startseite

I recently found a cool #RCE/path traversal bug on a target in Intigriti. It was rejected because of OoS :( But I am proud that I found this cool bug through a full manual testing of the endpoint. This video just simplifies the steps, but I took hours to...

38,890 Aufrufe • vor 2 Jahren •via X (Twitter)

10 Kommentare

Profilbild von Kanhaiya Sharma 🇮🇳
Kanhaiya Sharma 🇮🇳vor 2 Jahren

`id` `cat%20/etc/passwd` cmdi payloads #bugbountytips

Profilbild von N$
N$vor 2 Jahren

🙏

Profilbild von bugoverflow
bugoverflowvor 2 Jahren

Cool. What is software allow you redact the text :D?

Profilbild von N$
N$vor 2 Jahren

Snagit + CapCut

Profilbild von NOB0dy
NOB0dyvor 2 Jahren

Remind me of a web app I pentested where you could verify if a domain was registered or not. There was a filter in place, and I needed to use domain=example%3b`id`% to bypass it. It was unauth RCE xD the app was already pentested 4 times before me...

Profilbild von Ariff
Ariffvor 2 Jahren

👏 👏 👏

Profilbild von Wip3r
Wip3rvor 2 Jahren

nice job bro 😋

Profilbild von Shakti
Shaktivor 2 Jahren

Congratulation sir

Profilbild von Ayadim
Ayadimvor 2 Jahren

Thank you for sharing bro

Profilbild von st0x_r0
st0x_r0vor 2 Jahren

nice

Ähnliche Videos