![Paradox hunt (N.u) Profile](https://pbs.twimg.com/profile_images/1850025897765552128/QgQMN1J2_x96.jpg)
Paradox hunt (N.u)
@hunt_n27493
Followers
61
Following
135
Statuses
347
HI GUYS This is Paradox i am self taught learner and hunter preparing my self for purple team and malware dev with python currently doing bug hunting
Joined July 2024
Hey guys i got hall of fame me=Darknight21 am hunting more to break some more cool stuffs thanks to all @zseano @shubhamtiwari_r @shreyas_chavhan @0xblackbird @JR0ch17 @krishnsec @Rhynorater @techycodec08 @Yaseen11211 @coffinxp7 @ReebootToInit5 and everyone keep hunting π
0
0
5
@0xJin am not saying that don't post but atleast give some legit things not these cause this one = getting fame for useless things i hope you got me ππ©΅
0
0
1
Hey guys another tip for ssrf have a look π stay tune will upload more soon
πQuestion of the day: Where to find SSRF Issues? Many overlook testing for SSRF vulnerabilities, thinking they're complex and beyond their capabilities. π»π However, these issues can lead to bounties ranging from $1000 to $15000, depending on the Impact. These are the top 5 obvious features I look for in a target app to find SSRF Issues: 1οΈβ£ Export to PDF - Does your target app support generating PDFs? π Try injecting HTML into the content that is used for generating that PDF. If vulnerable to HTML injection, you might strike gold by injecting HTML/JS.π° 2οΈβ£ Integrations - If your target app supports web hook Integration feature, replace the URL with your Burp Collab and wait for a hit. π 3οΈβ£ Import via link Feature - Does your target app support importing files or websites via a link? π₯ Specify your attacker Burp Collab and check for a hit, especially when uploading profile pictures or media through a library. 4οΈβ£ Host Header - Test for Routing-based SSRF by supplying your Collaborator server domain in the Host header. If you receive a DNS lookup from the target server, you might be able to route requests to arbitrary domainsπ 5οΈβ£ File Upload - Does your target app support uploading files? π Try uploading an HTML file; if rendered and executed on the server-side, you might strike gold. No luck? Try an SVG with SSRF payload. If that fails, move on to the next! None of the above methods worked? Don't worry; we have more tricks up our sleeves, and we'll be sharing them soon! π§ββοΈ Takeaways: Note these features, and if you encounter them in your target app, don't forget to test for SSRF Issues. Who doesn't love some free money while securing the planet? Stay tuned for more! πΈπ #cybersecurity #bugbountytips #securitytips #bugcrowd #hackerone #tips #bounty
0
0
0
@sw33tLie old is gold bro web2 is better then web3 i agree that it's also best but don't go on web3 until you have not done work on web2 very betterly it's a total time waste π
0
0
2
@Masonhck3571 @Blaklis_ oh bro this was insane π
hope you handle them betterly well what happen if tal bugcrowd will get these type of reports ππ»πΊ
0
0
0
Hey guys if you all are looking for instagram osint use this one its better not so much but it works π stay tune will upload more soon #OSINT
#CyberSecurity
0
1
1
@krishnsec @Bugcrowd @ReebootToInit5 @RootxRavi @3ncryptSaan @starkcharry collaboration is also good but at the end solo leveling is awesome makes you more sharper and better collab is good to learn differ mindset and things everyone has it's own choice for me Solo= 80% and collab=20% π
0
0
1
Hey guys i got hall of fame me=Darknight21 am enhancing my skill to break more big achievments thanks to all @zseano @shubhamtiwari_r @shreyas_chavhan @0xblackbird @JR0ch17 @krishnsec @Rhynorater @techycodec08 @Yaseen11211 @coffinxp7 and everyone am improving moreπkeep hunting
0
0
3
@rirepra @GodfatherOrwa @OrwaGodfather yeah he is talking about fuzzing all the subdomains and the line he said that use the same keyword on every sub-domains you might get lucky π
0
0
0