▪️Part time Bug Bounty hunter
▪️Engineer
▪️Teacher
▪️x.com/saur1n
- Private IP addresses✅
- Normalization of diff. IPv4/IPv6 representations✅
- TOCTOU DNS rebinding✅
- HTTP Redirects✅
But still this little😈 slips through the cracks:
- 0.0.0.0❌
#bugbountytips
- Private IP addresses✅
- Normalization of diff. IPv4/IPv6 representations✅
- TOCTOU DNS rebinding✅
- HTTP Redirects✅
But still this little😈 slips through the cracks:
- 0.0.0.0❌
#bugbountytips
#bugbountytips
#bugbountytips
It just feels right to be around computers and entangled stuff that most of the time, u cannot wrap your head around it, but guess what? That's the beauty of it
It just feels right to be around computers and entangled stuff that most of the time, u cannot wrap your head around it, but guess what? That's the beauty of it
REcollapse aims to find it!
Just give it a URL and it will generate a fuzzing list for all regex pivot positions with all possible bytes %00 to %ff!
Check it 👇
REcollapse aims to find it!
Just give it a URL and it will generate a fuzzing list for all regex pivot positions with all possible bytes %00 to %ff!
Check it 👇
Bug Bounty poem :)
Bug Bounty poem :)
a compact group of five galaxies located in the constellation Hydra. It's a fascinating object for astronomers because these galaxies are in close proximity and interacting with each other.
Processed Hubble data by Dr. Mehmet Hakan Özsaraç.
www.flickr.com/photos/mhozs...
🔭 🧪
a compact group of five galaxies located in the constellation Hydra. It's a fascinating object for astronomers because these galaxies are in close proximity and interacting with each other.
Processed Hubble data by Dr. Mehmet Hakan Özsaraç.
www.flickr.com/photos/mhozs...
🔭 🧪
Welcome to the future - nobody owns anything, and all art and entertainment is disposable, temporary, and lost forever.
Welcome to the future - nobody owns anything, and all art and entertainment is disposable, temporary, and lost forever.
While loading the Burp Suite extension Autorize, it has by default this box checked:
1/n
While loading the Burp Suite extension Autorize, it has by default this box checked:
1/n
Therefore, there is a high chance defenses could be bypassed by entering the evil host after the redirection.
Don't forget 301,308 redir codes ;)
Therefore, there is a high chance defenses could be bypassed by entering the evil host after the redirection.
Don't forget 301,308 redir codes ;)
-Erwin Schrödinger, on quantum entanglement, 1935
-Erwin Schrödinger, on quantum entanglement, 1935