We just dove into our shelf of archived bug bounty write-ups from the most notable hackers! 🤠 In this issue, we selected 5 compelling articles (that are still relevant today) to share with you, from which you can learn something new! 😎 🧵 👇
1️⃣ The Ticket Hack: Free travel by hacking the Chennai Metro Rail. Manav shares his story of finding a bug in Chennai Metro Rail's booking system, allowing him to get free rides! https://infosecwriteups.com/th...
2️⃣ @Th3G3nt3lman Shares His Recon Methodology and How He Consistently Collects $15,000 Bounties! Although not an article, this hacker interview will stay forever useful. In this 1h+ video, @Th3G3nt3lman shows how he consistently scores 5-digit bounties with recon!
@Th3G3nt3lman 3️⃣ The Tricky XSS Smaran documents his way of exploiting a tricky cross-site scripting vulnerability with a max 20-character limit. https://smaranchand.com.np/202...
@Th3G3nt3lman 4️⃣ XXE-scape through the front door: circumventing the firewall with HTTP request smuggling XXE vulnerabilities are still present in modern web apps... they're just tricky to exploit! Pieter shows how he weaponized an HTTP request smuggling vulnerability to evade a WAF and
@Th3G3nt3lman 5️⃣ Write-up: AWS Document Signing Security Control Bypass Ozgur shares a cool way of abusing application logic to bypass AWS Document Signing! https://ozguralp.medium.com/wr...
@Th3G3nt3lman That was it! We hope you've learned something new (and enjoyed) this thread! If you have enjoyed this thread: 1. Follow us @INTIGRITI for more of these threads! 🐛 2. Retweet the first Tweet to share it with your friends 💙
@intigriti Niice
Once you start treating bug bounty like a business, everything changes. It’s not a side gig. it’s your craft, your company. Show up every day like it’s your business, because it is. 💼
Use NextJS? Recon ✨ A quick way to find "all" paths for Next.js websites: DevTools->Console console.log(__BUILD_MANIFEST.sortedPages) javascript:console.log(__BUILD_MANIFEST.sortedPages.join('\n')); Cred = https://www.linkedin.com/in/0x... #infosec #cybersec #bugbountytips
Unlock hidden treasures in your recon! Add crm/config.ini to your wordlists—you’d be surprised at the sensitive info misconfigured INI files can leak. Happy hunting! 😏 #bugbountytips #bugbountytip #cybersecurity #ethicalhacking
Account takeover via OTP bypass (*code parameter payloads) New video with is out too! https://youtu.be/wHal3vnj12E #bugbounty






