Daily Writeups
3.88K subscribers
4 photos
134K links
Daily Bug Bounty / Cybersecurity Writeups
Source Code : https://github.com/Spix0r/writeup-miner
Download Telegram
⤷ Title: Learning CORS the Right Way: Understanding the Browser Before the Attack
════════════════════════
𐀪 Author: Anandhu Kannan
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 18:12:31 GMT
════════════════════════
⌗ Tags: #portswigger #ethical_hacking #javascript #bug_bounty #cors
⤷ Title: Shai-Hulud npm Worm Compromises Supply Chain
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 14:20:36 +0000
════════════════════════
⌗ Tags: #Malware #cybersecurity #JavaScript #malware #npm #Shai_Hulud #supply chain attack
⤷ Title: The Premium Feature That Was Only One API Request Away
════════════════════════
𐀪 Author: L0Ay
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 17:37:36 GMT
════════════════════════
⌗ Tags: #javascript #penetration_testing #bug_bounty_writeup #bug_bounty #bug_bounty_tips
⤷ Title: WebGPU: Hacking 101
════════════════════════
𐀪 Author: Pratik Sharma
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 20:49:13 GMT
════════════════════════
⌗ Tags: #javascript #programming #security #hacking
⤷ Title: DOM XSS using web messages
════════════════════════
𐀪 Author: Mubin mujawar
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 10:51:46 GMT
════════════════════════
⌗ Tags: #cybersecurity #xss_vulnerability #portswigger #javascript #web_security
⤷ Title: How a JavaScript file led me to an Admin Access
════════════════════════
𐀪 Author: Said-Abbosxon Nabijonov | 0trc
════════════════════════
ⴵ Time: Tue, 11 Aug 2026 09:05:14 GMT
════════════════════════
⌗ Tags: #penetration_testing #cybersecurity #infosec #pentesting #javascript
Forwarded from Bug Bounty Diary
✎ Extract & Download All JavaScript Files for Recon

For modern web apps, scraping <script> tags or relying on Burp's Site Map often isn't enough. Why? Because applications may dynamically load JavaScript from CDNs, cross-origin domains, specific routes (Lazy Loading), or after user interactions.

My Approach:
1. Open DevTools → Network
2. Enable Preserve log
3. Crawl the target and visit relevant pages/features
4. Interact with the application to trigger dynamic resources
5. Export the traffic as a HAR
6. Extract all JavaScript files from .HAR file using unhar (I'll talk about it in the next post.)

#bugbounty #javascript #recon
© t.iss.one/BugBounty_Diary
❤1
Forwarded from Bug Bounty Diary
✎ Unhar - Extract, Unminify, Beautify Javascript files from .Har file

In the previous post, I explained my approach to capturing and downloading a website’s JavaScript resources into a .HAR file for further local analysis. Now, let’s take it a step further with unhar and process that HAR files.

unhar turns a raw .HAR file into a structured set of web assets for local analysis. It extracts unique JavaScript and HTML resources while preserving the original URL structure, fetches available source maps, beautifies/unminifies JavaScript, and extracts inline scripts from HTML pages.

In short: HAR → Extract → Source Maps → Beautify → Ready for Analysis

● Installation
git clone https://github.com/Spix0r/unhar
cd unhar


● Usage
# custom output directory
python3 unhar.py site.har --output folder

# skip source map fetching
python3 unhar.py site.har --no-srcmap

# skip beautify
python3 unhar.py site.har --no-beautify


• Repository: Github

#bugbounty #javascript #recon
© t.iss.one/BugBounty_Diary
⤷ Title: JAVA SCRIPT DEOBFUSCATION
════════════════════════
𐀪 Author: Hassan Saif
════════════════════════
ⴵ Time: Mon, 31 Aug 2026 16:33:55 GMT
════════════════════════
⌗ Tags: #js_deobfuscation_walk_thr #hackthebox_writeup #js_deobfuscation #javascript #hackthebox
⤷ Title: Systematic JavaScript Reconnaissance
════════════════════════
𐀪 Author: Taoqui
════════════════════════
ⴵ Time: Thu, 03 Sep 2026 14:54:34 GMT
════════════════════════
⌗ Tags: #javascript #bug_bounty #infosec #reconnaissance #cybersecurity