Posts

The story of out-of-scope to $2137 dollar bounty in bugcrowd private program πŸ‘Œ

Image
Hello fellow hackers, hope everything is going fine. Today i will talk about "how i found critical idor which leak user critical PII" This was my recent Finding on bugcrowd private program so i can't disclose program name but i will take redacted.com as example. without further ado lets jump to the discussion . Can you ever Imagine a single referer url can give you a critical bugs with P1 bounty? Sounds crazy huh! But this the truth. but how? Ok let me tell you a crazy story about thatπŸ˜‡ During Ead-Ul-Adha cerebration i got some private invite on bugcrowd, there was one fresh on-going program which have wild-card scope but i was little bit late, after one months later i decide to test this so i picked this and start basic recon for try to find low hanging fruits.but in the end nothing touch in my hand. Then i decide to test manually, i fire up my burp proxy and start capturing all request, i create account and analyze all request, But then i got some error while making

How I got my first bounty $800 for a reflected XSS

Image
There are times in a person's life that he isn’t ready for, just as a beginner's bug hunter is not ready for when his first bounty comes in the life of an ethical hacker. Let's start without exaggerating. Let me tell you something about myself, my name is Nirob, I'm just a noob entering this bug bounty world. I don't know why I have been addicted to hacking since I was 15-16 years old but I still don't know what hacking is. Then when I was 16 years old I heard from someone that his Facebook account had been hacked and this is the way to go ... I will Share this story another day. I will do it inshallah. My journey of Bug Bounty Hunting started from December 2020 , then I started the learning and on. February 26, 2021 I started my journey by choosing a target of Bugcrowd, Although I would deface the website through sql, shell upload from 2018 πŸ˜‚πŸ˜‚ just for fun and show offπŸ™„ But when I came to this bug bount y world. that there are many differences between