Web appOpen in Telegram
BBug bounty Tips

Bug bounty Tips

@bugbounty_tech · channel · Tech · indexed since 2026-04-17
7 241subscribers+217 in a week
861average post reach
11.9%ER — reach to subscribers
73posts in 30 days
friendly me
File
The Top Hacker Methodologies.pdf · 592 KB · click to show
File
Bug Bounty Beginner's.pdf · 188 KB · click to show
Photo
click to show
File
common_security_issues_in_financially_orientated_web_applica · 654 KB · click to show
Photo
click to show
Photo
click to show
File
JWT Token Pentesting.pdf · 142 KB · click to show
File
BROKEN AUTHENTICATION.pdf · 814 KB · click to show
File
ATM Security Assessment Checklist.xlsx · 14 KB · click to show
File
Shodan_for_Pentesting_1718863899.pdf · 13.1 MB · click to show
Roadmap for Bug Bounty
19 · 1.6K ·
friendly me
🐛 Bug Bounty Writeup Bug Bounty শুরু করার আগে যা বুঝতে হবে: https://medium.com/@cyber.mehedi.13/bug-bounty-%E0%A6%B6%E0%A7%81%E0%A6%B0%E0%A7%81-%E0%A6%95%E0%A6%B0%E0%A6%BE%E0%A6%B0-%E0%A6%86%E0%A6%97%E0%A7%87-%E0%A6%AF%E0%A6%BE-%E0%A6%AC%E0%A7%81%E0%A6%9D%E0%A6%A4%E0%A7%87-%E0%A6%B9%E0%A6%AC%E0%A7%87-c53ab87a911b The Bug Bounty Blindspot: Why Crowdsourced Triage Leaves You More Exposed (and Costs You More) Than…: https://cyphernova1337.medium.com/the-bug-bounty-blindspot-why-crowdsourced-triage-leaves-you-more-exposed-and-costs-you-more-than-f08ba0981492 How I Went from Zero Experience to Finding Valid Bugs on HackerOne: https://medium.com/@tomsayers88/how-i-went-from-zero-experience-to-finding-valid-bugs-on-hackerone-5c4edc9b8bc0 Insecure Authorization on *** Android — mobile application: https://medium.com/@jokodfir/insecure-authorization-on-android-mobile-application-89472e4f468b 52 Request Smuggling Reports. Two Rules Decide the Payout.: https://infosecwriteups.com/52-request-smuggling-reports-two-rules-decide-the-payout-901479562df9 Apps SDK sandbox escape: *** App reaches native window.Android/window.AndroidBridge: https://medium.com/@jokodfir/apps-sdk-sandbox-escape-app-reaches-native-window-android-window-androidbridge-de7ef00e4bc3 Roboto Sans — picoCTF Write-up | Finding a Hidden File Through robots.txt and Base64: https://medium.com/@affanhaxor/roboto-sans-picoctf-write-up-finding-a-hidden-file-through-robots-txt-and-base64-6dd177498bd1 20 AI Red Teaming Techniques Every Security Professional Should Learn (Step-by-Step Guide): https://medium.com/@verylazytech/20-ai-red-teaming-techniques-every-security-professional-should-learn-step-by-step-guide-10ce49cd57ec Top 5 Bugs That Still Pay in 2026: https://sukhveersingh97997.medium.com/top-5-bugs-that-still-pay-in-2026-20fa296a212d
9 · 815 ·
F
🐛 Bug Bounty Writeup httpx: A Deep Dive Into the HTTP Probing Engine: https://pwnxotus.medium.com/httpx-a-deep-dive-into-the-http-probing-engine-359f29662b24 npm Just Fixed Supply Chain Attacks. Then Someone Found a Loophole in 3 Weeks.: https://medium.com/@riyalimba/npm-just-fixed-supply-chain-attacks-then-someone-found-a-loophole-in-3-weeks-aeb51acc529a Choosing the Right Bug Bounty Platform: HackerOne vs Bugcrowd vs Intigriti: https://sukhveersingh97997.medium.com/choosing-the-right-bug-bounty-platform-hackerone-vs-bugcrowd-vs-intigriti-4dfd3c4171ab When "We Added an Allowlist" Doesn’t Mean What You Think It Means: https://medium.com/@joashraf2005/when-we-added-an-allowlist-doesnt-mean-what-you-think-it-means-c2d7d9b09e01 Windows 11’s “Checking for Updates” Freeze Isn’t a Bug. It’s These 3 Things.: https://medium.com/@rama.geek/windows-11s-checking-for-updates-freeze-isn-t-a-bug-it-s-these-3-things-ca7f7be3ab37 Unauthenticated Email Injection: Turning a Transactional Email Endpoint into a Phishing Delivery…: https://medium.com/@redhunter01/unauthenticated-email-injection-turning-a-transactional-email-endpoint-into-a-phishing-delivery-cefcfe7e39ab Power Cookie — picoCTF Write-up | Privilege Escalation Through Cookie Manipulation: https://medium.com/@affanhaxor/power-cookie-picoctf-write-up-privilege-escalation-through-cookie-manipulation-5124ae513fdf 100 Days of Bug Bounty — Day 3: https://zubairahm3d.medium.com/100-days-of-bug-bounty-day-3-93d24bf37659 From Admin to Owner: How I Discovered a Critical Full Organization Takeover: https://medium.com/@ankitrathva/from-admin-to-owner-how-i-discovered-a-critical-full-organization-takeover-610a1aa013a7 I Verified One Email and Claimed Another’s Invitation: https://scriptjacker.medium.com/i-verified-one-email-and-claimed-anothers-invitation-5c372c83ba77
10 · 922 ·
friendly me
#tools #DFIR #Blue_Team_Techniques OmniTriage - zero-dependency, sub-second Windows live digital forensics and incident response triage engine for rapid USB responders // Python standard library only
7 · 572 ·
#Analytics #Threat_Research An analytical review of the main cybersecurity events (Sep 19-26, 2026) 1⃣ Simple MacOS Docker Escape // CVE-2026-77179 2⃣ Brevo ClickFix Compromise // malicious "ClickFix" script served via Brevo's Cloudflare account 3⃣ LastPass (and other) lookalike GitHub Repo and Kernel Module Infostealer 4⃣ How One Twitch Chat Message Became Code Execution on a Streamer’s PC // Target: OBS Studio 32.2.2 on an updated Windows 11 5⃣ macOS MacSync Malware Update // The new version of the MacSync infostealer differs quite significantly from its previously variants 6⃣ Send GitLab an email, push to main 7⃣ F5 Big-IP Vulnerability Details CVE-2026-94127 8⃣ Deterministic Cryptographic Network Covert Channel & Shannon Entropy Leak Detector 9⃣ Malicious Firefox Extension [Yet Another] 🔟 Bypassing EDR with Local AI // How hard is it to bypass EDR in the modern times with AI? As it turns out, not very hard..
8 · 620 ·
File
Ultimate_Kali_Linux_Book.pdf · 28.7 MB · click to show
#Tech_book #Offensive_security "The Ultimate Kali Linux Book, Third Edition: Harness Nmap, Metasploit, Aircrack-ng, and Empire for cutting-edge pentesting", 2024. ]-> Repo
15 · 713 ·
File
DSec.pdf · 768 KB · click to show
#MLSecOps "DeepSeek Elastic Compute (DSec): A Sandbox Infrastructure for Effective Agentic Training at Scale", Sep 2026. // This report presents DeepSeek Elastic Compute (DSec), a production sandbox platform that exposes FnCall, container, microVM, and full-VM sandbox backends through a unified SDK
15 · 693 ·
F
File
Advanced SQL Injection Techniques by nav1n0x.pdf · 1.0 MB · click to show
23 · 701 ·
🐛 Bug Bounty Writeup How I Got Into Cybersecurity — My Roadmap: https://medium.com/@sairajthorat077/how-i-got-into-cybersecurity-my-roadmap-a1d516eaa5f2 The Forgotten Bucket: How a 404 Became a High-Severity Subdomain Takeover: https://0xkrishn.medium.com/the-forgotten-bucket-how-a-404-became-a-high-severity-subdomain-takeover-739a0c4e5cab The Illusion of Instant Block: https://medium.com/@yosefmostef99/the-illusion-of-instant-block-4620220283f9 Telegram Desktop: From Proxy to RCE in 35 Seconds: https://medium.com/@expatch/telegram-desktop-from-proxy-to-rce-in-35-seconds-64de025fb0b4 Fake Ledger Update Email! DON’T Click This Button — Here’s How I Exposed It: https://medium.com/@pentesterclubpvtltd/fake-ledger-update-email-dont-click-this-button-here-s-how-i-exposed-it-536e43f1f749 Advanced Web Pentesting — Attack Techniques Cheat Sheet: https://mohamedalgabry.medium.com/advanced-web-pentesting-attack-techniques-cheat-sheet-cbf6dc365393 $17,000 for Walking a Class Hierarchy: Escaping a Template Sandbox to Full RCE: https://medium.com/@t4nv1/17-000-for-walking-a-class-hierarchy-escaping-a-template-sandbox-to-full-rce-2c8483e62935 From Leaked API Key to Full Account Takeover: Uncovering a Mass PII Vulnerability: https://medium.com/@Brian_Bange/from-leaked-api-key-to-full-account-takeover-uncovering-a-mass-pii-vulnerability-228a4a3d6bef Six Auth Checks That Turn an MCP Server Into a Bug Report: https://meetcyber.net/six-auth-checks-that-turn-an-mcp-server-into-a-bug-report-8794240abb77 100 Days of Bug Bounty — Day 5: https://zubairahm3d.medium.com/100-days-of-bug-bounty-day-5-605f464ce771
10 · 561 ·
🐛 Bug Bounty Writeup Fixing Frida LIBUSB_TRANSFER_STALL by Switching from USB to Wi-Fi: https://osintteam.blog/fixing-frida-libusb-transfer-stall-by-switching-from-usb-to-wi-fi-627817b60f23 The Recon Habit That Separates Paid Hackers From Tool Users: https://osintteam.blog/the-recon-habit-that-separates-paid-hackers-from-tool-users-187a6245d545 How I Solved Intigriti’s September 2026 Challenge: https://medium.com/@ronaldo.shrestha713/how-i-solved-intigritis-september-2026-challenge-e29292a20662 Broken Access Control: Unauthenticated Read/Write Access to Every Conversation in an Tiktok AI…: https://medium.com/@ayedmostafa330/broken-access-control-unauthenticated-read-write-access-to-every-conversation-in-an-tiktok-ai-0a6eb481f5fd Your AI Agent Just Leaked Your Email — And a Fake Restaurant Review Did It: https://infosecwriteups.com/your-ai-agent-just-leaked-your-email-and-a-fake-restaurant-review-did-it-6867b0daa9b9 How I Made a Fox Snitch on Its Own Database: https://medium.com/@sadhshitiz/how-i-made-a-fox-snitch-on-its-own-database-93920e37a12f The Easy Bug Series | #04: https://medium.com/@huntersoham/the-easy-bug-series-04-529f49e9717f How I Started Bug Bounty Hunting During My BCA Degree (With No Coding Background): https://sukhveersingh97997.medium.com/how-i-started-bug-bounty-hunting-during-my-bca-degree-with-no-coding-background-2e05b7d179f4 Why Beginners Fail at Pentesting (And How to Fix It): https://medium.com/@arfatkhan3708/why-beginners-fail-at-pentesting-and-how-to-fix-it-0fb5afd0c3bd Bookmarklet — picoCTF Write-up | Understanding JavaScript Bookmarklets and Client-Side Decryption: https://medium.com/@affanhaxor/bookmarklet-picoctf-write-up-understanding-javascript-bookmarklets-and-client-side-decryption-304368b08bd4
8 · 747 ·
F
File
hack_via_SYN_packet.pdf · 3.5 MB · click to show
#NetSec #Offensive_security I’ll hack you via a SYN packet, OFFZONE 2026. // CVE-2026-10817 in the TCP stack of NetScaler ADC and Gateway. Yes, attackers can leak decrypted data via a truncated TCP timestamp See also: ]-> NetScaler NSE script ]-> Various scripts to triage compromised systems (Linux, ESXi, FreeBSD/NetScaler)
11 · 802 ·

An open public feed from the search index ChatCrawler — “Google for public Telegram”; refreshed as the venue is crawled. Times are UTC.

Public content only, official Telegram API. About · FAQ · What we do not do · Remove a page · Catalog · Search · How we count