Discover and read the best of Twitter Threads about #bugbountydiary

Most recents (1)

4/8/22 #bugbountydiary #bugbountytips

Everyone is sick in the house but I had some running scans I needed to check up on.

I found a SQL injection bug on a blog.

Here's how I did it, so you can learn...

👇

🚨Like, retweet, & follow for more hacker tips!🚨

1/x
Firstly, I ran reconFTW on a set of domains related to the target. I had the main domain, and several acquisition domains running too. The acquisitions were gathered from CrunchBase and Wikipedia.

This gave me a pretty good list of targets.

2/x

github.com/six2dez/reconf…
ReconFTW runs screenshotting on all web-resolvable domains and subdomains.

I opened that folder and saw what looked to be a marketing campaign site that was super old for a product the company no longer supported. To further confirm the Copyright footer was from 2016

3/x
Read 12 tweets

Related hashtags

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3.00/month or $30.00/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!