Hossein NafisiAsl Profile picture
Web Security Researcher, ‌Bug Hunter Phd Candidate at Sharif University of Technology Farsi Tweets:@NafisiAslH

May 16, 2022, 8 tweets

#Secret3
6 Questions that Guarantee your Bounty 😈

#bugbountytips👇🏻🧵

1/
How does the app pass data?

parameter or path?

2/
How/Where does app Talk about users?

Cookie or API Calls?

uid or username or email or uuid?

3/
Does site have multiple user levels?

admin, user, viewer, etc...

4/
Has there been past vulns?

5/
How does the app handle?

xss? csrf? code injection?

6/
Does site have unique threat model?

#Secret3
6 Questions that Guarantee your Bounty 😈
github.com/NafisiAslH/Kno…

Share this Scrolly Tale with your friends.

A Scrolly Tale is a new way to read Twitter threads with a more visually immersive experience.
Discover more beautiful Scrolly Tales like this.

Keep scrolling