0 day exploit Profile picture
Know about cyber security , app development, Networks, Penetration , hacking attacks by kali Linux and everything you want to know about technology ..
Dec 1, 2023 4 tweets 3 min read
Top Microsoft IIS

Thread 🧵:👇 Here is how to find IIS bugs

1) Collect a huge number of targets, subdomains, and ports and even brutforceing the targets

2) Short the IIS services nuclei-templates/fuzzing/iis-shortname.yaml

#BugBounty #bugbountytips #infosec @GodfatherOrwa @GodfatherOrwa 3) Use Shortscan tool form github to find if it's possible to hack iis

4) JetBrains dotPeek to analyze files such as dll file and export the source of that file

5) ffuf to dir brutfoce using wordlist
github.com/orwagodfather/…
Feb 16, 2023 7 tweets 2 min read
Top IDOR ( Insecure direct object reference)
Thread 🧵:👇(1/12) Here is how to find IDOR all possible methods

" IDOR is a low hanging fruit which takes no skill with higher bounty" - can bypass payment , PII leak and want not 😍

#BugBounty #bugbountytips #infosec #IDOR 1) IDOR to delete images from other stores profile pic
a) facebook IDOR image delete - shorturl.at/fmsyY
b) hackerone report id -404797