Thread Reader
Share this page!
×
Post
Share
Email
Enter URL or ID to Unroll
×
Unroll Thread
You can paste full URL like: https://x.com/threadreaderapp/status/1644127596119195649
or just the ID like: 1644127596119195649
How to get URL link on X (Twitter) App
On the Twitter thread, click on
or
icon on the bottom
Click again on
or
Share Via icon
Click on
Copy Link to Tweet
Paste it above and click "Unroll Thread"!
More info at
Twitter Help
0 day exploit
@0day_exploit_
Security Researcher | Crypto auditor and malware analyst 🥰
Subscribe
Save as PDF
Dec 1, 2023
•
4 tweets
•
3 min read
Top Microsoft IIS
Thread 🧵:👇 Here is how to find IIS bugs
1)
Collect a huge number of targets, subdomains, and ports and even brutforceing the targets
2)
Short the IIS services nuclei-templates/fuzzing/iis-shortname.yaml
#BugBounty #bugbountytips #infosec @GodfatherOrwa @GodfatherOrwa 3) Use Shortscan tool form github to find if it's possible to hack iis
4)
JetBrains dotPeek to analyze files such as dll file and export the source of that file
5)
ffuf to dir brutfoce using wordlist
github.com/orwagodfather/…
Save as PDF
Feb 16, 2023
•
7 tweets
•
2 min read
Top IDOR ( Insecure direct object reference)
Thread 🧵:👇(1/12) Here is how to find IDOR all possible methods
" IDOR is a low hanging fruit which takes no skill with higher bounty" - can bypass payment , PII leak and want not 😍
#BugBounty
#bugbountytips
#infosec
#IDOR
1)
IDOR to delete images from other stores profile pic
a) facebook IDOR image delete -
shorturl.at/fmsyY
b) hackerone report id -404797