Posts

10 Rules of Bug Bounty

Image
1.Targeting the Bug Bounty Program How long you target the program ? If the Answer is Just Few Hour’s or a night, Then That’s where you are doing wrong .Bug Hunting is Matter of Skill’s and Luck .Spending just few hours on program’s could be waste Because those bugs are mostly reported.You May end up getting depressed by duplicates , would suggest to at least choose any program Spend a week on it . Big Bug’s Takes time. Take your time to understand the Functionality of the application. keep writing notes and track of Suspicious endpoint’s. Because you’re not going to earn much for known issue unless you’re very early to report. If you find out about a public program after 10/12 hours of its launching. Don’t waste your time looking for known issues or low hanging fruit .Just take a deep dive into the application. 2. How do you Approach the Target ?
If Answer is Just by Signing up at Target , Checking For Vulnerabilities like CSRF, XSS,Subdomain’s etc , Then This Could be the problem where y…

Getting started with Bug Bounty.

Image
Getting started with Bug Bounty.
Hey, guys! This post is dedicated to all those who want to do bug bounty. Although I am not a ranker like my friends Sai Kumar Reddy, KL Sreeram, Vasim Shekh, etc I learned many things throughout my way in bug bounty and I want to share them in this post 
What should you know before getting into bug bounty?  First of all, you should know basic things about web app(ofc. bug bounties are not limited to it) have what is HTTP? What is HTML? What are HTML Forms? What is JavaScript? What does JS do? Structure of a web app(Nowadays all web apps have MVC). IMO this thing matter. A book like Web Hacking 101 will help a lot.Keep learning new things, How?  HackerOne’s Hactivity (Web Hacking 101 also covers this section), Other Hunters blog, And just dig in whenever you see weird term or thing, Maybe you end up learning a good thing?Play with Burp, Explore it Approaching a target If you’re new don’t just focus on reward only sites, go for points in this way you will…

How I find Cross Site Script in THE HINDU website

Image
I felt happy when I found the Cross Site Script vulnerability in the hindu newspaper website which is the most leading newspaper in India.It my pleasure that I helped them as a White Hat Web Application Security Researcher. This is my First Finding.
                                                               About The Hindu The Hindu is an English-languageIndian daily newspaper. Headquartered at ChennaiThe Hindu was published weekly when it was launched in 1878, and started publishing daily in 1889. It is the second most circulated English-language newspaper in India, with average qualifying sales of 1.45 million copies as of Jan−Jun 2016.[4]The Hindu has its largest base of circulation in southern India, and is the most widely read English daily newspaper in Andhra PradeshTamil Nadu and KeralaTelanganaKarnataka. It is my Honor that I helped The Hindu.
Here is a Proof of Concept of Cross Site Scripting Vulnerability in thehindu.com


Host: https://www.thehindu.com P.O.C-http://…