Shammah zealsham Agwor's Avatar

Shammah zealsham Agwor

@zealsham.bsky.social

Bugbounty hunter| Rust dev| The man of mankind | Application Security Engineer . OSCP in view , #Bitcoin-core contributor

596 Followers  |  97 Following  |  8 Posts  |  Joined: 22.06.2023
Posts Following

Posts by Shammah zealsham Agwor (@zealsham.bsky.social)

Preview
GitHub - bebiksior/Caido403Bypasser: 403Bypasser is a simple plugin that lets you bypass 403 status code by transforming HTTP requests with custom templates. 403Bypasser is a simple plugin that lets you bypass 403 status code by transforming HTTP requests with custom templates. - bebiksior/Caido403Bypasser

Good shit, y'all. Give it a download.

github.com/bebiksior/Ca...

27.11.2024 15:01 β€” πŸ‘ 15    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

Incoming $1m hacker

27.11.2024 20:11 β€” πŸ‘ 4    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I talk about this on the pod all the time, but CSRF is dead simple. You just need to know the conditions.

I'm not gonna recite them again here, but today a new condition came up:

No Content-Type header -> no CSRF restrictions
Same-site: None
POST
= CSRF

The research:

27.11.2024 16:55 β€” πŸ‘ 41    πŸ” 5    πŸ’¬ 4    πŸ“Œ 0

Got a CSRF attack being blocked by Content-Type validation? You might be able to bypass it with this quality technique.

27.11.2024 13:28 β€” πŸ‘ 35    πŸ” 4    πŸ’¬ 0    πŸ“Œ 0

Coding without a package manager in 2024 is like building a house by mining limestones first and making cement and mortal with that

27.11.2024 00:14 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

As a #Bugbounty hunter , I was so mad when my workplace paid $30k for a pentest and only got horrible reports (ssl cert , httponly , rate limit ) . Mean while our bug bounty program had mediums and high reports

Moving forward I think every pentest company should have at least 2 bug bounty hunters

27.11.2024 00:09 β€” πŸ‘ 7    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Trying to make a list of programs that have hosted a live event on hackerone
-epic games
-tiktok
-zoom
-salesforce
-uber
-PayPal
-DoD
-shopify
-airbnb
-yahoo
-Starbucks
-Amazon
Which did I miss #Bugbounty

25.11.2024 01:15 β€” πŸ‘ 5    πŸ” 1    πŸ’¬ 2    πŸ“Œ 0

Myself

22.11.2024 21:14 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

#Bugbounty

22.11.2024 00:27 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

I remember this picture spooking me out when I first saw the write up πŸ˜‚

20.11.2024 10:18 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 1    πŸ“Œ 0

Bro , β€œsmoking tookah” literally won’t leave my lips for days

22.06.2023 12:50 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0