@gregxsunday.bsky.social
GraphQL CSRF via the HEAD method #bugbounty #bugbountytips #bugbountyhunter
30.06.2025 10:51 β π 5 π 0 π¬ 1 π 010/10 GraphQL SQL injection bug #bugbounty #bugbountytips #bugbountyhunter
28.06.2025 10:51 β π 2 π 0 π¬ 1 π 0Unexpected privilege escalation deletion bug #bugbounty #bugbountytips #bugbountyhunter
27.06.2025 10:51 β π 0 π 0 π¬ 1 π 1Unauthenticated β Low privileges β admin #bugbounty #bugbountytips #bugbountyhunter
26.06.2025 10:50 β π 0 π 0 π¬ 1 π 0Sometimes, one field is all you need for a bug #bugbounty #bugbountytips #bugbountyhunter
25.06.2025 10:47 β π 1 π 0 π¬ 1 π 0GraphQL isnβt just an API to deliver our payloads. Often, its implementations are what actually cause them. To see what bugs it can lead to, studied disclosed bug bounty reports. IDORs, privescs, DoS, CSRFs, SQLis - it's all there. Enjoy!
If your GraphQL testing stops at introspection and ID swapping, youβre missing out. SQLi, CSRF, caching bugs, race conditions, WebSocket bypasses - itβs all there. I studies 90 real reports to find what actually works.
16.06.2025 14:33 β π 2 π 0 π¬ 0 π 0Fuzzing vs broken access control bugs feat. Arthur Aires #bugbounty #bugbountytips #bugbountyhunter
16.06.2025 10:03 β π 0 π 0 π¬ 0 π 0This is why you should run bug bounty tools from a VPS feat. Arthur Aires #bugbounty #bugbountytips #bugbountyhunter
14.06.2025 11:02 β π 0 π 0 π¬ 0 π 0Managing your blind XSS payloads feat. Arthur Aires #bugbounty #bugbountytips #bugbountyhunter
13.06.2025 11:03 β π 1 π 1 π¬ 0 π 0Generating target-specific wordlists feat. Arthur Aires #bugbounty #bugbountytips #bugbountyhunter
12.06.2025 11:07 β π 0 π 0 π¬ 0 π 0Generating target-specific wordlists feat. Arthur Aires #bugbounty #bugbountytips #bugbountyhunter
12.06.2025 11:06 β π 1 π 0 π¬ 0 π 0Automation to get Hackerone program updates feat. Arthur Aires #bugbounty #bugbountytips #bugbountyhunter
11.06.2025 11:06 β π 2 π 0 π¬ 0 π 0In todayβs episode, Arthur Aires shares his bug bounty methodology which starts with heavy fuzzing and automation to find the best assets for manual exploitation and escalation. Enjoy!π₯
In this video, Arthur Aires walks us through two real-world deserialization RCEs that include bypassing a class allowlist and then exfiltrating data via DNS.
Techniques you'll want in your toolbox. Enjoy!
An ATO that doesnβt make sense feat. Jasmin βJR0ch17β Landry #bugbounty #bugbountytips #bugbountyhunter
21.05.2025 09:14 β π 3 π 0 π¬ 0 π 0Manipulating referer policy when DOM Purify is used feat. Jasmin βJR0ch17β Landry #bugbounty #bugbountytips #bugbountyhunter
20.05.2025 09:13 β π 1 π 0 π¬ 0 π 0SQLi still exists in 2025 feat. Jasmin βJR0ch17β Landry #bugbounty #bugbountytips #bugbountyhunter
19.05.2025 09:11 β π 0 π 0 π¬ 0 π 0Using match and replace rules for quickly applying polyglot payloads feat. Jasmin βJR0ch17β Landry #bugbounty #bugbountytips #bugbountyhunter
17.05.2025 09:11 β π 1 π 1 π¬ 0 π 0Second order injections feat. Jasmin βJR0ch17β Landry #bugbounty #bugbountytips #bugbountyhunter
16.05.2025 09:19 β π 0 π 0 π¬ 0 π 0In this episode, Jasmin βJR0ch17β Landry breaks down how he consistently lands highs and crits - from SSRFs to less common bugs like XXEs and SQLis. Enjoyπ₯
Hunting for privilege escalations by modifying the JS feat. @renniepak.nl #bugbounty #bugbountytips #bugbountyhunter
19.03.2025 11:57 β π 1 π 0 π¬ 0 π 0$50k XSS in a web3 website feat. @renniepak.nl #bugbounty #bugbountytips #bugbountyhunter
18.03.2025 11:57 β π 3 π 0 π¬ 0 π 0The CSPBypass website feat. @renniepak.nl #bugbounty #bugbountytips #bugbountyhunter
17.03.2025 11:57 β π 1 π 0 π¬ 1 π 0The mysterious bug bounty methodology
15.03.2025 11:57 β π 0 π 0 π¬ 0 π 0