Open in app

Sign In

Write

Sign In

Aneesha D
Aneesha D

195 Followers

Home

About

Mar 3

Finally, that’s Blind XSS

Hello 👋 people, We know that xsshunter is saying something about their services, I really didn’t not understood how to overcome that. Now we have another website that provides blind xss tracking service ie, by cyberxplore called https://bxsshunter.com/ I was kinda happy that we have free service available now, but…

Bug Bounty

1 min read

Finally, that’s Blind XSS
Finally, that’s Blind XSS
Bug Bounty

1 min read


Mar 3

Bypassing WAF and got XSS in DOD

Bypassing WAF and got XSS in DOD Hello all, In this post I will share about the how I found RXSS on DOD. https://hackerone.com/reports/1834042 During my latest security testing, I set my sights on the Department of Defense’s website and chose example.com as my target. My first step was to use subfinder to search for any subdomains…

2 min read

Bypassing WAF and got XSS in DOD
Bypassing WAF and got XSS in DOD

2 min read


Mar 3

My first IDOR on hackerone

Hello all… Today, I will be sharing with you how I discovered an IDOR vulnerability on a government website. So what is IDOR? Insecure Direct Object Reference (IDOR) vulnerabilities are a common security flaw in which applications unintentionally expose sensitive internal objects such as files, databases, and user details. Lets…

Bugbounty

2 min read

My first IDOR on hackerone
My first IDOR on hackerone
Bugbounty

2 min read


Dec 31, 2022

Not Validating the session may Leads to Account Deletion.

Session termination is an important part of the session lifecycle. Reducing to a minimum the lifetime of the session tokens decreases the likelihood of a successful session hijacking attack. This can be seen as a control against preventing other attacks like Cross Site Scripting and Cross Site Request Forgery. Such…

2 min read

Not Validating the session may Leads to Account Deletion.
Not Validating the session may Leads to Account Deletion.

2 min read


Mar 18, 2022

For the first Bounty, it takes a few challenging months, but only a few days for the second.

Good day, everyone! I spent nearly three hours looking for this bug, but it took me three months to uncover the bug that brought me my first bounty. And this is the continuation of my article about “On the way to 2nd Bounty”, where I said about XSS and a…

Bug Bounty

2 min read

For the first Bounty, it takes a few challenging months, but only a few days for the second.
For the first Bounty, it takes a few challenging months, but only a few days for the second.
Bug Bounty

2 min read


Mar 1, 2022

On the way to 2nd Bounty XSS and Apache server .

Hello readers, in this post, we’ll look at XSS and Apache Server furthere on apache server I will post another article. Cross Site Scripting (XSS) (https://owasp.org/www-community/attacks/xss/) Cross-Site Scripting (XSS) attacks are a type of injection, in which malicious scripts are injected into otherwise benign and trusted websites. XSS attacks occur when an attacker uses…

Bug Bounty

3 min read

On the way to 2nd Bounty XSS and Apache server .
On the way to 2nd Bounty XSS and Apache server .
Bug Bounty

3 min read


Feb 14, 2022

My First Bounty and How Did I Get It?

Hello!! This is my first article, and I really hope you enjoy it! From June 2021, I began looking for issues on the websites. So, one day after submiting many Report where some got accepted and Rejected, I was just showing/telling my sister about the BugBounty and clicked on the…

Bug Bounty

2 min read

My First Bounty and How Did I Get It?
My First Bounty and How Did I Get It?
Bug Bounty

2 min read

Aneesha D

Aneesha D

195 Followers
Following
  • Saransh Saraf aka (MR23R0)

    Saransh Saraf aka (MR23R0)

  • ParagBagul

    ParagBagul

  • Chenny Ren

    Chenny Ren

  • ZeusCybersec

    ZeusCybersec

  • 7h3h4ckv157

    7h3h4ckv157

See all (113)

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech

Teams