shubs 15
- So, you want to get into bug bounties?
- The ugly side of collaboration in bug bounties
- A hackers perspective on bug bounty triage
- A Glossary of Blind SSRF Chains
- Finding Hidden Files and Folders on IIS using BigQuery
- Hacking on Bug Bounties for Four Years
- Expanding the Attack Surface: React Native Android Applications
- Discovering a zero day and getting code execution on Mozilla's AWS Network
- Gaining access to Uber's user data through AMPScript evaluation
- High frequency security bug hunting: 120 days, 120 bugs
- Using ngrok to proxy internal servers in restrictive environments
- Abusing URL Shortners to discover sensitive resources or assets
- Enumerating IPs in X-Forwarded-Headers to bypass 403 restrictions
- Security for young people in Australia
- Exploiting Markdown Syntax and Telescope Persistent XSS through Markdown (CVE-2014-5144)