#yeswerhackers — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #yeswerhackers, aggregated by home.social.
-
#20 Vulnerable Snippet {{ solution }} ☑️
See more content on our blog: https://blog.yeswehack.com/category/yeswerhackers/
Bug: SQL injection 💉
Lang: PHP 🐘, MySQL 🐬Check out the explanation in the image below!👇
#YesWeRHackers #BugBounty #YWHSnippet -
Vulnerable Code Snippet 💀
Level: Easy 🪲Does it only work once?!
For all #BugBounty hunters, it is available on Github for hands-on testing! 👉 https://github.com/yeswehack/vulnerable-code-snippets/tree/main/new
#YesWeRHackers
Found the issue? Explain how in the comments! 👇 -
#19 Vulnerable snippets solution! ☑️
See more content on our blog: https://blog.yeswehack.com/category/yeswerhackers/
Github repo updated as usual!
➡️https://github.com/yeswehack/vulnerable-code-snippetsVuln: Open Redirect ⛔️
Lang: JavaScript ⚡️Check out the explanation in the image below!👇
#YesWeRHackers #BugBounty #YWHSnippet -
Vulnerable code snippets time!💀
Level: Easy 🪲~ [#]vulnerable..?
Try it out at Github: https://github.com/yeswehack/vulnerable-code-snippets/blob/main/new/vcode/19-new.php
#BugBounty #YesWeRHackers
Found the bug? Explain how in the comments! 👇 -
Pimp My Burp #7 is out! 🥷
We take a dive into the Burp extension HaE! 🤯
This extension can detect custom regex patterns and highlight them for you so you don't miss the juicy bugs!
Find out more 👉 https://blog.yeswehack.com/yeswerhackers/pimpmyburp/pimpmyburp-7-how-hae-burp-suite-extension-help-you-daily-hunting/
-
#18 Vulnerable snippets solution! ☑️
Congrats @[email protected]!
See you in DM for the swag 🎁See more content on our blog: https://blog.yeswehack.com/category/yeswerhackers/
Type: Local File Inclusion
Lang: PHP🐘Check out the explanation in the image below! 👇
#YesWeRHackers #YWHSnippet -
Vulnerable Code Snippets Time 🥷
Level: Medium 🐝This web application does not like dot dot slash!
Try it out at Github: https://github.com/yeswehack/vulnerable-code-snippets/tree/main/new
#BugBounty #YesWeRHackers
Found the issue? Explain how in the comments! 👇🎁 The best solution gets an exclusive swag!
-
⏰ DOJO Challenge #21 - EvilTwin-Admin
🎁 Top 3 reports win a swag pack!
🗓️ Submit your solution before 10/02/2023Check it out here 👉 https://dojo-yeswehack.com/practice/4401d46f16b6
-
#17 Vulnerable snippets solution! ✅
🎁Congrats @[email protected]! See you in DM for the swag
See more content on our blog: https://blog.yeswehack.com/category/yeswerhackers/
Type: Deserialization of Untrusted Data
Lang: Python 🐍Check out the explanation in the image below!👇
#YesWeRHackers #YWHSnippet -
Vulnerable code snippets time ⏰
Level: Medium 🐝🎁 The best solution gets an exclusive swag!
~ A dangerous pickle can be found here...
Check it out on Github: https://github.com/yeswehack/vulnerable-code-snippets/tree/main/new
#BugBounty #YesWeRHackers #YWHSnippet
Found the issue? Explain how in the comments! 👇 -
DOJO #⃣2⃣0⃣ is over!
We have our 3 winners! 🥁
Congrats to:· Tihmz (@[email protected])
· bosstester
· BraxoiaThe swags are on their way! Keep an eye on your mailbox 🎁
Read our blog and be prepared for the next challenge:
https://blog.yeswehack.com/dojo/dojo-challenge-20-winners/ -
Tips&Tricks 🕵️
Time for a #BugBountyTip!
Make your own wordlist adapted to the target language using the CLI tool dict & dictd 🧾
-
#16 Vulnerable snippets solution! ✅
Check out our blog page for more content: https://blog.yeswehack.com/category/yeswerhackers/
Type: Insecure direct object references (IDOR) 🎲
Lang: PHP 🐘Check out the explanation in the image below!👇
#YesWeRHackers #bugbounty #YWHSnippet -
✨ Happy New Year 2023 from the whole YesWeHack team! May this new year be filled with many vulnerabilities to discover and report! 🔒
What is your #bugbountygoal for this year? 👀
-
Vulnerable code snippets time ⏳
Level: Easy 🪲Simple bug with high severity!
Try it on our Github: https://github.com/yeswehack/vulnerable-code-snippets/tree/main/new#BugBounty #YesWeRHackers
Found the issue? Explain how in the comments! 👇 -
#15 Vulnerable snippets solution! ✅
Check out our blog page for more content: https://blog.yeswehack.com/category/yeswerhackers/
Type: Weak Password Recovery Mechanism 🔐
Lang: PHP 🐘Check out the explanation in the image below!👇
#YesWeRHackers #bugbounty #bugbountytips -
Vulnerable code snippets time ⏳
Level: Hard 🐞 (code analysis)Would you like to update "your" password? 🫵🔐
Github: https://github.com/yeswehack/vulnerable-code-snippets/tree/main/new
#BugBounty #YesWeRHackers
Found the issue? Explain how in the comments! -
#14 Vulnerable snippets solution! ✅
Check out our blog page for more content: https://blog.yeswehack.com/category/yeswerhackers/
Type: Denial Of Service (DOS)💀
Lang: PHP🐘Check the comments below to see the results!👇
#YesWeRHackers #bugbounty #bugbountytips -
Vulnerable code snippets time ⏳
Level: Easy 🪲This code snippet could make someone late for the weekend!🤯
#BugBounty #YesWeRHackers
Found the issue? Explain how in the comments! 👇 -
Tips&Exploit 🕵️
Time for a #BugBountyTip!
Did you know that Metasploit offers a JavaScript keylogger module?💀
Use it as a proof of concept (POC) & improve your XSS exploitation!💻
-
🚀 @[email protected] is happy to support #IWCON2022, the virtual conference by @[email protected], on Dec 17-18. The event will be a great opportunity to learn from #infosec experts and interact with the #cybersecurity community, so be sure to attend!
https://blog.yeswehack.com/events/yeswehack-supports-iwcon-2022/
-
Vulnerable code snippets time ⏳
Level: Medium 🐝~ Uploading files and sharing them, what could possibly go wrong?
Try it out at our Github (new folder)! 🙀
https://github.com/yeswehack/vulnerable-code-snippets#BugBounty #YesWeRHackers
Found the issue? Explain how in the comments! 👇 -
Ramp 🆙 - JavaScript The Language For Bugs
Explore the weirdness of JavaScript 😵💫, for a better Cross Site Scripting (XSS) exploitation!
🔹 There are four valid comment types in JS?
🔹 DOM XSS with only a single char?➡️ https://blog.yeswehack.com/yeswerhackers/javascript-language-made-for-bugs/
-
⏰ DOJO Challenge - DOM XSS (Butters Adventure)
🎁 Top 3 reports win a swag pack!
🗓️ Submit your solution before 05/01/2023Check out it out here 😼👇
https://dojo-yeswehack.com/practice/ca271cf752e3 -
Winners of DOJO #⃣1⃣9⃣
Congrats to!🥳🏆
- xk3tla (@[email protected])
- karaharauh (@[email protected])
- cyrilp (@[email protected])Some swag is on the way!❤️🔥
Read the blog for more information and how you can participate in the next challenge!👇
https://blog.yeswehack.com/dojo/dojo-challenge-19-winners/ -
Vulnerable code snippets time⏳
Level: Medium🐝➡️This is an underestimated vulnerability if you manage to exploit it correctly!🤯
Let us know which vulnerability you thought it was after a quick look!😼
#BugBounty #YesWeRHackers
Found the issue? Explain how in the comments!👇 -
🚨 Good news for you, hunters: @[email protected]’s #BugBounty program has gone public on our platform!
With 12 in-scope assets and rewards up to €2,000, the bug hunt promises to be exciting. Curious to know more? Check out the new program here 👉 https://yeswehack.com/programs/swapcard
#YesWeRHackers -
HackPack #11 goes brrrrr🚗💨
Lots of great resources this month to keep you up to date on the latest bug bounty news🪩, #BugBountyTip & hacking tools⚔️
Check it out!👇
https://twitter.com/i/events/1587745151761481728 -
▶️ Thanks @[email protected] for mentioning our weekly code snippet challenges! 🤗
👉 If you want to practice for code review:
https://github.com/yeswehack/vulnerable-code-snippetsLink to the video 👇https://youtu.be/ajcxjnTFo6A
-
#⃣1⃣1⃣ Vulnerable code snippets time ⏳
Level: Easy 🪲You'll find the code directly on our GitHub: https://github.com/yeswehack/vulnerable-code-snippets
Go & play with it!💀
#BugBounty #YesWeRHackers
Found the issue? Explain how in the comments! 👇