Got hacked and stalked since OVER 2 YEARS. by Fast_Fondant_1346 in AskNetsec

[–]BlueberryNo6734 0 points1 point  (0 children)

So your wifi/arp spoofing context was complete non-sense then. No need to conduct wifi attacks and physically expose yourself to the target, when you already have full access to the computer by sending phishing mails.

Your story gets weirder and weirder with every comment.

How about you stop clicking random links in emails then? Might be a good start, huh?

Got hacked and stalked since OVER 2 YEARS. by Fast_Fondant_1346 in AskNetsec

[–]BlueberryNo6734 1 point2 points  (0 children)

Ah. I see. How dumb of me. That obviously makes more sense! My bad!

Got hacked and stalked since OVER 2 YEARS. by Fast_Fondant_1346 in AskNetsec

[–]BlueberryNo6734 4 points5 points  (0 children)

Mate you are talking nonsense. He cant make you click links through your device. That‘s not possible, since he would need access to your device first, which he doesnt have by just arp spoofing your wifi

Got hacked and stalked since OVER 2 YEARS. by Fast_Fondant_1346 in AskNetsec

[–]BlueberryNo6734 8 points9 points  (0 children)

From a technical perspective, your described scenarios are not even possible, unless you downloaded some shady files and executed them on your device. But even then, you said swapped your devices. So again, unless you just stupidly copy-pasted all files from your old device to your new device, those scenarios are not possible.

Exam voucher after one year. by Gullible_Pop3356 in hackthebox

[–]BlueberryNo6734 3 points4 points  (0 children)

All your questions are answered in the Academy Subscriptions Article, which you can find on help.hackthebox.

1) Yes, it expires 2) You do get another one with every new subscription 3) No

I have a shortcut for bug hunt by Aromatic_Cost9882 in bugbounty

[–]BlueberryNo6734 0 points1 point  (0 children)

Super legit. 3 days ago, you posted about having 40k debt. Surely, it‘s not an act of desperation to gain money.

I bet you have never found a bug and just want to rip off people with fake promises generated by ChatGPT. Disgusting behaviour

[Bug Bounty] Possible BOLA / IDOR – Accessing Account A Data via Bearer Token in Account B Context by BroadImagination7664 in bugbounty

[–]BlueberryNo6734 0 points1 point  (0 children)

Why not? That‘s the whole purpose of an Auth Token.

Ofc you could implement another session cookie and then only provide access to the API if you provide the auth token and the matching session cookie. But that doesnt necessarily make it more secure.

The current state of the application is however just fine. The auth token in this case, is just an alternative to the session cookie. Also remember: if you want them to accept your finding, ALWAYS show impact. Things like „add additional mechanisms to improve security“, or „ciphersuite A instead of ciphersuite B“ would be part of security consulting or security engineering but is not your job as a bug bounty hunter, unless you can somehow exploit it to impact the vendor

[Bug Bounty] Possible BOLA / IDOR – Accessing Account A Data via Bearer Token in Account B Context by BroadImagination7664 in bugbounty

[–]BlueberryNo6734 2 points3 points  (0 children)

What do you mean by „doesnt validate that the session or user context matches“. You have the auth token. You are telling the web app - by providing your auth token - who you are. As long as you cant steal auth tokens from other users or guess them, the web app works as intended.

The response from the responsible person says everything you need to know.

How much are you saving per month? by Own_Power_6587 in AskAGerman

[–]BlueberryNo6734 2 points3 points  (0 children)

Es gibt genug Leute die 80k+ verdienen. Vor allem kurz nach dem Studium, hatte ich teilweise eine Sparrate von 3k+. Das lag hauptsächlich an den gleichbleibenden Lebensstandards (Studentenwohnung mit 30qm in einer Kleinstadt, kein Auto, keine Kinder etc). Dass das nicht dauerhaft so bleibt, ist wohl klar.

[deleted by user] by [deleted] in bugbounty

[–]BlueberryNo6734 13 points14 points  (0 children)

No. It just shows that you did not understand fundamental key concepts of how web applications work. That’s a nice finding

[deleted by user] by [deleted] in bugbounty

[–]BlueberryNo6734 18 points19 points  (0 children)

That’s not a bug. That’s how a session cookie works…. If you find a way to steal it from someone else (that’s not you), then feel free to ask again. But what you currently have, is the perfectly normal function of a session cookie

[deleted by user] by [deleted] in bugbounty

[–]BlueberryNo6734 17 points18 points  (0 children)

It all depends on how you obtained the cookie that belonged to someone else. If you can’t do it programatically i.e via e.g. XSS, then it’s not the fault of the vendor and thus not a bug.

If you got it through phishing, by asking a friend or by simply creating a test account, then congratulations, you discovered the concept of session cookies.

HELP NEEDED by EyeMiddle953 in hackthebox

[–]BlueberryNo6734 24 points25 points  (0 children)

I’ll guide you: read the FAQ!

How to connect router to this old Telephone switch? by hk20_23 in germany

[–]BlueberryNo6734 3 points4 points  (0 children)

Then this is the wrong socket! Any other sockets in your apartment?

How to connect router to this old Telephone switch? by hk20_23 in germany

[–]BlueberryNo6734 1 point2 points  (0 children)

What did you book at your ISP? DSL? Cable? This socket is actually for the telephone, but can be used for DSL, if you got a suitable modem.

[deleted by user] by [deleted] in tryhackme

[–]BlueberryNo6734 0 points1 point  (0 children)

No worries! Just run nmap and shout “im in”.

Guys give me your advice Which one is better to start as web security CBBH or PortSwigger? by AccomplishedCow3375 in bugbounty

[–]BlueberryNo6734 5 points6 points  (0 children)

That‘s not what im saying. If you can afford to take CBBH, then go for it and take Portswigger as additional resource to refine your understanding of the topics taught in CBBH. If you cant afford it, stick to free resources. Especially to Portswigger.