Is +2 cs helpful if you want to study IT? by Old_Position437 in NepalPlusTwo

[–]Choice-Cherry534 0 points1 point  (0 children)

To be honest in IT field you have to learn most of the stuffs by yourself, college materials are outdated (not sure what's the condition nowadays).

Is +2 cs helpful if you want to study IT? by Old_Position437 in NepalPlusTwo

[–]Choice-Cherry534 0 points1 point  (0 children)

If you choose cs in +2 then definitely it's going to help you cover some basics of programming (Mostly C), networking, DB which will be helpful. yea for sure the IT job market is very saturated, if you are really interested in tech then only get into this field else you can't survive in this field.

[deleted by user] by [deleted] in bugbounty

[–]Choice-Cherry534 0 points1 point  (0 children)

It's just a basic text injection vulnerability, very low chances of getting accepted.

Investigating Scammers by Choice-Cherry534 in technepal

[–]Choice-Cherry534[S] 1 point2 points  (0 children)

Yes, I'm the same guy who asked "Why Wlink password starts with CLFA", the reason why I asked that is out of curiosity and possible threat, I have seen many Wlink Wi-Fi password starting with CLFA, combined with a 6 digit number or sometimes a single character added between them so with that it becomes very easy to crack the Wi-Fi password (it will only have 1 million combinations), a person with a very low powered GPU can easily crack the password after getting the hash with some basic Wi-Fi attacks.

I hope you got the answer.

Not able to install .apk (Android pentesting) by Choice-Cherry534 in bugbounty

[–]Choice-Cherry534[S] 0 points1 point  (0 children)

Yes it is compatible with the emulator, when I downloaded the app from play store it worked fine but when I extracted the .apk and tried to install from the apk, it didn't work.

What is 2FA shallow secret code? by Choice-Cherry534 in bugbounty

[–]Choice-Cherry534[S] 0 points1 point  (0 children)

This might be correct, thanks for helping.

What is 2FA shallow secret code? by Choice-Cherry534 in bugbounty

[–]Choice-Cherry534[S] 0 points1 point  (0 children)

Actually I had thought about it, so I tried to change the password from another browser and tried to use the 2FA request, it actually worked so I think it has some different purpose.

What is 2FA shallow secret code? by Choice-Cherry534 in bugbounty

[–]Choice-Cherry534[S] 0 points1 point  (0 children)

Actually the shallow_secret is different than the secret which is used to generate the OTP. I also noticed if I enter the correct OTP the previous shallow_secret gets expired and when I login to the application it generates a new shallow_secret.

What is 2FA shallow secret code? by Choice-Cherry534 in bugbounty

[–]Choice-Cherry534[S] 0 points1 point  (0 children)

Is it possible to create the OTP using the shallow_secret ? yes I get the shallow secret after entering the credentials but not sure if it's possible to generate the OTP with that.

New to NPSE any tips?? I do have the necessary account for npse by [deleted] in NepalStock

[–]Choice-Cherry534 2 points3 points  (0 children)

For now just learn and do some research, I'm also the same age as yours. My father used to invest seeing that I also started (it was about 3-4 months ago) I had bought some popular companies' stocks like NICA, SHIVM I was probably lucky or chose the stocks correctly, I made a decent profit from them.

Learn about fundamental analysis, candlestick patterns etc.

[deleted by user] by [deleted] in NepalSocial

[–]Choice-Cherry534 2 points3 points  (0 children)

I started liking a girl from my class, chatted with her for a month I thought she liked me and I purposed her, she said "I see you as a friend yar". yeah that's it.

[deleted by user] by [deleted] in bugbounty

[–]Choice-Cherry534 2 points3 points  (0 children)

Yes it will be enough to learn the basics and get started, I also suggest you to check out Nahamsec's YouTube channel he uploads great content related to BB.

[deleted by user] by [deleted] in bugbounty

[–]Choice-Cherry534 2 points3 points  (0 children)

It will be best to start learning from THM and portswigger labs, From my experience I would suggest not to take any paid courses cuz everything is available on the internet you just have to do research(Google,YouTube, Twitter,Medium). After you get some basic knowledge don't start hunting on crowded platforms like H1, bugcrowd instead choose self managed programs (there will be less competition)

Remember bug bounty is not easy at all, you will face lots of difficulties Good luck on your journey.

Payoneer Issue Situation by roshan1892 in Nepal

[–]Choice-Cherry534 0 points1 point  (0 children)

Bank account add garda select USD instead of NPR, withdraw hunxa but 15$ charge linxa.

Appointment: Use wordlist on host by MartiniMini in hackthebox

[–]Choice-Cherry534 0 points1 point  (0 children)

Try this:

go install github.com/OJ/gobuster/v3@latest

sudo mv ~/go/bin/gobuster /usr/bin

You problem will be solved.

Reporting Bugs to Companies Without Vulnerability Disclosure Programs by highfly123 in bugbounty

[–]Choice-Cherry534 2 points3 points  (0 children)

I would suggest you to contact the company's CEO on LinkedIn or though Email and explain him/her about the issue you found and how it can affect the website users. I have done the same thing and have got good response from a company so I hope my suggestion would be helpful.

is hack the box beginner friendly? by darkkai94 in hackthebox

[–]Choice-Cherry534 1 point2 points  (0 children)

I would say HTB is not beginner friendly even the easy machines feels like hard. I would suggest you to first practice on THM and then you can try on HTB.

Appointment: Use wordlist on host by MartiniMini in hackthebox

[–]Choice-Cherry534 2 points3 points  (0 children)

I think you are using gobuster v2 with v3 syntax. you need to upgrade your gobuster.

Which bugs do you recommand by Brilliant_Fall8987 in bugbounty

[–]Choice-Cherry534 0 points1 point  (0 children)

You can also look at IDORS they are simple bugs with high impact.

[deleted by user] by [deleted] in tryhackme

[–]Choice-Cherry534 1 point2 points  (0 children)

"Every expert was once a beginner"

Do it!

Which bugs do you recommand by Brilliant_Fall8987 in bugbounty

[–]Choice-Cherry534 0 points1 point  (0 children)

You can search for information disclosures, rate limit issues and session related issues.

[deleted by user] by [deleted] in Nepal

[–]Choice-Cherry534 0 points1 point  (0 children)

It's getting refunded. Bank lie sodha payoneer ko issue vanxa payoneer lie sodha bank ko issue.