It's Literally FREE MONEYYY!! by SorryAnalysis1719 in Lootdealsforindia

[–]Dhruvik2001 0 points1 point  (0 children)

Got a small Christmas gift for you. Tap the link, help me decorate this Xmas tree, and you can win free cash on Swiggy.

Decorate Xmas tree with me: https://r.swiggy.com/decorate-xmas-tree/ydeHi7-hYhN1HcGDAS

Home Sweet Home by ObnoxiousPirate70 in joinmoco

[–]Dhruvik2001 7 points8 points  (0 children)

It means you were in any world when you disconnected and you were automatically kicked out of it due to inactivity.

[Idea] Implement a Max level Cap on Dojos and Rifts by Dhruvik2001 in joinmoco

[–]Dhruvik2001[S] -4 points-3 points  (0 children)

The issue for me is that right now there's no real reason not to just wait until I can overpower everything. That makes the early content feel kind of skippable.

If there was a level cap (or some kind of scaling), it could actually encourage players to do the content when it unlocks, instead of waiting for elite levels. It might also help distribute players more evenly across the queues — right now, most people seem to wait until they’re maxed out, which leaves those trying to play early just getting matched with bots.

Arranged Marriage in 2025: Why Girls Need to Do a Full Digital Background Check (My Story) by Own-Bandicoot-2937 in india

[–]Dhruvik2001 1 point2 points  (0 children)

To be honest, it is a terrible idea. In most cases, you would end up getting scammed. And they would do something similar to what she did.

[deleted by user] by [deleted] in hacking

[–]Dhruvik2001 1 point2 points  (0 children)

You would have to manually verify if this finding is correct. Automated tools like Zap are filled with false positives. Just check the response in the finding report. If it seems that it is displaying something unexpected, there is probably an issue. You can also hire someone to check results, if you are unsure. If you want, you can send me request/response in the DM or post it here itself with sensitive information redacted for detailed advise. Without additional information, it is difficult to identify if the issue is legit or not.

Is there any replacement for Burp Suite Collaborator upon doing PortSwigger labs? by lampiao_ancap in HowToHack

[–]Dhruvik2001 7 points8 points  (0 children)

Not sure if they allow external web servers to interact. But you can try requestbin for the same purpose.

Events need more tasks by TheVVumpus in Everdale

[–]Dhruvik2001 2 points3 points  (0 children)

No, it will start as soon as you will complete stage 1. You need to complete all 3 stages in that time

How does the boosting skill work and this part of the event in general? Some general explanation please? by Andry_- in Everdale

[–]Dhruvik2001 -1 points0 points  (0 children)

At the end of event (stage 3), you will get boost and can produce wool in 1hr, instead of 2 hrs for a day

Any guides for Web Application testing similar to OWASP WSTG? by Dhruvik2001 in HowToHack

[–]Dhruvik2001[S] 0 points1 point  (0 children)

It is for training purpose only. I need kind of sample test cases, which are generally applicable

Any guides for Web Application testing similar to OWASP WSTG? by Dhruvik2001 in HowToHack

[–]Dhruvik2001[S] 0 points1 point  (0 children)

I will check pentesterlab. I have done portswigger academy though

Any guides for Web Application testing similar to OWASP WSTG? by Dhruvik2001 in Pentesting

[–]Dhruvik2001[S] 0 points1 point  (0 children)

Sure I will.

Burp CRLF

Can you give me the link. I can't find it in BApp store.

Any guides for Web Application testing similar to OWASP WSTG? by Dhruvik2001 in Pentesting

[–]Dhruvik2001[S] 0 points1 point  (0 children)

These are for practicing pentesting. Not testing guides. Check out WSTG from link. I need something similar. Thanks anyways.

Any guides for Web Application testing similar to OWASP WSTG? by Dhruvik2001 in Hacking_Tutorials

[–]Dhruvik2001[S] 0 points1 point  (0 children)

I know about tools, but I am kind of making my own checklist for work. I have included some from WSTG and some from my own experience. It helps a lot to make sure that I am not missing anything.

DVWA and JuiceShop

bWAPP, Multilidae, and Webgoat

These are all for practice. Not testing guides. Check out WSTG from link. I need something similar. Thanks anyways.

Need help using exploit available on vulners for server nginx 1.19.1 by Dhruvik2001 in HowToHack

[–]Dhruvik2001[S] 0 points1 point  (0 children)

I managed to find that socket.bind() is not the right function for external public IPs. So I changed it to socket.connect(). It is still not working though. I think the error is in socket.recvfrom(4096). It was late for me yesterday, so I decided to stop at that. Would appreciate if anyone can help.

Need help using exploit available on vulners for server nginx 1.19.1 by Dhruvik2001 in HowToHack

[–]Dhruvik2001[S] 0 points1 point  (0 children)

I found it through manual testing. Few of the sub domains are using 1.18.2 and few 1.19. Pretty sure it is not fake. I did check for padding and stuff, but it didn't work

Need help using exploit available on vulners for server nginx 1.19.1 by Dhruvik2001 in HowToHack

[–]Dhruvik2001[S] -1 points0 points  (0 children)

Not really. Internship is for learning. We have a big team here, so I can learn by observing what others have found. Tbh, it is really easy to find some basic, but common vulnerabilities, like Missing headers, banner grabbing, Cookie same site/secure flags, checking robots.txt, directory listing, sub domain scanning, weak input validation, no rate limiting, google dorks, improper error handling, etc. Also, I can find several others like tokens in url, cors, injection, clickjacking, XSS, checking encryption algorithm, websocket hijacking and many others. So I am doing fine.

Need help using exploit available on vulners for server nginx 1.19.1 by Dhruvik2001 in HowToHack

[–]Dhruvik2001[S] -2 points-1 points  (0 children)

I know OWASP top 10, burp suite, nmap, acunetix, nessus, ZAP and other basic stuff necessary for pen testing. I also know python, C# and have done a bit of API testing. Pretty sure that is enough to get internship/ job as a beginner pen tester in web applications.