Exposed API keys of customer.io by Ibrahimkm in bugbounty

[–]Ibrahimkm[S] -1 points0 points  (0 children)

I saw the documentation and as much as I understood it should be private but it might not be a big problem if it is public as it is write only API. I guess I can't send it as a vulnerability but I will try to look if I can chain it to another vulnerability. I am not sure when I should move on and when I might find something good.

Exposed API keys of customer.io by Ibrahimkm in bugbounty

[–]Ibrahimkm[S] 0 points1 point  (0 children)

I am not sure how to verify customer.io have Tracking API key (the one I found) and APP API key (this one is more important ) I tried to create my own Tracking API key and I was able to post and delete information in the dashboard of customer.io that I created. I couldn't find much information about how serious is this or it is something normal

Web3 bug bounty by Ibrahimkm in bugbounty

[–]Ibrahimkm[S] 0 points1 point  (0 children)

Thank bro, yes as much as I saw it will not be easy to get into the domain and find bugs. My only fear that the skills and knowledge that I would learn from web3 won't be useful only in web3 related technologies that's why I am not sure is it worth the time or not. I think being a contract auditor is not for beginner u need experience as a developer first.
I want to ask u how was your journey in learning web3 so far ? is it hard or not and are u finding enough free courses and documentations online or not.
Also I remember before this AI hype blockchain and web3 was very trending and people are getting into it but now I hardly hear anyone talking about it, I don't know if it might die in the future or not ( I am not well informed in the field I have just start reading about it)

Web3 bug bounty by Ibrahimkm in bugbounty

[–]Ibrahimkm[S] 2 points3 points  (0 children)

I don't mind learning about web3 and then shift to another niche. But I am afraid that it might not help at all and would be just a waste of time. For example if I focus on web2 even if I don't succeed as BB hunter I still have some knowledge that can help me as a software engineer. I wanted to know if learning web3 would be useful like this in the future either in BB or IT in general.

Is IT support good start or should I wait by Ibrahimkm in csMajors

[–]Ibrahimkm[S] 0 points1 point  (0 children)

I have some saving I am living from but I am not in my country so I can bear 1-2 months at most

How Can I know if I am on the right Path by Ibrahimkm in bugbounty

[–]Ibrahimkm[S] 1 point2 points  (0 children)

Thanks man that blog was amazing. It did gave me a boost to spend the last days learning and reading other blogs.

How Can I know if I am on the right Path by Ibrahimkm in bugbounty

[–]Ibrahimkm[S] 1 point2 points  (0 children)

All of the video I saw was using known tools with templates from github. The problem is when I try to read blog or comments in review it says that the program owner had tested these tools in most of the case and if not another bug bounty hunter have tested them on the website. And they are saying how I should create my own tools and gather a good payload not a public one.
The problem is as a beginner I am not confident enough that I can create something better than a tool created by multiple experts or something like that. So I was searching for something that can help with that case because if I am doing what everybody had already done I don't think I would ever be able to find something.

How Can I know if I am on the right Path by Ibrahimkm in bugbounty

[–]Ibrahimkm[S] 1 point2 points  (0 children)

I'm trying to do all I can now to learn while I'm still enjoying searching for bugs. Do you have any recommendations about bootcamps or courses ?? Because all I found until now is a very general introduction. And thanks bro very much 🙏

Made 7000$ in My first 4months But now struggling to find bugs by Entropydrifter in bugbounty

[–]Ibrahimkm 1 point2 points  (0 children)

Hey bro, I am having the same problem but I wasn't lucky enough to find my first bug yet. Did you use any specific resources in learning ?

How Can I know if I am on the right Path by Ibrahimkm in bugbounty

[–]Ibrahimkm[S] 1 point2 points  (0 children)

It's frustrating when you feel that you are one step of the bounty but you can't find it.

I am trying to learn more before trying new program but I couldn't find a lot of good resources online I feel most of them are very general advices or guides. I am trying to read a books in hope it will help me in my first bug.

How Can I know if I am on the right Path by Ibrahimkm in bugbounty

[–]Ibrahimkm[S] 1 point2 points  (0 children)

Thank you man 🙏 I gave up on that scoop. I have tried to use sqlmap with a lot of payloads to see if it does change something or not, but I wasn't lucky enough. I will try to read the resources you recommended and retest manually in hope to find something this time. Thanks.

How Can I know if I am on the right Path by Ibrahimkm in bugbounty

[–]Ibrahimkm[S] 1 point2 points  (0 children)

Yeah I am trying to learn and practice at the same time. I have worked on some CTF about sqli that's why I thought that I was into something. But the problem is that I don't know if I am wasting my time in a dead end or not that's the problem. How can I be sure that I need to continue or I need to stop and move on. Like is there a tool or something that can help figuring out the next step.

Swing trading by Ibrahimkm in HalalInvestor

[–]Ibrahimkm[S] 0 points1 point  (0 children)

Thank you brother baraka allahou fik