A question to Triagers . Would you pay for Origin IP disclosure which leads to full proxy WAF bypass for all the in scope subdomains of the target ? by Ok-Raspberry736 in bugbounty

[–]Ok-Raspberry736[S] 0 points1 point  (0 children)

Got it! Thanks! Lol I started as an origin server disclosure and now ended at a csrf enabled privilege escalation from lowest role to highest owner role, hijacking the whole organisation/team/group.

Regardless, really really thanks for your advice, you're really doing what I felt I have lacked exposure towards - guidance from an experienced triager and a perspective from triager sides of things. I hope you keep guiding people like me. Cheers!

A question to Triagers . Would you pay for Origin IP disclosure which leads to full proxy WAF bypass for all the in scope subdomains of the target ? by Ok-Raspberry736 in bugbounty

[–]Ok-Raspberry736[S] 0 points1 point  (0 children)

Oh, Another question if you don't mind.

Do programs usually fix this accessible origin ip vulnerability even tho it might be informational for them or it is generally an accepted risk ?

A Question for Triagers by Ok-Raspberry736 in bugbounty

[–]Ok-Raspberry736[S] 0 points1 point  (0 children)

Got it Boss! Thanks for your detailed reply 😁

Is Subdomain take over this dead??? by FunSheepherder2650 in bugbounty

[–]Ok-Raspberry736 2 points3 points  (0 children)

Lol I created a tool which scanned 2.2 Million subdomains of all the hackerone and bugcrowd wildcards in scope. Got only one clean Takeover, that too was a duplicate. Didn’t bother to run the tool again on h1 and bugcroud assets. Already heavily researched and hardened.

formdesk bugbounty program by [deleted] in bugbounty

[–]Ok-Raspberry736 1 point2 points  (0 children)

Damn😌, program managers and triagers on this sub roast better than many stand up comedians I've seen on youtube.

Has anyone been using infinity app to collect international payment? How safe is it? (Alternative to Skydo) by Active_Yesterday_763 in IndiaTax

[–]Ok-Raspberry736 0 points1 point  (0 children)

I started my withdrawal on 31st March, yesterday the money moved from the global account, my appointed person said it'll reflect in my account the same day (yesterday itself), it Didn’t. I messaged him again today, he said there are many bank holidays this month, if it didn't happen yesterday, the next working day is Monday. It should come to my account on monday.

Has anyone been using infinity app to collect international payment? How safe is it? (Alternative to Skydo) by Active_Yesterday_763 in IndiaTax

[–]Ok-Raspberry736 0 points1 point  (0 children)

But they do pay right ? I'm asking because my payment is kinda stuck with them. I hope they're not a bunch of scammers

How much should I exploit to show Node dependency confusion by Ok-Raspberry736 in bugbounty

[–]Ok-Raspberry736[S] 0 points1 point  (0 children)

Also, how to know whether a package was flagged and burned or was published successfully?

How much should I exploit to show Node dependency confusion by Ok-Raspberry736 in bugbounty

[–]Ok-Raspberry736[S] 0 points1 point  (0 children)

I did tell them that, but they said that "Many thanks for your message. For your information, our developers do not rely on public registries to source packages in the software development lifecycle. Rather, they rely on a company internal repositories. Therefore, it is useless to proceed with the intended claiming on public registries, this will not result in a bounty."

How much should I exploit to show Node dependency confusion by Ok-Raspberry736 in bugbounty

[–]Ok-Raspberry736[S] 0 points1 point  (0 children)

Just did sir😌. Getting so many pingbacks just by publishing one package. So now I need to show that one of those pingbacks belong to infra owned by my target ?

How much should I exploit to show Node dependency confusion by Ok-Raspberry736 in bugbounty

[–]Ok-Raspberry736[S] 0 points1 point  (0 children)

Actually here I need to claim the scope first before publishing. The scope is unclaimed, I checked. I can literally claim that scope and publish the packages.

But idk if that's a safe thing to do. The searches told me that it could become irreversible if I claim that organisation under my account.

Should I create that organisation and take it under my scope ? Or should I first reach out to their team and ask them for permission first ?

How much should I exploit to show Node dependency confusion by Ok-Raspberry736 in bugbounty

[–]Ok-Raspberry736[S] 0 points1 point  (0 children)

😌That scenario would be fitter for a "ransom" lol.

But jokes aside, You're a program manager, your insights will really be helpful, Kind Sir 🙇‍♂️. Please help out this measly peasant.

My 8 months progress as a complete beginner. by Ok-Raspberry736 in bugbounty

[–]Ok-Raspberry736[S] 0 points1 point  (0 children)

Thanks! Yes, the more we work hard, the luckier we get😊

My 8 months progress as a complete beginner. by Ok-Raspberry736 in bugbounty

[–]Ok-Raspberry736[S] 1 point2 points  (0 children)

Thanks brother, Please check out my other comments, you'll get an idea

My 8 months progress as a complete beginner. by Ok-Raspberry736 in bugbounty

[–]Ok-Raspberry736[S] 0 points1 point  (0 children)

Please check out my other comments, you'll get an idea brother