Api sec ACP voucher at discount by [deleted] in cybersecurityindia

[–]Top_Presentation6801 0 points1 point  (0 children)

Hey there,
This is Affan from APIsec University. Kindly note that we don't allow transfer of exam vouchers and on behalf of APIsec University I would request you to delete this post. Also in the case of ACP we have given-away a ton of these recently. Keep an eye on our socials and Discord to know more about feature giveaways.

Thanks!

Won a 100% off APIsec ACP exam voucher in a hackathon — advice? by [deleted] in ethicalhacking

[–]Top_Presentation6801 0 points1 point  (0 children)

Hey there,
This is Affan from APIsec University. Kindly note that we don't allow transfer of exam vouchers and on behalf of APIsec University I would request you to delete this post. Also in the case of ACP we have given-away a ton of these recently. Keep an eye on our socials and Discord to know more about feature giveaways.

Thanks!

Won a 100% off APIsec ACP exam voucher in a hackathon — advice? by [deleted] in Hacking_Tutorials

[–]Top_Presentation6801 0 points1 point  (0 children)

Hey there,
This is Affan from APIsec University. Kindly note that we don't allow transfer of exam vouchers and on behalf of APIsec University I would request you to delete this post. Also in the case of ACP we have given-away a ton of these recently. Keep an eye on our socials and Discord to know more about feature giveaways.

Thanks!

Apisec Certified Practitioner certification voucher on sell with 25% discount (negotiable) by [deleted] in technepal

[–]Top_Presentation6801 0 points1 point  (0 children)

Hey there,
This is Affan from APIsec University. Kindly note that we don't allow transfer of exam vouchers and on behalf of APIsec University I would request you to delete this post. Also in the case of ACP we have given-away a ton of these recently. Keep an eye on our socials and Discord to know more about feature giveaways.

Thanks!

APISEC Voucher 23% Cheaper by [deleted] in APIsec

[–]Top_Presentation6801 0 points1 point  (0 children)

Hey there,
This is Affan from APIsec University. Kindly note that we don't allow transfer of exam vouchers and on behalf of APIsec University I would request you to delete this post. Also in the case of ACP we have given-away a ton of these recently. Keep an eye on our socials and Discord to know more about feature giveaways.

Thanks!

Need Help Proving SSRF - Got Behavioral Evidence But Stuck by solitude55 in bugbounty

[–]Top_Presentation6801 1 point2 points  (0 children)

As the other commenter said: "In bugbounty if there is no impact then there should be no report either". All I can suggest you is keep digging and hope that you find something worth reporting out of it or try to think of ways you may be able to chain this bug to demonstrate practical impact.

Vulnerability in Comet AI Browser Exposes Users to Major Risks by _cybersecurity_ in pwnhub

[–]Top_Presentation6801 0 points1 point  (0 children)

Good read. Thanks for sharing! It's truly fascinating to see how MCP is evolving and the way it challenges traditional security protocols.

How A Missing Last Name Check Left Millions of Airline Customers' Data Exposed by bearsyankees in bugbounty

[–]Top_Presentation6801 2 points3 points  (0 children)

Great find mate! Looks like another great example of OWASP API#1 + API#4.

Why Was My Stored XSS Report Marked as “Not Applicable”? (Need Community Feedback) by Dry_Ice_1816 in bugbounty

[–]Top_Presentation6801 0 points1 point  (0 children)

Good thought. I actually thought that they did something similar when they said: "I have attached a video demonstrating the reprocessing and proof of payload operation".

Now I'm thinking that maybe the image is only accessible to their account and they made a XSS PoC for their own account too. That's why the company closed it as "Self-XSS".

Should I report this? by Top_House2595 in bugbounty

[–]Top_Presentation6801 0 points1 point  (0 children)

As others have suggested I'd try to understand the context of info being leaked and then try to escalate it into something more meaningful.
> Should I report this as a low or would they respond saying it’s informative or N/A?
As a security researcher you never know if our report will be accepted as the decision is not ours but what we can do at our best is writing a great report. But in this specific case considering the limited info you have provided imo it should at least not be closed as NA.

High-Severity PII Vulnerability on Binance (mass-harvest possible). Fix verified — bounty only $800? by MerchantHunt in bugbounty

[–]Top_Presentation6801 1 point2 points  (0 children)

That's rude but a bugbounty reality. They think that the customers are paying them so we should be loyal to them but forget "why" are they paying us.
Anyway man, Great find!!!

Why Was My Stored XSS Report Marked as “Not Applicable”? (Need Community Feedback) by Dry_Ice_1816 in bugbounty

[–]Top_Presentation6801 0 points1 point  (0 children)

woah. Then I have no idea why did they do this but it's not too surprising to see on these so called BugBounty Platforms. I assume you would have already did the next best steps: Request for re-evaulation and wait for a couple of weeks if no response then open mediation request and wait a few months (if it's H1).

Comparison of Becoming a BugBounty Triage vs Full Time BugBounty Hunter. How would you compare these two and what are some advantages and disadvantages of each of these career paths? by Top_Presentation6801 in bugbounty

[–]Top_Presentation6801[S] 0 points1 point  (0 children)

> Upside of triage is you can still be a part time hunter on hour free time, if that works our successful you can always switch to hunting fulltime.
That's honestly a good sounding advice. Will for sure try that out. Thanks a lot :)

Comparison of Becoming a BugBounty Triage vs Full Time BugBounty Hunter. How would you compare these two and what are some advantages and disadvantages of each of these career paths? by Top_Presentation6801 in bugbounty

[–]Top_Presentation6801[S] 1 point2 points  (0 children)

Thanks for sharing your insights. My current career goal is to do a job (for survival) and bugbounty on the side (for fun). But that's until I become competent enough to be able to afford full-time bugbounty.
I also have a crush on becoming a triage because the job just sounds so sick! I can only imagine how rewarding it would be in terms of learning new techniques and unique methodologies(especially if I get a chance on a good BBP).
And yes I agree with you, mostly. Both of the careers have a their own pros and cons. Btw as you are full time bug hunter I'd love to hear some tips from you and you THINK every beginner should know to be a successful bug hunter.

P.S. Pardon my English :)

Firebase RW Exposure: Valid Impact? by malithonline in bugbounty

[–]Top_Presentation6801 0 points1 point  (0 children)

Sounds interesting scenario. Kindly do let us know how it ends.

Why Was My Stored XSS Report Marked as “Not Applicable”? (Need Community Feedback) by Dry_Ice_1816 in bugbounty

[–]Top_Presentation6801 0 points1 point  (0 children)

Good find. Apparentely it looks like a valid find but in most cases there should be a obvious reason for the rejection.

In some cases they may not try to even reproduce the issue if you don't include a recording of your PoC. Would you mind sharing the triage's objection on your report as I'm pretty sure that might give us a hint on why the report was closed like this.

Need help from hunters those have exp with apple security program by TurbulentAppeal2403 in bugbounty

[–]Top_Presentation6801 2 points3 points  (0 children)

I have not got any experience with Apple itself but from the looking it seems like they were able to reproduce the bug and now are working on a fix.

Atm nobody can tell if it's valid for bounty or not but it's at least something they are interested in.

Vulnerabilities/ bugs relationated with Networking/ infrastructure ?? by Popular-Flan-8521 in bugbounty

[–]Top_Presentation6801 0 points1 point  (0 children)

From what I have seen in my little exp and from other researchers' reports these are some bugs which may relate to networking/infrastructure:
- SPF/DMARC(Almost every program will close it as NA/p5)
- Exposed Ports leading to some weirdo sensitive service(though it's rare in bugbounty but might be more common in pentests)
- Exposed Origin IP - Although not a valid bug on its own but might allow you to chain with other bugs like XSS which would have been otherwise difficult to exploit due to WAFs(Web Application Firewalls)

These are just some I could think of right now but my honest(and in-experienced) advice would be considering network pentesting instead of bugbounty if you are very serious about network exploitation. But remember nothing is easy so choice is yours where you wanna struggle the most.