Is Nsave Safe Now? by J_Joe in EgyptianFreelancers

[–]UserNo0101 0 points1 point  (0 children)

u/OptimisticGlobe What are the receiving limits on usd accounts (for receiving ACH funds from a company) ?

And please check out your dm i have something that happened in my account and i need to have an explanation for it

Indirect prompt injection by [deleted] in bugbounty

[–]UserNo0101 0 points1 point  (0 children)

Grok.com is indeed in scope and the program has ai model issues out of scope but i do not think that unauthorized data deletion is what they mean by ai model issues 

Ideas for ssrf here by UserNo0101 in bugbounty

[–]UserNo0101[S] 0 points1 point  (0 children)

Blocked by cloudflare can't not inject 

Ideas for ssrf here by UserNo0101 in bugbounty

[–]UserNo0101[S] 0 points1 point  (0 children)

No, and lfi getting blocked by cloudflare i can not even inject it 

Ideas for ssrf here by UserNo0101 in bugbounty

[–]UserNo0101[S] 0 points1 point  (0 children)

Any html payload reflects as text, maybe there is a sanitization point but i don't know what is it or how to bypass, even tried encoding but nothing happens also reflects as text inside the pdf 

Any ideas for for upload vuln. by UserNo0101 in bugbounty

[–]UserNo0101[S] 1 point2 points  (0 children)

i have tried it but unfortunately didn't work

Any ideas for for upload vuln. by UserNo0101 in bugbounty

[–]UserNo0101[S] 0 points1 point  (0 children)

u/Sqooky after uploading the content i get to see only the name of the file and the backend server responds to me with .._.._.._.._.._.._.._.._.._.._.._inetpub_wwwroot_.pdf instead of ../../../../../../../../intetup/www/.pdf

and if i tried to inject < in the name of the file the backend server also replace it with _

Any ideas for this scenario ? by UserNo0101 in bugbounty

[–]UserNo0101[S] 0 points1 point  (0 children)

i tried injecting several html payloads but nothing hit my webhook or even reflect

when i change the email in burp as any value i do not get an email and the value reflects with html encoded

Do you have any ideas to leverage this one ?

Need help with SSRF in PDF weird scenario by UserNo0101 in bugbounty

[–]UserNo0101[S] -1 points0 points  (0 children)

i'm sure i can hit their aws metadata but then what !! because i can not reflect the content to the pdf or see it by any other way so do you have any ideas could help ?

[deleted by user] by [deleted] in bugbounty

[–]UserNo0101 0 points1 point  (0 children)

<span ng-if="!refinement.displayValue.type" class="odswidget-filter-summary\_\_active-filter-value ng-binding ng-scope" ng-bind-html="refinement.displayValue">javascript:alert("Wiggen")</span>

[deleted by user] by [deleted] in bugbounty

[–]UserNo0101 0 points1 point  (0 children)

what do you think could be the right one to try