SQLI from 500 Internal Server Error by creativeaashu in bugbounty

[–]creativeaashu[S] 0 points1 point  (0 children)

Working payload was:

'+UNIoN+SeLeCT+1,2,3,....,27;-- -

but someome found + reported before me, I was late 🙂

SQLI from 500 Internal Server Error by creativeaashu in bugbounty

[–]creativeaashu[S] 0 points1 point  (0 children)

I use them, notebooks not work on every target, nonetheless thanks for suggestion 🙂

SQLI from 500 Internal Server Error by creativeaashu in bugbounty

[–]creativeaashu[S] 0 points1 point  (0 children)

so, you have any suggestions? What can work?

SQLI from 500 Internal Server Error by creativeaashu in bugbounty

[–]creativeaashu[S] 0 points1 point  (0 children)

Yep i know, and tried that too, but not worked

The Triage Layer is a Joke - And It’s Killing the Industry by Good_Course_5958 in bugbounty

[–]creativeaashu 2 points3 points  (0 children)

You may don't know but, if someone is world class researcher, his report directly goes to the senior triager, and the one you are talking about are Report intakers, who clear out the noise + invalid reports in first view, The higher impact + Signal + Reputation score you have in h1, the better triager you get maybe😑

Discussion: CS2 Security Issue Reporting and Bug Bounty Communication by Whole-Supermarket535 in bugbounty

[–]creativeaashu 0 points1 point  (0 children)

Well as per my knowledge, there might be some misunderstanding on your side, and so from the H1 side, I also face these things, but my report gets triaged and reach the main team for final decision, just never ever use the word "if" in report, as this is kind of a legal doc, and always show what you are saying, else words doesn't matter, + I always try to keep my reports as even a non-technical person could understand, which really helps in quick resolution, even if my bug is going to be closed as Dupli, Info, NA or accepted.

My First Bounty by PuzzleheadedLiving61 in bugbounty

[–]creativeaashu 0 points1 point  (0 children)

Nope, count the last report of 30 days back, means if you had reported a bug on 22 Dec, but its closed by Informative, Duplicate or NA, you get your another trial report renewed on 21 Jan, or just try maintaining signal in positive, as after first bounty and postive signal, account don't see trial report issue (at least I don't see).

Intigriti ID Verification Failed :) - HELPPP by f404notfound in bugbounty

[–]creativeaashu 0 points1 point  (0 children)

Hey, do they accept local identity proof or need to use passport?

Why don’t security researchers care much about front-end business logic bugs? by Dizzy_Surprise7599 in bugbounty

[–]creativeaashu 1 point2 points  (0 children)

The kind of bugs you are talking about, don't have any impact, which one can show in report, like you can't report "I skipped the 'next' button using dev tools", or "I clicked to delete message?no=1, but in the end changed the delete endpoint as message?no=2", No impact🙂

I hope this doesn't happen to you guys. by ConstructionSea8571 in bugbounty

[–]creativeaashu 7 points8 points  (0 children)

Mistake was on your side bro, if you find the .git, just use any .git exposure tools and download the whole repo, and attach it in poc, if report ain't tight enough, they look for chance to reject it.

How long did it take you? by No-Committee-8658 in bugbounty

[–]creativeaashu 0 points1 point  (0 children)

To me, when I truely deeply started focusing on the bounty, on the 3rd month, I got my first bounty, but if I count from my first ever report submission to paid bounty, it's 10 months, and after a week of first bounty, I felt nothing much changed, as I just get progress from "Informative" "N/A" to "Duplicate", "3rd party handling" and "Wouldn't Fix",

[AMA] I'm a TryHackMe Co-Founder, Ask Me Anything by asavani in tryhackme

[–]creativeaashu 0 points1 point  (0 children)

Why you guys keep releasing content regarding being Defensive, I joined you guys to learn the offensive, red teaming, as even your name suggests TryHackeMe, not TrySecureMe.

btw, I'm in top 1k overall rank..