Bug Bounty Reports Explained @gregxsunday.bsky.social · 30/06/2025GraphQL CSRF via the HEAD method #bugbounty #bugbountytips #bugbountyhunter 160
Bug Bounty Reports Explained @gregxsunday.bsky.social · 28/06/202510/10 GraphQL SQL injection bug #bugbounty #bugbountytips #bugbountyhunter 140
Bug Bounty Reports Explained @gregxsunday.bsky.social · 27/06/2025Unexpected privilege escalation deletion bug #bugbounty #bugbountytips #bugbountyhunter 110
Bug Bounty Reports Explained @gregxsunday.bsky.social · 26/06/2025Unauthenticated → Low privileges → admin #bugbounty #bugbountytips #bugbountyhunter 110
Bug Bounty Reports Explained @gregxsunday.bsky.social · 25/06/2025Sometimes, one field is all you need for a bug #bugbounty #bugbountytips #bugbountyhunter 110
Bug Bounty Reports Explained @gregxsunday.bsky.social · 24/06/2025GraphQL isn’t just an API to deliver our payloads. Often, its implementations are what actually cause them. To see what bugs it can lead to, studied disclosed bug bounty reports. IDORs, privescs, DoS, CSRFs, SQLis - it's all there. Enjoy! youtu.beEnjoy the videos and music that you love, upload original content and share it all with friends, family and the world on YouTube. 030
Bug Bounty Reports Explained @gregxsunday.bsky.social · 16/06/2025If your GraphQL testing stops at introspection and ID swapping, you’re missing out. SQLi, CSRF, caching bugs, race conditions, WebSocket bypasses - it’s all there. I studies 90 real reports to find what actually works. 020
Bug Bounty Reports Explained @gregxsunday.bsky.social · 16/06/2025Fuzzing vs broken access control bugs feat. Arthur Aires #bugbounty #bugbountytips #bugbountyhunter 000
Bug Bounty Reports Explained @gregxsunday.bsky.social · 14/06/2025This is why you should run bug bounty tools from a VPS feat. Arthur Aires #bugbounty #bugbountytips #bugbountyhunter 000
Bug Bounty Reports Explained @gregxsunday.bsky.social · 13/06/2025Managing your blind XSS payloads feat. Arthur Aires #bugbounty #bugbountytips #bugbountyhunter 011
Bug Bounty Reports Explained @gregxsunday.bsky.social · 12/06/2025Generating target-specific wordlists feat. Arthur Aires #bugbounty #bugbountytips #bugbountyhunter 000
Bug Bounty Reports Explained @gregxsunday.bsky.social · 12/06/2025Generating target-specific wordlists feat. Arthur Aires #bugbounty #bugbountytips #bugbountyhunter 010
Bug Bounty Reports Explained @gregxsunday.bsky.social · 11/06/2025Automation to get Hackerone program updates feat. Arthur Aires #bugbounty #bugbountytips #bugbountyhunter 020
Bug Bounty Reports Explained @gregxsunday.bsky.social · 10/06/2025In today’s episode, Arthur Aires shares his bug bounty methodology which starts with heavy fuzzing and automation to find the best assets for manual exploitation and escalation. Enjoy!🔥 youtu.beEnjoy the videos and music that you love, upload original content and share it all with friends, family and the world on YouTube. 010
Bug Bounty Reports Explained @gregxsunday.bsky.social · 28/05/2025In this video, Arthur Aires walks us through two real-world deserialization RCEs that include bypassing a class allowlist and then exfiltrating data via DNS. Techniques you'll want in your toolbox. Enjoy! youtu.beEnjoy the videos and music that you love, upload original content and share it all with friends, family and the world on YouTube. 030
Bug Bounty Reports Explained @gregxsunday.bsky.social · 21/05/2025An ATO that doesn’t make sense feat. Jasmin “JR0ch17” Landry #bugbounty #bugbountytips #bugbountyhunter 030
Bug Bounty Reports Explained @gregxsunday.bsky.social · 20/05/2025Manipulating referer policy when DOM Purify is used feat. Jasmin “JR0ch17” Landry #bugbounty #bugbountytips #bugbountyhunter 000
Bug Bounty Reports Explained @gregxsunday.bsky.social · 19/05/2025SQLi still exists in 2025 feat. Jasmin “JR0ch17” Landry #bugbounty #bugbountytips #bugbountyhunter 000
Bug Bounty Reports Explained @gregxsunday.bsky.social · 17/05/2025Using match and replace rules for quickly applying polyglot payloads feat. Jasmin “JR0ch17” Landry #bugbounty #bugbountytips #bugbountyhunter 011
Bug Bounty Reports Explained @gregxsunday.bsky.social · 16/05/2025Second order injections feat. Jasmin “JR0ch17” Landry #bugbounty #bugbountytips #bugbountyhunter 000
Bug Bounty Reports Explained @gregxsunday.bsky.social · 14/05/2025In this episode, Jasmin “JR0ch17” Landry breaks down how he consistently lands highs and crits - from SSRFs to less common bugs like XXEs and SQLis. Enjoy🔥 youtu.beEnjoy the videos and music that you love, upload original content and share it all with friends, family and the world on YouTube. 020
Bug Bounty Reports Explained @gregxsunday.bsky.social · 19/03/2025Hunting for privilege escalations by modifying the JS feat. @renniepak.nl #bugbounty #bugbountytips #bugbountyhunter 010
Bug Bounty Reports Explained @gregxsunday.bsky.social · 18/03/2025$50k XSS in a web3 website feat. @renniepak.nl #bugbounty #bugbountytips #bugbountyhunter 030
Bug Bounty Reports Explained @gregxsunday.bsky.social · 17/03/2025The CSPBypass website feat. @renniepak.nl #bugbounty #bugbountytips #bugbountyhunter 110
Bug Bounty Reports Explained @gregxsunday.bsky.social · 15/03/2025The mysterious bug bounty methodology 000
Bug Bounty Reports Explained @gregxsunday.bsky.social · 14/03/2025Using javascript bookmarks to speed up bug hunting feat. @renniepak.nl #bugbounty #bugbountytips #bugbountyhunter 070
Bug Bounty Reports Explained @gregxsunday.bsky.social · 13/03/2025An XSS payload tattooed on the forearm feat. @renniepak.nl #bugbounty #bugbountytips #bugbountyhunter 040
Bug Bounty Reports Explained @gregxsunday.bsky.social · 12/03/2025XSS is still the most common bug class that can be insanely profitable if you master it like my today's guest - Renniepak. In this interview, we talk XSS, CSP bypasses, access control, JS bookmarks, and more... Enjoy🔥 youtu.beEnjoy the videos and music that you love, upload original content and share it all with friends, family and the world on YouTube. 161
Bug Bounty Reports Explained @gregxsunday.bsky.social · 22/02/2025My favourite bug bounty moment of 2024 #bugbounty #bugbountytips #bugbountyhunter 010
Bug Bounty Reports Explained @gregxsunday.bsky.social · 21/02/2025Are client-side RCEs a big part of my hunting style? #bugbounty #bugbountytips #bugbountyhunter 010
Bug Bounty Reports Explained @gregxsunday.bsky.social · 21/02/2025I am discontinuing BBRE Premium in its membership form. 120
Bug Bounty Reports Explained @gregxsunday.bsky.social · 20/02/2025Hackbots for looking for privilege escalation bugs? #bugbounty #bugbountytips #bugbountyhunter 000
Bug Bounty Reports Explained @gregxsunday.bsky.social · 19/02/2025The biggest change I made in my bug bounty hunting in 2024 #bugbounty #bugbountytips #bugbountyhunter 000
Bug Bounty Reports Explained @gregxsunday.bsky.social · 19/02/2025My 2024 bug bounty recap. This episode goes over my most common findings, key lessons learned, changes in my bug bounty methodology, and, as always, a full breakdown of my earnings. Enjoy🔥 youtu.beEnjoy the videos and music that you love, upload original content and share it all with friends, family and the world on YouTube. 020
Bug Bounty Reports Explained @gregxsunday.bsky.social · 13/02/2025I decided to take a look at the 2024 and choose the best bug bounty writeups, blogposts and tools, as well as the most underrated reports of the year. Enjoy🔥 youtu.beEnjoy the videos and music that you love, upload original content and share it all with friends, family and the world on YouTube. 052
Reposted by Bug Bounty Reports Explainedrenniepak @renniepak.nl · 13/02/2025Found a handy new CSP bypass gadget on Snapchat: cspbypass.com#snapchat 1224
Bug Bounty Reports Explained @gregxsunday.bsky.social · 28/01/2025Inside the FBI’s Secret Encrypted Phone Company ‘Anom’ - Joseph Cox by @josephfcox www.youtube.com/watch?v=uFyk5UOyNqI #BBRENewsletter87 010
Reposted by Bug Bounty Reports ExplainedMikhail Shcherbakov @yu5k3.bsky.social · 25/01/2025If you want to hear cool BB stories about how I used these gadgets, check out the #DEFCON talk youtu.be/H-bhmSwnRdYyoutu.beDEF CON 32 - Exploiting the Unexploitable Insights from the Kibana Bug Bounty - Mikhail ShcherbakovYouTube video by DEFCONConference 012
Bug Bounty Reports Explained @gregxsunday.bsky.social · 27/01/2025DoubleClickjacking: A new era of UI redressing? by @PaulosYibelo www.paulosyibelo.com/2024/12/double… #BBRENewsletter87 020
Bug Bounty Reports Explained @gregxsunday.bsky.social · 27/01/2025ReDoS - Regular Expression Denial of Service feat. @joaxcar.bsky.social #bugbounty #bugbountytips #bugbountyhunter 020
Bug Bounty Reports Explained @gregxsunday.bsky.social · 25/01/2025Server-Side Prototype Pollution gadget collection github.com/KTH-LangSec/server-side-… #BBRENewsletter87 1111
Bug Bounty Reports Explained @gregxsunday.bsky.social · 25/01/202520 DoS bugs in GitLab in one year feat. @joaxcar.bsky.social #bugbounty #bugbountytips #bugbountyhunter 060
Bug Bounty Reports Explained @gregxsunday.bsky.social · 24/01/2025Bypassing File Upload Restrictions To Exploit Client-Side Path Traversal by @doyensec blog.doyensec.com/2025/01/09/cspt-f… #BBRENewsletter87 072
Reposted by Bug Bounty Reports ExplainedMastering Burp Suite @mastering-burp.agarri.fr · 03/01/2025A nice tip Match & Replace from Intigriti... 💎 Replace `Content-Type: application/json` with `Content-Type: application/xml` in requests and look for XML parsing errors in responses 🛠️ That will allow you to identify XML-processing endpoints 🧠 0194
Bug Bounty Reports Explained @gregxsunday.bsky.social · 24/01/2025DOM clobbering is more useful than you think feat. @joaxcar.bsky.social #bugbounty #bugbountytips #bugbountyhunter 020
Bug Bounty Reports Explained @gregxsunday.bsky.social · 24/01/2025What was your favourite bug bounty writeup of 2024? 030
Bug Bounty Reports Explained @gregxsunday.bsky.social · 23/01/2025Signature Verification Bypass in Nuclei by @wiz_io www.wiz.io/blog/nuclei-signature-ve… #BBRENewsletter87 020
Bug Bounty Reports Explained @gregxsunday.bsky.social · 23/01/2025Little known trick to bypass CSP feat. @joaxcar.bsky.social #bugbounty #bugbountytips #bugbountyhunter 081
Bug Bounty Reports Explained @gregxsunday.bsky.social · 22/01/2025SQL Injection Isn't Dead Smuggling Queries at the Protocol Level by @pspaul95 www.youtube.com/watch?v=Tfg1B8u1yvE #BBRENewsletter87 010
Bug Bounty Reports Explained @gregxsunday.bsky.social · 22/01/2025A severe browser bug found during a bus ride from work feat. @joaxcar.bsky.social #bugbounty #bugbountytips #bugbountyhunter 030