Sign in

Bug Bounty Reports Explained

@gregxsunday.bsky.social
535 followers 103 following 96 posts
PostsRepliesMedia
Bug Bounty Reports Explained @gregxsunday.bsky.social · 30/06/2025
GraphQL CSRF via the HEAD method #bugbounty #bugbountytips #bugbountyhunter
160
Bug Bounty Reports Explained @gregxsunday.bsky.social · 28/06/2025
10/10 GraphQL SQL injection bug #bugbounty #bugbountytips #bugbountyhunter
140
Bug Bounty Reports Explained @gregxsunday.bsky.social · 27/06/2025
Unexpected privilege escalation deletion bug #bugbounty #bugbountytips #bugbountyhunter
110
Bug Bounty Reports Explained @gregxsunday.bsky.social · 26/06/2025
Unauthenticated → Low privileges → admin #bugbounty #bugbountytips #bugbountyhunter
110
Bug Bounty Reports Explained @gregxsunday.bsky.social · 25/06/2025
Sometimes, one field is all you need for a bug #bugbounty #bugbountytips #bugbountyhunter
110
Bug Bounty Reports Explained @gregxsunday.bsky.social · 24/06/2025
GraphQL isn’t just an API to deliver our payloads. Often, its implementations are what actually cause them. To see what bugs it can lead to, studied disclosed bug bounty reports. IDORs, privescs, DoS, CSRFs, SQLis - it's all there. Enjoy!
youtu.be
Enjoy the videos and music that you love, upload original content and share it all with friends, family and the world on YouTube.
030
Bug Bounty Reports Explained @gregxsunday.bsky.social · 16/06/2025
If your GraphQL testing stops at introspection and ID swapping, you’re missing out. SQLi, CSRF, caching bugs, race conditions, WebSocket bypasses - it’s all there. I studies 90 real reports to find what actually works.
020
Bug Bounty Reports Explained @gregxsunday.bsky.social · 16/06/2025
Fuzzing vs broken access control bugs feat. Arthur Aires #bugbounty #bugbountytips #bugbountyhunter
000
Bug Bounty Reports Explained @gregxsunday.bsky.social · 14/06/2025
This is why you should run bug bounty tools from a VPS feat. Arthur Aires #bugbounty #bugbountytips #bugbountyhunter
000
Bug Bounty Reports Explained @gregxsunday.bsky.social · 13/06/2025
Managing your blind XSS payloads feat. Arthur Aires #bugbounty #bugbountytips #bugbountyhunter
011
Bug Bounty Reports Explained @gregxsunday.bsky.social · 12/06/2025
Generating target-specific wordlists feat. Arthur Aires #bugbounty #bugbountytips #bugbountyhunter
000
Bug Bounty Reports Explained @gregxsunday.bsky.social · 12/06/2025
Generating target-specific wordlists feat. Arthur Aires #bugbounty #bugbountytips #bugbountyhunter
010
Bug Bounty Reports Explained @gregxsunday.bsky.social · 11/06/2025
Automation to get Hackerone program updates feat. Arthur Aires #bugbounty #bugbountytips #bugbountyhunter
020
Bug Bounty Reports Explained @gregxsunday.bsky.social · 10/06/2025
In today’s episode, Arthur Aires shares his bug bounty methodology which starts with heavy fuzzing and automation to find the best assets for manual exploitation and escalation. Enjoy!🔥
youtu.be
Enjoy the videos and music that you love, upload original content and share it all with friends, family and the world on YouTube.
010
Bug Bounty Reports Explained @gregxsunday.bsky.social · 28/05/2025
In this video, Arthur Aires walks us through two real-world deserialization RCEs that include bypassing a class allowlist and then exfiltrating data via DNS. Techniques you'll want in your toolbox. Enjoy!
youtu.be
Enjoy the videos and music that you love, upload original content and share it all with friends, family and the world on YouTube.
030
Bug Bounty Reports Explained @gregxsunday.bsky.social · 21/05/2025
An ATO that doesn’t make sense feat. Jasmin “JR0ch17” Landry #bugbounty #bugbountytips #bugbountyhunter
030
Bug Bounty Reports Explained @gregxsunday.bsky.social · 20/05/2025
Manipulating referer policy when DOM Purify is used feat. Jasmin “JR0ch17” Landry #bugbounty #bugbountytips #bugbountyhunter
000
Bug Bounty Reports Explained @gregxsunday.bsky.social · 19/05/2025
SQLi still exists in 2025 feat. Jasmin “JR0ch17” Landry #bugbounty #bugbountytips #bugbountyhunter
000
Bug Bounty Reports Explained @gregxsunday.bsky.social · 17/05/2025
Using match and replace rules for quickly applying polyglot payloads feat. Jasmin “JR0ch17” Landry #bugbounty #bugbountytips #bugbountyhunter
011
Bug Bounty Reports Explained @gregxsunday.bsky.social · 16/05/2025
Second order injections feat. Jasmin “JR0ch17” Landry #bugbounty #bugbountytips #bugbountyhunter
000
Bug Bounty Reports Explained @gregxsunday.bsky.social · 14/05/2025
In this episode, Jasmin “JR0ch17” Landry breaks down how he consistently lands highs and crits - from SSRFs to less common bugs like XXEs and SQLis. Enjoy🔥
youtu.be
Enjoy the videos and music that you love, upload original content and share it all with friends, family and the world on YouTube.
020
Bug Bounty Reports Explained @gregxsunday.bsky.social · 19/03/2025
Hunting for privilege escalations by modifying the JS feat. @renniepak.nl #bugbounty #bugbountytips #bugbountyhunter
010
Bug Bounty Reports Explained @gregxsunday.bsky.social · 18/03/2025
$50k XSS in a web3 website feat. @renniepak.nl #bugbounty #bugbountytips #bugbountyhunter
030
Bug Bounty Reports Explained @gregxsunday.bsky.social · 17/03/2025
The CSPBypass website feat. @renniepak.nl #bugbounty #bugbountytips #bugbountyhunter
110
Bug Bounty Reports Explained @gregxsunday.bsky.social · 15/03/2025
The mysterious bug bounty methodology
000
Bug Bounty Reports Explained @gregxsunday.bsky.social · 14/03/2025
Using javascript bookmarks to speed up bug hunting feat. @renniepak.nl #bugbounty #bugbountytips #bugbountyhunter
070
Bug Bounty Reports Explained @gregxsunday.bsky.social · 13/03/2025
An XSS payload tattooed on the forearm feat. @renniepak.nl  #bugbounty #bugbountytips #bugbountyhunter
040
Bug Bounty Reports Explained @gregxsunday.bsky.social · 12/03/2025
XSS is still the most common bug class that can be insanely profitable if you master it like my today's guest - Renniepak. In this interview, we talk XSS, CSP bypasses, access control, JS bookmarks, and more... Enjoy🔥
youtu.be
Enjoy the videos and music that you love, upload original content and share it all with friends, family and the world on YouTube.
161
Bug Bounty Reports Explained @gregxsunday.bsky.social · 22/02/2025
My favourite bug bounty moment of 2024 #bugbounty #bugbountytips #bugbountyhunter
010
Bug Bounty Reports Explained @gregxsunday.bsky.social · 21/02/2025
Are client-side RCEs a big part of my hunting style? #bugbounty #bugbountytips #bugbountyhunter
010
Bug Bounty Reports Explained @gregxsunday.bsky.social · 21/02/2025
I am discontinuing BBRE Premium in its membership form.
120
Bug Bounty Reports Explained @gregxsunday.bsky.social · 20/02/2025
Hackbots for looking for privilege escalation bugs? #bugbounty #bugbountytips #bugbountyhunter
000
Bug Bounty Reports Explained @gregxsunday.bsky.social · 19/02/2025
The biggest change I made in my bug bounty hunting in 2024 #bugbounty #bugbountytips #bugbountyhunter
000
Bug Bounty Reports Explained @gregxsunday.bsky.social · 19/02/2025
My 2024 bug bounty recap. This episode goes over my most common findings, key lessons learned, changes in my bug bounty methodology, and, as always, a full breakdown of my earnings. Enjoy🔥
youtu.be
Enjoy the videos and music that you love, upload original content and share it all with friends, family and the world on YouTube.
020
Bug Bounty Reports Explained @gregxsunday.bsky.social · 13/02/2025
I decided to take a look at the 2024 and choose the best bug bounty writeups, blogposts and tools, as well as the most underrated reports of the year. Enjoy🔥
youtu.be
Enjoy the videos and music that you love, upload original content and share it all with friends, family and the world on YouTube.
052
Reposted by Bug Bounty Reports Explained
renniepak @renniepak.nl · 13/02/2025
Found a handy new CSP bypass gadget on Snapchat: cspbypass.com#snapchat
<script src="https://tr.snapchat.com/config/com/%27%29%7d%63%61%74%63%68%28%65%29%7b%7d%7d%28%29%3b%61%6c%65%72%74%28%31%29%2f%2f.js"></script>
1224
Bug Bounty Reports Explained @gregxsunday.bsky.social · 28/01/2025
Inside the FBI’s Secret Encrypted Phone Company ‘Anom’ - Joseph Cox by @josephfcox www.youtube.com/watch?v=uFyk5UOyNqI #BBRENewsletter87
010
Reposted by Bug Bounty Reports Explained
Mikhail Shcherbakov @yu5k3.bsky.social · 25/01/2025
If you want to hear cool BB stories about how I used these gadgets, check out the #DEFCON talk youtu.be/H-bhmSwnRdY
youtu.be
DEF CON 32 - Exploiting the Unexploitable Insights from the Kibana Bug Bounty - Mikhail Shcherbakov
YouTube video by DEFCONConference
012
Bug Bounty Reports Explained @gregxsunday.bsky.social · 27/01/2025
DoubleClickjacking: A new era of UI redressing? by @PaulosYibelo www.paulosyibelo.com/2024/12/double… #BBRENewsletter87
020
Bug Bounty Reports Explained @gregxsunday.bsky.social · 27/01/2025
ReDoS - Regular Expression Denial of Service feat. @joaxcar.bsky.social #bugbounty #bugbountytips #bugbountyhunter
020
Bug Bounty Reports Explained @gregxsunday.bsky.social · 25/01/2025
Server-Side Prototype Pollution gadget collection github.com/KTH-LangSec/server-side-… #BBRENewsletter87
1111
Bug Bounty Reports Explained @gregxsunday.bsky.social · 25/01/2025
20 DoS bugs in GitLab in one year feat. @joaxcar.bsky.social #bugbounty #bugbountytips #bugbountyhunter
060
Bug Bounty Reports Explained @gregxsunday.bsky.social · 24/01/2025
Bypassing File Upload Restrictions To Exploit Client-Side Path Traversal by @doyensec blog.doyensec.com/2025/01/09/cspt-f… #BBRENewsletter87
072
Reposted by Bug Bounty Reports Explained
Mastering Burp Suite @mastering-burp.agarri.fr · 03/01/2025
A nice tip Match & Replace from Intigriti... 💎 Replace `Content-Type: application/json` with `Content-Type: application/xml` in requests and look for XML parsing errors in responses 🛠️ That will allow you to identify XML-processing endpoints 🧠
0194
Bug Bounty Reports Explained @gregxsunday.bsky.social · 24/01/2025
DOM clobbering is more useful than you think feat. @joaxcar.bsky.social #bugbounty #bugbountytips #bugbountyhunter
020
Bug Bounty Reports Explained @gregxsunday.bsky.social · 24/01/2025
What was your favourite bug bounty writeup of 2024?
030
Bug Bounty Reports Explained @gregxsunday.bsky.social · 23/01/2025
Signature Verification Bypass in Nuclei by @wiz_io www.wiz.io/blog/nuclei-signature-ve… #BBRENewsletter87
020
Bug Bounty Reports Explained @gregxsunday.bsky.social · 23/01/2025
Little known trick to bypass CSP feat. @joaxcar.bsky.social #bugbounty #bugbountytips #bugbountyhunter
081
Bug Bounty Reports Explained @gregxsunday.bsky.social · 22/01/2025
SQL Injection Isn't Dead Smuggling Queries at the Protocol Level by @pspaul95 www.youtube.com/watch?v=Tfg1B8u1yvE #BBRENewsletter87
010
Bug Bounty Reports Explained @gregxsunday.bsky.social · 22/01/2025
A severe browser bug found during a bus ride from work feat. @joaxcar.bsky.social #bugbounty #bugbountytips #bugbountyhunter
030