4 entries - 8 tags

Recon is one of the most important parts of bug bounty, and also the most repetitive. This is the order and the tools that work for me, phase by phase, and the tool I built so I wouldn't have to do it all by hand again.

Here's how an unvalidated URL parameter on a government chatbot turned into a full MITM over its WebSocket: I intercepted messages, impersonated the bot, and stole other people's chat history without a session.

I explain how HTTP Request Smuggling works, how to detect it, and how to exploit it with practical examples.

In this post I'll tell you how I found a vulnerability in NASA, and how you can start looking for one too ⚡