From a lame SSRF to a full $4000 RCE

From a lame SSRF to a full $4000 RCE

Hello ethical hackers and bug bounty hunters! Welcome to this bug bounty write-up where I show you how I found a Server-Side Request Forgery vulnerability (SSRF). Then, I will explain how I was able to escalate it to obtain a Remote Code Execution (RCE). Finally, you will see how it is possible to gain a full SSH shell on the vulnerable server.

If all this seems intimidating for you, let me tell you that shouldn’t be; just make sure you stick with me until the end. I promise you are going to learn many things today!


Read more on https://thehackerish.com/bug-bounty-write-up-from-ssrf-to-4000/

Download your FREE Web hacking LAB: https://thehackerish.com/owasp-top-10-lab-vm-free

Facebook Page: https://www.facebook.com/thehackerish

Follow us on Twitter: https://twitter.com/thehackerish

Avsnitt(11)

Certified Red Team Operator Review

Certified Red Team Operator Review

In this episode, I will give you my honest review of CRTO (certified red team operator certification) from Zeropoint Security. Download your FREE Web hacking LAB: https://thehackerish.com/owasp-top-1...

29 Dec 202111min

JavaScript Enumeration for bug bounty hunters

JavaScript Enumeration for bug bounty hunters

JavaScript Enumeration is a critical skill to have if you want to level up your penetration testing or bug bounty hunting game. Yet, not everyone does it, partly because it is a boring exercise or i...

24 Dec 202010min

OSCP Certification: All you need to know

OSCP Certification: All you need to know

Hello ethical hackers! In this episode, you will learn everything related to OSCP certification. What is OSCP? Why is it a strong certification? What sets it apart? What are the requirements? How to...

30 Juli 202014min

Hacking a new web application from start to finish

Hacking a new web application from start to finish

Hello ethical hackers and bug bounty hunters! I’ve recently conducted a successful penetration testing against a web application built using Google Web Toolkit, and I want to share with you the proc...

4 Juni 202015min

Bug bounty tools you should start using!

Bug bounty tools you should start using!

Hello ethical hackers and welcome to the world of hacking and bug bounty hunting. Today, I will share the tools I use to gather open source intelligence and perform subdomain enumeration. Every crafts...

27 Maj 202013min

This is how you write bug bounty reports that stand out!

This is how you write bug bounty reports that stand out!

Hello dear ethical hackers and welcome to this new article about bug bounty hunting. In this episode, you will discover my report template and learn how you can write outstanding bug bounty reports wh...

7 Maj 202015min

My bug bounty methodology and how I approach a target for the first time

My bug bounty methodology and how I approach a target for the first time

Welcome again to the Hack for Fun and Profit podcast, where we explore topics related to cyber security and bug bounty hunting. Last time, I showed you the best resources I use to stay up to date in b...

30 Apr 202018min

Populärt inom Utbildning

historiepodden-se
rss-bara-en-till-om-missbruk-medberoende-2
det-skaver
harrisons-dramatiska-historia
nu-blir-det-historia
rss-viktmedicinpodden
alska-oss
sektledare
johannes-hansen-podcast
roda-vita-rosen
not-fanny-anymore
allt-du-velat-veta
rss-sjalsligt-avkladd
rikatillsammans-om-privatekonomi-rikedom-i-livet
sa-in-i-sjalen
polisutbildningspodden
i-vantan-pa-katastrofen
rss-max-tant-med-max-villman
rss-om-vi-ska-vara-arliga
rss-relationsrevolutionen