dirb

2 articles
sort: new top best
clear filter
0 7/10

A bug bounty writeup demonstrating LFI-to-RCE on Deutche Telekom via path traversal in help.php parameter, escalated to command execution through Apache error log poisoning by injecting PHP code via the referer header.

Deutche Telekom Daniel Maksimovic telekom.de netweb.telekom.de aquatone dnsenum recon-ng sublist3r BurpSuite dirb
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details
0 2/10

A researcher discovered an XSS vulnerability on payment-providers.uber.com by using subdomain enumeration (Sublist3r), directory brute-forcing (dirb), and the KNOXSS tool, earning a $500 bounty that was later revoked for being on a non-browser-facing endpoint.

UBER KNOXSS Emad Shanab brutelogic Sublist3r aquatone dirb Rob Fletcher HackerOne payment-providers.uber.com
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details