knoxss

1 article
sort: new top best
clear filter
0 2/10

A researcher discovered an XSS vulnerability on payment-providers.uber.com by using subdomain enumeration (Sublist3r), directory brute-forcing (dirb), and the KNOXSS tool, earning a $500 bounty that was later revoked for being on a non-browser-facing endpoint.

UBER KNOXSS Emad Shanab brutelogic Sublist3r aquatone dirb Rob Fletcher HackerOne payment-providers.uber.com
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details