Match & Replace is a very underrated feature of Burp Suite. I think more people should try to employ it in their test flow. My favorite rules:
✅ Simply replace false with true. This usually helps to unlock many hidden features of targeted web apps. Note in some cases it could also break the app, so be cautious here.
✅ Header manipulation. Sometimes it's a good idea to experiment with Referer, Origin, and X-Forwarded-For headers to bypass some weird WAF restrictions. I like to use localhost, or 127.0.0.1 as a value for these headers.
✅ Replacing session tokens. This one is good for testing IDORs. Alternatively, you could use the autorepeater plugin.
✅ HTTP parameter values. Sometimes after testing for a while, you could find some parameters like userRole. You could try different values, like changing from user to admin, etc.
#bugbounty#infosec#hacking
Did a little writeup of the CSP bypass I reported to PortSwigger. It might be interesting to anyone who saw the disclosed report and wonders if CSP bypasses are the new ripe low-hanging fruit!
joaxcar.com/blog/2024/02/1…
Northern Ireland's police force accidentally shared the names and work locations of every member of staff in a data breach it said would be of 'significant concern' to officers who are often targeted by militant groups reut.rs/45prsMV
An AI system developed by Google researchers can decide when to trust AI-based decisions about medical diagnoses, and when to refer to a human doctor for a second opinion.
newscientist.com/article/238275…
10K Followers 2 FollowingUser friendly unofficial HackerOne public disclosures, keeps you updated about the recently disclosed bugs.
Made With ♥ By Hackers For Hackers. - @rohsec
248K Followers 1K FollowingCofounder @hackinghub_io | Advisor @CaidoIO. I hack companies and make content about it. #NahamCon organizer. ex @hacker0x01🇮🇷
112K Followers 2 FollowingMonitor your external network, search the Internet of Things and perform empirical market research. You can also find us on https://t.co/nPLFbFy8R5
199K Followers 6K FollowingThe leading provider of crowdsourced cybersecurity solutions purpose-built to secure the digitally connected world...Unleash Ingenuity™
3.4M Followers 589 FollowingNewsweek provides in-depth analysis, news and opinion about international issues, technology, business, culture and politics.
300K Followers 93 FollowingDWS is a private intelligence organization that has been analyzing the threat of nuclear war since 1984 and offers an alert code to the public.
253K Followers 182 FollowingOfficial account of the Metasploit Project, part of the @rapid7 family.
Mastodon: @[email protected]
Slack: https://t.co/ZOLPDG2O2s
198K Followers 14K FollowingWe help professionals acquire the skills, knowledge and certificates by teaching defense through offense to advance their careers in cybersecurity.
193K Followers 412 FollowingSANS is the most trusted and by far the largest source for information & cyber security training, certification and research in the world.
117K Followers 515 FollowingMITRE ATT&CK® - A knowledge base for describing the behavior of adversaries. Replying/Following/Re-tweeting ≠ endorsement. @ https://t.co/wt46ArkZVt
216K Followers 525 FollowingWe improve the security of apps with community-led open source projects, 260 local chapters, and tens of thousands of members worldwide. Famous for OWASP Top 10
298K Followers 73 FollowingPart of @CISAgov, we respond to major incidents, analyze threats, and exchange critical cybersecurity information with partners around the world.
120K Followers 13 FollowingCySecurity News is one of the leading IT security news portal delivers news on #security #hacking #Exploit #CyberCrime & #infosec #Hacker. *
248K Followers 860 FollowingThe only magazine dedicated to the strategy and technology of information security, delivering critical business and technical information for IT professionals.
352K Followers 49 FollowingOne of the most widely read and trusted cybersecurity news sites, providing IT security professionals informed insights into the latest news and trends.
337K Followers 3K FollowingHackerOne makes security continuous.
We unite AI and human insight through a unified platform to expose risk and eliminate it.
61.9M Followers 1K FollowingIt’s our job to #GoThere and tell the most difficult stories. For breaking news, follow @CNNBRK and download the CNN app ➡️ https://t.co/7PQD7o6fLw
50.1M Followers 3 FollowingBreaking news alerts and updates from the BBC. For news, features, analysis follow @BBCWorld (international) or @BBCNews (UK). Latest sport news @BBCSport.
25.9M Followers 1K FollowingTop and breaking news, pictures and videos from Reuters. For breaking business news, follow @ReutersBiz. Our daily podcast is here: https://t.co/KO0QFy0d3a
3.9M Followers 10K FollowingBreaking news, features and more from the NY Post. Follow ➡️ @pagesix, @nypmetro, @nypostbiz, @nypostsports, @nypfashion, @nypostopinion, @vrtpod, @_nynext
21.6M Followers 1K FollowingSign up for our newsletters and alerts: https://t.co/QevH0DLQi8 | Got a tip? https://t.co/iXIigdPjEZ | For WSJ customer support: https://t.co/DZgH9n53qg