今日重点:
1.Bheem 侦察平台,聚合了很多的工具
https://github.com/harsh-bothra/Bheem
漏洞挖掘资源
https://github.com/sushiwushi/bug-bounty-dorks
https://github.com/maurosoria/dirsearch
3.gin – a Git index file parser
https://github.com/KingOfBugbounty/KingOfBugBountyTips
漏洞报告学习
1.The YouTube bug that allowed unlisted uploads to any channel
https://medium.com/bugbountywriteup/the-youtube-bug-that-allowed-uploads-to-any-channel-3b41c7b7902a
2.Subdomain Takeovers, beyond the basics for Pentesters and Bug Bounty Hunters
3.Account Takeover(ATO) and Email verification bypass in 2mins
4.Server-Side Request Forgery using Javascript allows to exfill data from Google Metadata
https://hackerone.com/reports/530974
5.Bcrypt — Account TakeOver Due To Weak Encryption — #HR51KDB