GraphQL CSRF via the HEAD method #bugbounty #bugbountytips #bugbountyhunter
10/10 GraphQL SQL injection bug #bugbounty #bugbountytips #bugbountyhunter
Unexpected privilege escalation deletion bug #bugbounty #bugbountytips #bugbountyhunter
Unauthenticated → Low privileges → admin #bugbounty #bugbountytips #bugbountyhunter
Sometimes, one field is all you need for a bug #bugbounty #bugbountytips #bugbountyhunter
GraphQL isn’t just an API to deliver our payloads. Often, its implementations are what actually cause them. To see what bugs it can lead to, studied disclosed bug bounty reports. IDORs, privescs, DoS, CSRFs, SQLis - it's all there. Enjoy!
Enjoy the videos and music that you love, upload original content and share it all with friends, family and the world on YouTube.
youtu.be
If your GraphQL testing stops at introspection and ID swapping, you’re missing out. SQLi, CSRF, caching bugs, race conditions, WebSocket bypasses - it’s all there. I studies 90 real reports to find what actually works.
Fuzzing vs broken access control bugs feat. Arthur Aires #bugbounty #bugbountytips #bugbountyhunter
This is why you should run bug bounty tools from a VPS feat. Arthur Aires #bugbounty #bugbountytips #bugbountyhunter
Managing your blind XSS payloads feat. Arthur Aires #bugbounty #bugbountytips #bugbountyhunter
Generating target-specific wordlists feat. Arthur Aires #bugbounty #bugbountytips #bugbountyhunter
Generating target-specific wordlists feat. Arthur Aires #bugbounty #bugbountytips #bugbountyhunter
Automation to get Hackerone program updates feat. Arthur Aires #bugbounty #bugbountytips #bugbountyhunter
In today’s episode, Arthur Aires shares his bug bounty methodology which starts with heavy fuzzing and automation to find the best assets for manual exploitation and escalation. Enjoy!🔥
Enjoy the videos and music that you love, upload original content and share it all with friends, family and the world on YouTube.
youtu.be
In this video, Arthur Aires walks us through two real-world deserialization RCEs that include bypassing a class allowlist and then exfiltrating data via DNS. Techniques you'll want in your toolbox. Enjoy!
Enjoy the videos and music that you love, upload original content and share it all with friends, family and the world on YouTube.
youtu.be
An ATO that doesn’t make sense feat. Jasmin “JR0ch17” Landry #bugbounty #bugbountytips #bugbountyhunter
Manipulating referer policy when DOM Purify is used feat. Jasmin “JR0ch17” Landry #bugbounty #bugbountytips #bugbountyhunter
SQLi still exists in 2025 feat. Jasmin “JR0ch17” Landry #bugbounty #bugbountytips #bugbountyhunter
Using match and replace rules for quickly applying polyglot payloads feat. Jasmin “JR0ch17” Landry #bugbounty #bugbountytips #bugbountyhunter
Second order injections feat. Jasmin “JR0ch17” Landry #bugbounty #bugbountytips #bugbountyhunter
In this episode, Jasmin “JR0ch17” Landry breaks down how he consistently lands highs and crits - from SSRFs to less common bugs like XXEs and SQLis. Enjoy🔥
Enjoy the videos and music that you love, upload original content and share it all with friends, family and the world on YouTube.
youtu.be
Hunting for privilege escalations by modifying the JS feat. @renniepak.nl #bugbounty #bugbountytips #bugbountyhunter
$50k XSS in a web3 website feat. @renniepak.nl #bugbounty #bugbountytips #bugbountyhunter
The CSPBypass website feat. @renniepak.nl #bugbounty #bugbountytips #bugbountyhunter
The mysterious bug bounty methodology
Using javascript bookmarks to speed up bug hunting feat. @renniepak.nl #bugbounty #bugbountytips #bugbountyhunter
An XSS payload tattooed on the forearm feat. @renniepak.nl #bugbounty #bugbountytips #bugbountyhunter
XSS is still the most common bug class that can be insanely profitable if you master it like my today's guest - Renniepak. In this interview, we talk XSS, CSP bypasses, access control, JS bookmarks, and more... Enjoy🔥
Enjoy the videos and music that you love, upload original content and share it all with friends, family and the world on YouTube.
youtu.be
My favourite bug bounty moment of 2024 #bugbounty #bugbountytips #bugbountyhunter
Are client-side RCEs a big part of my hunting style? #bugbounty #bugbountytips #bugbountyhunter