Bug Bounty Hunting Hub

17 resources available

Everything you need to know about bug bounty hunting, from basics to advanced techniques

All Resources

Prototype Pollution: Engine Internals, Node.js Gadget Chains, and Hardening Architecture

A deep technical dissection of JavaScript prototype pollution: V8 object shapes, server-side gadget chains in Node.js child_process and template engines, client-side DOM vectors, and strong runtime mitigations.

A deep technical dissection of JavaScript prototype pollution: V8 object shapes, server-side gadget chains in Node.js child_process and template engines, client-side DOM vectors, and strong runtime mitigations.

13 min read
2,587 words
İS

ibrahimsql

Cybersecurity Engineer

Read More

Prototype Pollution: V8 Motor İç Mekanikleri, Node.js Gadget Zincirleri ve Savunma Mimarisi

JavaScript prototip kirlenmesinin derin teknik analizi: V8 nesne modelleri, child_process ve şablon motorları üzerinden sunucu taraflı RCE zincirleri, istemci taraflı DOM vektörleri ve çalışma zamanı sertleştirme mimarileri.

JavaScript prototip kirlenmesinin derin teknik analizi: V8 nesne modelleri, child_process ve şablon motorları üzerinden sunucu taraflı RCE zincirleri, istemci taraflı DOM vektörleri ve çalışma zamanı sertleştirme mimarileri.

13 dk okuma
2,432 words
İS

ibrahimsql

Cybersecurity Engineer

Read More

Güvenli Next.js Uygulama Yapısı: Küçük Ekipler İçin Pratik Kontrol Listesi

Next.js projelerinde rota, environment değişkenleri, form güvenliği ve SEO temellerini aynı anda sağlamlaştırmak için uygulanabilir bir rehber.

Next.js projelerinde rota, environment değişkenleri, form güvenliği ve SEO temellerini aynı anda sağlamlaştırmak için uygulanabilir bir rehber.

10 dk okuma
1,842 words
İS

ibrahimsql

Cybersecurity Engineer

Read More

TwoMillion: Davet Kodundan Root'a

HackTheBox TwoMillion makinesinin nmap'ten root'a giden tam çözüm zinciri: obfuscated JS'ten davet kodu, BOLA ile admin, command injection, .env şifre tekrarı ve CVE-2023-0386.

HackTheBox TwoMillion makinesinin nmap'ten root'a giden tam çözüm zinciri: obfuscated JS'ten davet kodu, BOLA ile admin, command injection, .env şifre tekrarı ve CVE-2023-0386.

8 dk okuma
1,531 words
İS

ibrahimsql

Cybersecurity Engineer

Read More

Bypassing WAFs with Unicode Compatibility

When a WAF inspects input before Unicode normalization but the backend processes it after, compatibility characters can slip through.

When a WAF inspects input before Unicode normalization but the backend processes it after, compatibility characters can slip through.

10 min read
1,951 words
İS

ibrahimsql

Cybersecurity Engineer

Read More