Acumen_cyber_security

Acumen_cyber_security we can provide cyber_security related help and service's We are cyber Security helpers

๐“๐ก๐ซ๐ž๐ž ๐“๐ข๐ฉ๐ฌ ๐Ÿ๐จ๐ซ ๐๐ฎ๐  ๐๐จ๐ฎ๐ง๐ญ๐ฒ ๐‘๐ž๐ฉ๐จ๐ซ๐ญ๐ฌ ๐Ÿ‘‡ If you struggle getting your bugbounty vulns accepted (quick reject/duplicate or N/A...
21/08/2025

๐“๐ก๐ซ๐ž๐ž ๐“๐ข๐ฉ๐ฌ ๐Ÿ๐จ๐ซ ๐๐ฎ๐  ๐๐จ๐ฎ๐ง๐ญ๐ฒ ๐‘๐ž๐ฉ๐จ๐ซ๐ญ๐ฌ ๐Ÿ‘‡

If you struggle getting your bugbounty vulns accepted (quick reject/duplicate or N/A)

-> it might be that the triager doesn't want to deal with your report

๐ˆ๐ง ๐Ÿ๐š๐œ๐ญ ๐ญ๐ก๐ž๐ฒ ๐๐จ๐ง'๐ญ ๐ฐ๐š๐ง๐ญ ๐ญ๐จ ๐๐ž๐š๐ฅ ๐ฐ๐ข๐ญ๐ก ๐๐Ž๐Ž๐‘๐‹๐˜ ๐–๐‘๐ˆ๐“๐“๐„๐ ๐ซ๐ž๐ฉ๐จ๐ซ๐ญ๐ฌ

As a triager myself who did this job for 3+ years and reviewed over 2500 reports, here are 3 tips I have for everyone who plans to submit a report

-----

1. ๐…๐จ๐ซ๐ฆ๐š๐ญ/๐๐ž๐š๐ฎ๐ญ๐ข๐Ÿ๐ฒ
โ€ข If you report includes code snippets -> use indentation
โ€ข If your report has JSON/XML snippets -> use a beautifying tool
โ€ข Verbose HTTP headers? -> remove the irrelevant ones

2. ๐’๐ž๐ง๐ฌ๐ข๐ญ๐ข๐ฏ๐ž ๐ƒ๐š๐ญ๐š
โ€ข Remove passwords/tokens/JWTs/API keys
โ€ข If they are relevant-> obfuscate them
โ€ข Last thing that you is to create one more security hole

3. ๐‡๐ข๐ ๐ก๐ฅ๐ข๐ ๐ก๐ญ ๐ญ๐ก๐ž ๐ˆ๐ฌ๐ฌ๐ฎ๐ž
โ€ข When you work onreport -> it's where the problem is
โ€ข You submit a picture/video and you say "see the attached"
โ€ข But for someone who just read -> is not where to look
โ€ข Highlight with circles/squares/arrows what exactly you want to point out

๐Ÿ•ต๏ธeach time i get into API Hacking i enjoy it more :)i found secret API Key stored in insecure way then i was able to in...
07/11/2024

๐Ÿ•ต๏ธeach time i get into API Hacking i enjoy it more :)
i found secret API Key stored in insecure way then i was able to interact with API and send unauthorized requests
which i enjoyed the Manually hunting & reported it
also i made sure API Key is Valid ๐Ÿ˜‰

An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition ...
15/10/2024

An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configurations, and device API keys. With this, attackers can also create and read arbitrary files on the Expedition system.

CVSS 4.0 Severity and Vector Strings:

CNA : Palo Alto Networks , Inc.

CVSS-B : Base Score 9.2 CRITICAL ๐Ÿ’€

Vector : CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N/AU:N/R:U/V:C/RE:H/U:Amber

Stored Xss via BASF Vulnerability disclosure program Description:In a web application, there's a comment section where u...
09/10/2024

Stored Xss via BASF Vulnerability disclosure program

Description:
In a web application, there's a comment section where users can leave feedback. The application fails to properly sanitize user input before displaying it to other users.
Exploitation:
An attacker submits a comment containing a malicious script as part of the feedback. The script steals the session cookie of any user who views the comment.
Indicators:
The attacker doesn't directly observe the stolen session cookies but receives notifications whenever a new cookie is captured, confirming the successful ex*****on of the script.
Impact:
Session hijacking: The attacker can impersonate legitimate users and perform actions on their behalf, such as making unauthorized transactions or modifying account settings.

Address

Chennai
Chennai
600001

Telephone

+917550303998

Website

Alerts

Be the first to know and let us send you an email when Acumen_cyber_security posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Acumen_cyber_security:

Shortcuts

Share