When I started doing bug bounty I've been using my home computer for all. Recon, host scanning, domain bruteforcing, port scanning, subdomains enumeration, screenshoting websites.…
Hello
The title might have been clickbait but it is not. I started from recon and discovered as many subdomains as possible of the target.com company.…
The cookie-based XSS
One evening I started hunting on the Terrahost Bug Bounty program. I was testing the terrahost.no main domain. There was a functionality…