Some unusual ideas - please evaluate

Joined
Oct 30, 2017
Messages
4
Reaction score
0
Hi All,

As bug bounties get more and more attention how valuable for a smart hunter would be the following domains

en-gb.uk
webstatic.co.uk
recaptcha.uk


For instance - crafting XSS, downgrading the SRI policies, cookie smuggling etc, perhaps someone can suggest other possible ways to establish vulnerability threads? (Only ethical please)
 
Nothing from what you mentioned has anything to do with these domains and bug hunting, so...
 
Are you sure?
They all can be utilised in my opinion, as often look same as the part of the page route, and are perfect for crafting XSS payloads.
 
Note that XSS is still the top 1 vulnerability
Ultimately it can contribute to many, as -
SSRF, cache poisoning, malicious js or Web workers injection, http2 weaknesses etc

Hope to hear some thoughts if there are areas more rewarding than others
 
Back
Top