Bug Bounty Tip | Do This Exercise Every Day to Get Better at Finding XSS Bugs!

NOTE: The Discord server has been deleted & rs0n is no longer actively bug hunting. Any future content on this channel will be focused on defensive Application Security concepts designed to help security teams protect against attackers. Information about the "Why?" behind this decision can be found in his LinkedIn post here:   / urn:li:activity:7457414267240292352   He wishes everyone the best of luck on their journey!

Three Common OAuth Misconfigurations That Lead to Account Takeover (Bug Bounty Reports)
▶︎

Three Common OAuth Misconfigurations That Lead to Account Takeover (Bug Bounty Reports)

[Part I] Bug Bounty Hunting for IDORs and Access Control Violations
▶︎

[Part I] Bug Bounty Hunting for IDORs and Access Control Violations

Bug Bounty | Scan ALL HackerOne & BugCrowd Public Programs for Cross-Site Scripting (XSS) Targets
▶︎

Bug Bounty | Scan ALL HackerOne & BugCrowd Public Programs for Cross-Site Scripting (XSS) Targets

Bug Bounty Hunting for Client-Side Injection Vulnerabilities | Part I
▶︎

Bug Bounty Hunting for Client-Side Injection Vulnerabilities | Part I

Selling Dr*gs at my Job in CHICAGO in GTA 5 RP
▶︎

Selling Dr*gs at my Job in CHICAGO in GTA 5 RP

Bug Bounty Hunting | Using Burpsuite's Match & Replace Rules to Find IDORS and Break Applications
▶︎

Bug Bounty Hunting | Using Burpsuite's Match & Replace Rules to Find IDORS and Break Applications

Chosen One, This Is Why God Kept You Single All This Time
▶︎

Chosen One, This Is Why God Kept You Single All This Time

Insecure Direct Object Reference  / IDOR Explained  // How to Bug Bounty
▶︎

Insecure Direct Object Reference / IDOR Explained // How to Bug Bounty

Is This Wish Meant to Be Fulfilled? 🧚🤲 Detailed Pick a Card Tarot Reading ✫・
▶︎

Is This Wish Meant to Be Fulfilled? 🧚🤲 Detailed Pick a Card Tarot Reading ✫・

The best methodology I've found to get Account Takeover through XSS (Free Members-Only Video!)
▶︎

The best methodology I've found to get Account Takeover through XSS (Free Members-Only Video!)

Michael Hudson: Der US-Plan zur Wiederbelebung der geoökonomischen Dominanz
▶︎

Michael Hudson: Der US-Plan zur Wiederbelebung der geoökonomischen Dominanz

The Most Powerful Manifestation Technique ... It Works So Fast It's Scary.
▶︎

The Most Powerful Manifestation Technique ... It Works So Fast It's Scary.

Don't Make This Recon Mistake // How To Bug Bounty
▶︎

Don't Make This Recon Mistake // How To Bug Bounty

My $20,000 S3 bug that leaked everyone’s attachments - S3 bucket misconfig of pre-signed URLs
▶︎

My $20,000 S3 bug that leaked everyone’s attachments - S3 bucket misconfig of pre-signed URLs

777 Portal ✨ Manifest Miracles, Abundance & Divine Alignment - Meditation Music
▶︎

777 Portal ✨ Manifest Miracles, Abundance & Divine Alignment - Meditation Music

Which XSS payloads get the biggest bounties? - Case study of 174 reports
▶︎

Which XSS payloads get the biggest bounties? - Case study of 174 reports

I Built an Untraceable OSINT Lab (Here's How)
▶︎

I Built an Untraceable OSINT Lab (Here's How)

Master Urlscan.io Dorking for Bug Bounty Hunting
▶︎

Master Urlscan.io Dorking for Bug Bounty Hunting

Nmap Tutorial to find Network Vulnerabilities
▶︎

Nmap Tutorial to find Network Vulnerabilities

Methodology for Bug Bounty Hunters to move from Recon to Manual Testing (FREE Members-Only Video)
▶︎

Methodology for Bug Bounty Hunters to move from Recon to Manual Testing (FREE Members-Only Video)