bug bounty tips(10-19 2022)
org:company filename:sftp.jsonorg:company host AND pass
user:name filename:sftp.json
user:name host AND pass
"company.com" host AND pass
示例:
{
"protocol": "sftp",
"host": "example.com",
"remotePath": "/var/www",
"username": "root",
"password": "swordfish!23"
}
org:company filename:.credentialsorg:company aws_secret_access_key OR aws_secret_key
user:name filename:.credentials
user:name aws_secret_access_key OR aws_secret_key
user:name aws_secret_access_key OR aws_secret_key
示例:
#
AWS Credentials file
[default]
aws_access_key_id = yLryKGwcGc3ez9G8YAnjeYMQOc # Informative, can't be used alone
aws_secret_access_key = nAH2VzKrMrRjySLlt8HCdFU3tM2TUuUZgh39NX
[second-profile]
aws_access_key_id = yLryKGwcGc3ez9G8YAnjeYMQOc # Informative, can't be used alone
aws_secret_access_key = nAH2VzKrMrRjySLlt8HCdFU3tM2TUuUZgh39NX
将/api/metadata和/api/resource
加入到你的字典
/api/users/login -----> 需要有two-factor认证/api/users/auth-token --------->绕过
其它学习教程。