A Small URL Fuzzing make me a 200$

A Small URL Fuzzing make me a 200$

Oct 25, 2024

Hello guys hope you well , First of all Am Praveenarsh, a security researcher ,a part time hunter and a Space Researcher .

Buy me Coffee: https://buymeacoffee.com/praveenarsh0xx0

Am in more than a year in Bug bounty and penetration testings , but This is my first blog about to make a tricks in bug bounty :)

Ok lets start ..This is a small fuzzing technique to bypass using language server , ok we all know that for ex: we can translate a netherland language to english (like nl-en to us-en) in the URL like (www.target.com/en-us)behind the scenario there a particular server for each languages (some companies do )

Let’s say the vulnerable site name is target.com and this target is using a ./git folder , whenever i access the the www.target.com/.git/config/ it will blocked as 403. haa ok lets resaearch about language servers.

After some researches ,…..

Ok lets Bypass this , I suddenly open my kali and open FUZZ tool lets fuzz with the URL like ffuf -u http://target.com/FUFF/.git/config -w /wordlist.txt

Waiting…………………….

After couple of minutes i got 200 ok with the URL https://target.com/fr/.git/config , and successfully accessed .

image

Whenever I use a language path(like ““/fr ,”) , it will allow me to access the sensitive content.

Conclusion:

Don’t ignore the domains which have a language changer , not all security configurations done on all the language servers.

Submitted: 25 /04/2024

Triaged : 29/ 04/2024

And we got a bounty with 200$

¿Te gusta esta publicación?

Comprar Praveenarsh0xx0 un café

Más de Praveenarsh0xx0