Skip to main content

Posts

Showing posts from January, 2021

Making money from Google & Facebook How tough is Bug Bounty?

  Bug Bounty has become the bread and jam for many developers and it is getting tough since the year 2014. Only the hackers with deep research can get through it and those who find XSS in a intellectual way get paid. If you find and IDOR bug they defininetly say it is already know or there are changes or it is an intentional and works as expected. But what's the truth  no one knows or they wantedly close the report. Find a bug which is difficult to exploit by others. The more easy the bug the more easy it is for them to get it rejected and throw nothing at you. But if it is more difficult to reproduce. It would be tougher for them to Reject the report. I have found pretty easy bug and it was told that it is working intented or either they marked it as duplicate.. The truth..??? No one knows. Either they wantedly marked as duplicate just to escape the payment or just it is easy and anyone can find it.

YouTube bug Bypass Banned words.

  In the Settings  of YT Studio.  The Community tab has Advanced Filters  tab, that lets you enter the "Blocked Words".  For example if you enter the word "Hello" and save. Enter the Hello in different styles like "HElLo", and it gets Held for Review. But if you append an emoji it could bypass the filter at the server  and goes for review and gets displayed in the the comment section.

Facebook Page Managers disclosure bug in the comments $$$$

  In the Facebook Page General settings, the section " Page Moderation " allows you to input a list of words that never gets displayed if someone enter them in the comments. But when a Page manager, it may be an analyst, Advertiser enter those words It gets shown in the comments.  Keeping the page managers at risk of their names getting disclosed in the comments section of any post.

Does Google & Facebook share data of the users ?

 Open your Google Chrome in incognito mode and search for e commerce website. Search products like flop flops or T-shirts in it. Now, open your Facebook or Instagram app and experience it... Did you experience it in the news feed.... You see the exact products that you saw in the incognito mode. That's what is happening they are sharing it. No doubt !!!