<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>
	Comments on: WRITE UP – GOOGLE BUG BOUNTY: LFI ON PRODUCTION SERVERS in &#8220;springboard.google.com&#8221; &#8211; $13,337 USD	</title>
	<atom:link href="/write-up-google-bug-bounty-lfi-on-production-servers-in-redacted-google-com-13337-usd/feed/" rel="self" type="application/rss+xml" />
	<link>/write-up-google-bug-bounty-lfi-on-production-servers-in-redacted-google-com-13337-usd/</link>
	<description>just another security blog.</description>
	<lastBuildDate>Fri, 07 Jan 2022 23:23:23 +0000</lastBuildDate>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=5.9.3</generator>
	<item>
		<title>
		By: Binamra		</title>
		<link>/write-up-google-bug-bounty-lfi-on-production-servers-in-redacted-google-com-13337-usd/#comment-6937</link>

		<dc:creator><![CDATA[Binamra]]></dc:creator>
		<pubDate>Sun, 14 Feb 2021 13:30:43 +0000</pubDate>
		<guid isPermaLink="false">http://e02.omespino.com/?p=457#comment-6937</guid>

					<description><![CDATA[Hey bro i am also learning bug bounty. It&#039;s been about 6 months. What i do is directly hunt on website. Don&#039;t know much about recon, can you explain little on how to do recon because haven&#039;t go more then 3 valid bugs i think this is because not doing any recon and others things.. Any tips bro ?]]></description>
			<content:encoded><![CDATA[<p>Hey bro i am also learning bug bounty. It&#8217;s been about 6 months. What i do is directly hunt on website. Don&#8217;t know much about recon, can you explain little on how to do recon because haven&#8217;t go more then 3 valid bugs i think this is because not doing any recon and others things.. Any tips bro ?</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: milad		</title>
		<link>/write-up-google-bug-bounty-lfi-on-production-servers-in-redacted-google-com-13337-usd/#comment-6552</link>

		<dc:creator><![CDATA[milad]]></dc:creator>
		<pubDate>Sun, 28 Jun 2020 13:04:15 +0000</pubDate>
		<guid isPermaLink="false">http://e02.omespino.com/?p=457#comment-6552</guid>

					<description><![CDATA[Hey, congratulation and thank you for all this information.

Could you please share the report that you send to google, to see the template and how you write  report ? 

Thank you !]]></description>
			<content:encoded><![CDATA[<p>Hey, congratulation and thank you for all this information.</p>
<p>Could you please share the report that you send to google, to see the template and how you write  report ? </p>
<p>Thank you !</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: pinudsdos		</title>
		<link>/write-up-google-bug-bounty-lfi-on-production-servers-in-redacted-google-com-13337-usd/#comment-6416</link>

		<dc:creator><![CDATA[pinudsdos]]></dc:creator>
		<pubDate>Fri, 03 Apr 2020 20:04:08 +0000</pubDate>
		<guid isPermaLink="false">http://e02.omespino.com/?p=457#comment-6416</guid>

					<description><![CDATA[Годнота спасибо]]></description>
			<content:encoded><![CDATA[<p>Годнота спасибо</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Anonymous		</title>
		<link>/write-up-google-bug-bounty-lfi-on-production-servers-in-redacted-google-com-13337-usd/#comment-6239</link>

		<dc:creator><![CDATA[Anonymous]]></dc:creator>
		<pubDate>Sat, 01 Feb 2020 06:02:28 +0000</pubDate>
		<guid isPermaLink="false">http://e02.omespino.com/?p=457#comment-6239</guid>

					<description><![CDATA[Thanks in support of sharing such a good idea, article is good, thats 
why i have read it entirely]]></description>
			<content:encoded><![CDATA[<p>Thanks in support of sharing such a good idea, article is good, thats<br />
why i have read it entirely</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: omespino		</title>
		<link>/write-up-google-bug-bounty-lfi-on-production-servers-in-redacted-google-com-13337-usd/#comment-6053</link>

		<dc:creator><![CDATA[omespino]]></dc:creator>
		<pubDate>Tue, 19 Nov 2019 16:40:09 +0000</pubDate>
		<guid isPermaLink="false">http://e02.omespino.com/?p=457#comment-6053</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;/write-up-google-bug-bounty-lfi-on-production-servers-in-redacted-google-com-13337-usd/#comment-6049&quot;&gt;Aditya&lt;/a&gt;.

Hey, I just update this blog with some slides about my talk in google security yearly event called ESCAL8 where I describe in more specific detail how I have found this but, and also explain how I have found that parameter, thanks for reading]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="/write-up-google-bug-bounty-lfi-on-production-servers-in-redacted-google-com-13337-usd/#comment-6049">Aditya</a>.</p>
<p>Hey, I just update this blog with some slides about my talk in google security yearly event called ESCAL8 where I describe in more specific detail how I have found this but, and also explain how I have found that parameter, thanks for reading</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Aditya		</title>
		<link>/write-up-google-bug-bounty-lfi-on-production-servers-in-redacted-google-com-13337-usd/#comment-6049</link>

		<dc:creator><![CDATA[Aditya]]></dc:creator>
		<pubDate>Mon, 18 Nov 2019 22:43:52 +0000</pubDate>
		<guid isPermaLink="false">http://e02.omespino.com/?p=457#comment-6049</guid>

					<description><![CDATA[I really want to know how did you find that file parameter? After ANOTHER_DIR]]></description>
			<content:encoded><![CDATA[<p>I really want to know how did you find that file parameter? After ANOTHER_DIR</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: omespino		</title>
		<link>/write-up-google-bug-bounty-lfi-on-production-servers-in-redacted-google-com-13337-usd/#comment-5940</link>

		<dc:creator><![CDATA[omespino]]></dc:creator>
		<pubDate>Thu, 03 Oct 2019 20:05:54 +0000</pubDate>
		<guid isPermaLink="false">http://e02.omespino.com/?p=457#comment-5940</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;/write-up-google-bug-bounty-lfi-on-production-servers-in-redacted-google-com-13337-usd/#comment-5931&quot;&gt;0x1bitcrack3r&lt;/a&gt;.

Thank you for reading thanks for your comments, happy hunting.]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="/write-up-google-bug-bounty-lfi-on-production-servers-in-redacted-google-com-13337-usd/#comment-5931">0x1bitcrack3r</a>.</p>
<p>Thank you for reading thanks for your comments, happy hunting.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: 0x1bitcrack3r		</title>
		<link>/write-up-google-bug-bounty-lfi-on-production-servers-in-redacted-google-com-13337-usd/#comment-5931</link>

		<dc:creator><![CDATA[0x1bitcrack3r]]></dc:creator>
		<pubDate>Thu, 03 Oct 2019 06:07:34 +0000</pubDate>
		<guid isPermaLink="false">http://e02.omespino.com/?p=457#comment-5931</guid>

					<description><![CDATA[This is an amazing finding man. You recon process is very simple. Keep up the good work.]]></description>
			<content:encoded><![CDATA[<p>This is an amazing finding man. You recon process is very simple. Keep up the good work.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: omespino		</title>
		<link>/write-up-google-bug-bounty-lfi-on-production-servers-in-redacted-google-com-13337-usd/#comment-5836</link>

		<dc:creator><![CDATA[omespino]]></dc:creator>
		<pubDate>Fri, 06 Sep 2019 22:14:53 +0000</pubDate>
		<guid isPermaLink="false">http://e02.omespino.com/?p=457#comment-5836</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;/write-up-google-bug-bounty-lfi-on-production-servers-in-redacted-google-com-13337-usd/#comment-5813&quot;&gt;Afolic&lt;/a&gt;.

Hey thanks  for reading, I created a custom list from Fuzz and Discovery/Web-Content, but to be honest at the end I always use the all.txt from Jhaddix and wait, for parameter bruce forcing I never look for that but I have reading that Arjun by somd3v is really cool to do that https://github.com/s0md3v/Arjun]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="/write-up-google-bug-bounty-lfi-on-production-servers-in-redacted-google-com-13337-usd/#comment-5813">Afolic</a>.</p>
<p>Hey thanks  for reading, I created a custom list from Fuzz and Discovery/Web-Content, but to be honest at the end I always use the all.txt from Jhaddix and wait, for parameter bruce forcing I never look for that but I have reading that Arjun by somd3v is really cool to do that <a href="https://github.com/s0md3v/Arjun" rel="nofollow ugc">https://github.com/s0md3v/Arjun</a></p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Afolic		</title>
		<link>/write-up-google-bug-bounty-lfi-on-production-servers-in-redacted-google-com-13337-usd/#comment-5813</link>

		<dc:creator><![CDATA[Afolic]]></dc:creator>
		<pubDate>Sun, 01 Sep 2019 23:06:53 +0000</pubDate>
		<guid isPermaLink="false">http://e02.omespino.com/?p=457#comment-5813</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;/write-up-google-bug-bounty-lfi-on-production-servers-in-redacted-google-com-13337-usd/#comment-5710&quot;&gt;omespino&lt;/a&gt;.

Thanks for this amazing write-up, I really would like to know your recommendation on the wordlist to use, seclist has tons of wordlist and that makes it difficulty to choice the correct one for dir bruteforce and also I would love to Know if there is any wordlist for parameter bruteforce, not sure if that&#039;s a thing. Thanks for the write up once again.]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="/write-up-google-bug-bounty-lfi-on-production-servers-in-redacted-google-com-13337-usd/#comment-5710">omespino</a>.</p>
<p>Thanks for this amazing write-up, I really would like to know your recommendation on the wordlist to use, seclist has tons of wordlist and that makes it difficulty to choice the correct one for dir bruteforce and also I would love to Know if there is any wordlist for parameter bruteforce, not sure if that&#8217;s a thing. Thanks for the write up once again.</p>
]]></content:encoded>
		
			</item>
	</channel>
</rss>
