Hi guys. This will be my last reflected xss write-up for now. We should focus more complex vulnerabilities. We need more reading and learning. Until next month, I plan to stop find bugs and learn a lot more technique. Because I'm new in bug bounty and I'm looking for xss predominantly.

Anyway, let's start. 🐱‍💻

1 - Google Dork

An easy and effective tool to use. It is a tool that I use constantly, not just when looking for a target.

Screenshot

Also you should check following resources…

Listing of a number of useful Google dorks

Google Hacking Database

Google Dork List

2 - Look everywhere

First target was

After a little browsing, I discovered the target page.

Screenshot

Then I viewed the page source and looked for a reflected value.

Screenshot

It was very easy. Let's try to get XSS. Oops

Screenshot

Then I saw that this site redirect me to the pro.sony site.

Screenshot

I thought this was the same code and when I looked at the same place, the result was positive.

Screenshot

I tried to get xss right away, but I came across akamai.

Screenshot
Screenshot

Let's find a payload using twitter 😉

Screenshot
https://twitter.com/niksthehacker
Screenshot

New report with waf bypass.

Thank you and sorry about my bad english. As I learn new things, I will try to share with you. You can follow to be informed about new write-ups.