Get PentesterLab stickers
https://pentesterlab.com/100
https://pentesterlab.com/100
Pentesterlab
Learn Web Penetration Testing: The Right Way
Shopping Products For Free- Parameter Tampering Vulnerability
https://blog.usejournal.com/shopping-products-for-free-parameter-tampering-vulnerability-8e09e1471596
https://blog.usejournal.com/shopping-products-for-free-parameter-tampering-vulnerability-8e09e1471596
Medium
Shopping Products For Free- Parameter Tampering Vulnerability
Let’s bargain online from an e-commerce website
The $12,000 Intersection between Clickjacking, XSS, and Denial of Service
https://medium.com/@imashishmathur/the-12-000-intersection-between-clickjacking-xss-and-denial-of-service-f8cdb3c5e6d1
https://medium.com/@imashishmathur/the-12-000-intersection-between-clickjacking-xss-and-denial-of-service-f8cdb3c5e6d1
Paypal bug $10K - All Secondary users account takeover leads to unauthorized money transfer from paypal business accounts
https://whitehathaji.blogspot.com/2019/07/paypal-bug-10k-all-secondary-users.html
https://whitehathaji.blogspot.com/2019/07/paypal-bug-10k-all-secondary-users.html
The 7 Main XSS Cases Everyone Should Know
https://brutelogic.com.br/blog/the-7-main-xss-cases-everyone-should-know/
https://brutelogic.com.br/blog/the-7-main-xss-cases-everyone-should-know/
Whenever you see a link with two parameters try changing one of them and check if the value gets accepted
https://medium.com/@baibhavanandjha/xx-to-xxx-in-one-day-9578858b6286
https://medium.com/@baibhavanandjha/xx-to-xxx-in-one-day-9578858b6286
Medium
How I made $$$$ attending one day bug bounty workshop.
This is my story about how a web security vulnerability workshop organized by BoutntyBash helped me multiply my money in one day.
SQL Injection Extracts Starbucks Enterprise Accounting, Financial, Payroll Database
https://hackerone.com/reports/531051
https://hackerone.com/reports/531051
HackerOne
Starbucks disclosed on HackerOne: SQL Injection Extracts Starbucks...
As described in the Hacker Summary, @spaceraccoon discovered a SQL Injection vulnerability in a web service backed by Microsoft Dynamics AX. @spaceraccoon demonstrated that the flaw was exploitable...
Change OPTIONS method into GET method to find XSS and SQLi
https://twitter.com/xalerafera/status/1156906139881267206
https://twitter.com/xalerafera/status/1156906139881267206
Twitter
Bogdan Bodishtyanu
If you come across requests with the OPTIONS method, do not miss them. Try changing them to the GET method and try to find XSS and SQL injection vulnerabilities! Good luck for hunting. #BugBountyTip #Hacker0x01 #TogetherWeHitHarder
HTTP Desync Attacks: Request Smuggling Reborn
https://portswigger.net/blog/http-desync-attacks-request-smuggling-reborn
https://portswigger.net/blog/http-desync-attacks-request-smuggling-reborn
PortSwigger Research
HTTP Desync Attacks: Request Smuggling Reborn
Checking for leaked API keys while normal surfing
https://twitter.com/Momenbassel/status/1158987288975740929
https://twitter.com/Momenbassel/status/1158987288975740929
Twitter
Mo'men Basel
#bugbountytip: install keyFinder at your browser(https://t.co/TqSwU28eb4) --> surf the web --> go to results --> check API key at https://t.co/S3jRAYOEZp #BugBounty #bugbountytips #BugbountyProTip
Attacking SSL VPN - Part 2: Breaking the Fortigate SSL VPN
https://blog.orange.tw/2019/08/attacking-ssl-vpn-part-2-breaking-the-fortigate-ssl-vpn.html
https://blog.orange.tw/2019/08/attacking-ssl-vpn-part-2-breaking-the-fortigate-ssl-vpn.html
Orange
Attacking SSL VPN - Part 2: Breaking the Fortigate SSL VPN
This is 🍊 speaking