How to find unprotected databases with Netlas.io?
Databases accessible from the Internet are an attractive target for attackers. How to make sure you are invulnerable?Continue reading on Medium »
Read more...
Databases accessible from the Internet are an attractive target for attackers. How to make sure you are invulnerable?Continue reading on Medium »
Read more...
Medium
How to find unprotected databases with Netlas.io?
Databases accessible from the Internet are an attractive target for attackers. How to make sure you are invulnerable?
Behind the Firewall: My First Valid Bug — Exposing Security Flaw in a multi-dollar Financial and…
Greetings, everyone!Continue reading on Medium »
Read more...
Greetings, everyone!Continue reading on Medium »
Read more...
Medium
Behind the Firewall: My First Valid Bug — Exposing Security Flaw in a multi-dollar Financial and payment card company
Greetings, everyone!
Beyond Search Queries: Bug Bounty Hunting with Dorkz
Beyond Search Queries: Bug Bounty Hunting with DorkzContinue reading on Medium »
Read more...
Beyond Search Queries: Bug Bounty Hunting with DorkzContinue reading on Medium »
Read more...
Medium
Beyond Search Queries: Bug Bounty Hunting with Dorkz
Beyond Search Queries: Bug Bounty Hunting with Dorkz
How to find unprotected databases with Netlas.io?
https://netlas.medium.com/how-to-find-unprotected-databases-with-netlas-io-2bf186e9fc2d?source=rss------bug_bounty-5
https://netlas.medium.com/how-to-find-unprotected-databases-with-netlas-io-2bf186e9fc2d?source=rss------bug_bounty-5
Databases accessible from the Internet are an attractive target for attackers. How to make sure you are invulnerable?Continue reading on Medium » (https://netlas.medium.com/how-to-find-unprotected-databases-with-netlas-io-2bf186e9fc2d?source=rss------bug_bounty-5)
Behind the Firewall: My First Valid Bug — Exposing Security Flaw in a multi-dollar Financial and…
https://medium.com/@MohaseenK/behind-the-firewall-my-first-valid-bug-exposing-security-flaw-in-a-multi-dollar-financial-and-ff56e7bc4589?source=rss------bug_bounty-5
https://medium.com/@MohaseenK/behind-the-firewall-my-first-valid-bug-exposing-security-flaw-in-a-multi-dollar-financial-and-ff56e7bc4589?source=rss------bug_bounty-5
Greetings, everyone!Continue reading on Medium » (https://medium.com/@MohaseenK/behind-the-firewall-my-first-valid-bug-exposing-security-flaw-in-a-multi-dollar-financial-and-ff56e7bc4589?source=rss------bug_bounty-5)
Beyond Search Queries: Bug Bounty Hunting with Dorkz
https://medium.com/@paxnull/beyond-search-queries-bug-bounty-hunting-with-dorkz-850cfa8c3ddc?source=rss------bug_bounty-5
https://medium.com/@paxnull/beyond-search-queries-bug-bounty-hunting-with-dorkz-850cfa8c3ddc?source=rss------bug_bounty-5
Beyond Search Queries: Bug Bounty Hunting with DorkzContinue reading on Medium » (https://medium.com/@paxnull/beyond-search-queries-bug-bounty-hunting-with-dorkz-850cfa8c3ddc?source=rss------bug_bounty-5)
Pentesting OT/ICS Environment
https://www.reddit.com/r/redteamsec/comments/18tj4wf/pentesting_otics_environment/
<!-- SC_OFF -->I am quite new to OT/ICS area, Looking for advice on conducting a thorough pentest on OT/ICS networks following the Purdue model. What methodologies should I consider when approaching this? Should I perform the tests from the same level or opt for a different approach? Seeking guidance on the best practices and strategies for a comprehensive assessment. If someone has resources related to this, would be highly helpful. <!-- SC_ON --> submitted by /u/Self-financed-hacker (https://www.reddit.com/user/Self-financed-hacker)
[link] (https://www.reddit.com/r/redteamsec/comments/18tj4wf/pentesting_otics_environment/) [comments] (https://www.reddit.com/r/redteamsec/comments/18tj4wf/pentesting_otics_environment/)
https://www.reddit.com/r/redteamsec/comments/18tj4wf/pentesting_otics_environment/
<!-- SC_OFF -->I am quite new to OT/ICS area, Looking for advice on conducting a thorough pentest on OT/ICS networks following the Purdue model. What methodologies should I consider when approaching this? Should I perform the tests from the same level or opt for a different approach? Seeking guidance on the best practices and strategies for a comprehensive assessment. If someone has resources related to this, would be highly helpful. <!-- SC_ON --> submitted by /u/Self-financed-hacker (https://www.reddit.com/user/Self-financed-hacker)
[link] (https://www.reddit.com/r/redteamsec/comments/18tj4wf/pentesting_otics_environment/) [comments] (https://www.reddit.com/r/redteamsec/comments/18tj4wf/pentesting_otics_environment/)
1.15 Lab: SQL injection attack, querying the database type and version on Oracle | 2023
This lab contains a SQL injection vulnerability in the product category filter. You can use a UNION attack to retrieve the results from an…Continue reading on Medium »
Read more...
This lab contains a SQL injection vulnerability in the product category filter. You can use a UNION attack to retrieve the results from an…Continue reading on Medium »
Read more...
Medium
1.15 Lab: SQL injection attack, querying the database type and version on Oracle | 2023
This lab contains a SQL injection vulnerability in the product category filter. You can use a UNION attack to retrieve the results from an…
1.15 Lab: SQL injection attack, querying the database type and version on Oracle | 2023
https://cyberw1ng.medium.com/1-15-lab-sql-injection-attack-querying-the-database-type-and-version-on-oracle-2023-cd4118eb604d?source=rss------bug_bounty-5
https://cyberw1ng.medium.com/1-15-lab-sql-injection-attack-querying-the-database-type-and-version-on-oracle-2023-cd4118eb604d?source=rss------bug_bounty-5
This lab contains a SQL injection vulnerability in the product category filter. You can use a UNION attack to retrieve the results from an…Continue reading on Medium » (https://cyberw1ng.medium.com/1-15-lab-sql-injection-attack-querying-the-database-type-and-version-on-oracle-2023-cd4118eb604d?source=rss------bug_bounty-5)
Vulnerability Scanning Options
https://www.reddit.com/r/Pentesting/comments/18tt6de/vulnerability_scanning_options/
<!-- SC_OFF -->Im looking for my best option to vulnerability scan multiple client networks regularly. We were first looking at tenable MSSP for some of their solutions which are priced per asset at each client. I’m wondering if one of the Nessus licenses with unlimited assets could be a more economical solution for my company. Like we could install Nessus on a laptop, VPN in or physically go to the network location and run a scan? This way we could charge clients less and also profit more ourselves. I know there are other solutions such as OpenVAS but I’m not familiar with them. I’d love to learn more or get any information on my options here. <!-- SC_ON --> submitted by /u/LevitatingGuru (https://www.reddit.com/user/LevitatingGuru)
[link] (https://www.reddit.com/r/Pentesting/comments/18tt6de/vulnerability_scanning_options/) [comments] (https://www.reddit.com/r/Pentesting/comments/18tt6de/vulnerability_scanning_options/)
https://www.reddit.com/r/Pentesting/comments/18tt6de/vulnerability_scanning_options/
<!-- SC_OFF -->Im looking for my best option to vulnerability scan multiple client networks regularly. We were first looking at tenable MSSP for some of their solutions which are priced per asset at each client. I’m wondering if one of the Nessus licenses with unlimited assets could be a more economical solution for my company. Like we could install Nessus on a laptop, VPN in or physically go to the network location and run a scan? This way we could charge clients less and also profit more ourselves. I know there are other solutions such as OpenVAS but I’m not familiar with them. I’d love to learn more or get any information on my options here. <!-- SC_ON --> submitted by /u/LevitatingGuru (https://www.reddit.com/user/LevitatingGuru)
[link] (https://www.reddit.com/r/Pentesting/comments/18tt6de/vulnerability_scanning_options/) [comments] (https://www.reddit.com/r/Pentesting/comments/18tt6de/vulnerability_scanning_options/)
200 Materials of CyberSecurity in PDFs
https://medium.com/@dineshpathro593/200-materials-of-cybersecurity-in-pdfs-e7a942123be5?source=rss------bug_bounty-5
https://medium.com/@dineshpathro593/200-materials-of-cybersecurity-in-pdfs-e7a942123be5?source=rss------bug_bounty-5
CLICK HEREContinue reading on Medium » (https://medium.com/@dineshpathro593/200-materials-of-cybersecurity-in-pdfs-e7a942123be5?source=rss------bug_bounty-5)