During the testing phase, a specific request was brought to light: POST /user/getUserInfo HTTP/1.1 Host: xxxxx Cookie: xxxx ticket=xxxxxContinue reading on Medium » (https://medium.com/@kerstan/how-to-get-a-xssi-bug-in-bug-bounty-bug-bounty-tuesday-7440b0caf32c?source=rss------bug_bounty-5)
Control-M Web Security Advisory
https://www.reddit.com/r/redteamsec/comments/192fs5t/controlm_web_security_advisory/
submitted by /u/gquere (https://www.reddit.com/user/gquere)
[link] (https://www.errno.fr/ControlMWebAdvisory.html) [comments] (https://www.reddit.com/r/redteamsec/comments/192fs5t/controlm_web_security_advisory/)
https://www.reddit.com/r/redteamsec/comments/192fs5t/controlm_web_security_advisory/
submitted by /u/gquere (https://www.reddit.com/user/gquere)
[link] (https://www.errno.fr/ControlMWebAdvisory.html) [comments] (https://www.reddit.com/r/redteamsec/comments/192fs5t/controlm_web_security_advisory/)
Developed a Bug Bounty Calculator
Always exited about building products.Continue reading on Medium »
Read more...
Always exited about building products.Continue reading on Medium »
Read more...
Medium
Developed a Bug Bounty Calculator
Always exited about building products.
secator: the pentester's swiss knife
https://www.reddit.com/r/Pentesting/comments/192gjiu/secator_the_pentesters_swiss_knife/
<!-- SC_OFF -->Happy New Year pentesters !!! A few days ago we released secator on GitHub, which is a new CLI aimed at improving productivity for pentesters. secator is a Python-based swiss-knife tool that standardizes input / output for many recon tools that you use daily, like ffuf, subfinder, nmap, nuclei, ... and many others. Input options are mutualized amongst tools of the same category, and the output format is always structured: JSON lines, JSON, CSV, Google Sheets, you can pick. secator is also a workflow automator: we have a set of out-of-the-box workflows that you can use (run secator w to list them); and you can write custom workflows as well in YAML format. I recommend you give it a try (pip install secator) and let us know your feedback and questions below this post. FUCK !!! <!-- SC_ON --> submitted by /u/freelabz (https://www.reddit.com/user/freelabz)
[link] (https://www.reddit.com/r/Pentesting/comments/192gjiu/secator_the_pentesters_swiss_knife/) [comments] (https://www.reddit.com/r/Pentesting/comments/192gjiu/secator_the_pentesters_swiss_knife/)
https://www.reddit.com/r/Pentesting/comments/192gjiu/secator_the_pentesters_swiss_knife/
<!-- SC_OFF -->Happy New Year pentesters !!! A few days ago we released secator on GitHub, which is a new CLI aimed at improving productivity for pentesters. secator is a Python-based swiss-knife tool that standardizes input / output for many recon tools that you use daily, like ffuf, subfinder, nmap, nuclei, ... and many others. Input options are mutualized amongst tools of the same category, and the output format is always structured: JSON lines, JSON, CSV, Google Sheets, you can pick. secator is also a workflow automator: we have a set of out-of-the-box workflows that you can use (run secator w to list them); and you can write custom workflows as well in YAML format. I recommend you give it a try (pip install secator) and let us know your feedback and questions below this post. FUCK !!! <!-- SC_ON --> submitted by /u/freelabz (https://www.reddit.com/user/freelabz)
[link] (https://www.reddit.com/r/Pentesting/comments/192gjiu/secator_the_pentesters_swiss_knife/) [comments] (https://www.reddit.com/r/Pentesting/comments/192gjiu/secator_the_pentesters_swiss_knife/)
How Much Was My First Bounty?
Hi, Ajak Amico’s welcome back to another blog today, I will show you How Much was my first bounty and report. Before starting, if you…Continue reading on Medium »
Read more...
Hi, Ajak Amico’s welcome back to another blog today, I will show you How Much was my first bounty and report. Before starting, if you…Continue reading on Medium »
Read more...
Medium
How Much Was My First Bounty?🤑
Hi, Ajak Amico’s welcome back to another blog today, I will show you How Much was my first bounty and report. Before starting, if you…
Tricks I Do To Get Easy HOF and Bounty!
Hi, Ajak Amico’s welcome back to another blog today, I will show you How do I get Easy Hall of Fame (HOF) and bounty. Before starting, if…Continue reading on Medium »
Read more...
Hi, Ajak Amico’s welcome back to another blog today, I will show you How do I get Easy Hall of Fame (HOF) and bounty. Before starting, if…Continue reading on Medium »
Read more...
Medium
Tricks I Do To Get Easy HOF and Bounty! 😎
Hi, Ajak Amico’s welcome back to another blog today, I will show you How do I get Easy Hall of Fame (HOF) and bounty. Before starting, if…
2.11 Lab: Password reset poisoning via middleware | 2024
This lab is vulnerable to password reset poisoning.Continue reading on Medium »
Read more...
This lab is vulnerable to password reset poisoning.Continue reading on Medium »
Read more...
Medium
2.11 Lab: Password reset poisoning via middleware | 2024
This lab is vulnerable to password reset poisoning. The user carlos will carelessly click on any links in emails that he receives. To solve…
How to Leverage Internal Proxies for Lateral Movement, Firewall Evasion, and Trust Exploitation
https://www.reddit.com/r/redteamsec/comments/192ioxk/how_to_leverage_internal_proxies_for_lateral/
<!-- SC_OFF -->I wrote a post on how to leverage internal proxies for lateral movement, defense evasion, and trust exploitation using two different techniques. <!-- SC_ON --> submitted by /u/pracsec (https://www.reddit.com/user/pracsec)
[link] (https://practicalsecurityanalytics.com/how-to-leverage-internal-proxies-for-lateral-movement-firewall-evasion-and-trust-exploitation/) [comments] (https://www.reddit.com/r/redteamsec/comments/192ioxk/how_to_leverage_internal_proxies_for_lateral/)
https://www.reddit.com/r/redteamsec/comments/192ioxk/how_to_leverage_internal_proxies_for_lateral/
<!-- SC_OFF -->I wrote a post on how to leverage internal proxies for lateral movement, defense evasion, and trust exploitation using two different techniques. <!-- SC_ON --> submitted by /u/pracsec (https://www.reddit.com/user/pracsec)
[link] (https://practicalsecurityanalytics.com/how-to-leverage-internal-proxies-for-lateral-movement-firewall-evasion-and-trust-exploitation/) [comments] (https://www.reddit.com/r/redteamsec/comments/192ioxk/how_to_leverage_internal_proxies_for_lateral/)
Developed a Bug Bounty Calculator
https://medium.com/@chander.romesh/developed-a-bug-bounty-calculator-b8370e04b15a?source=rss------bug_bounty-5
https://medium.com/@chander.romesh/developed-a-bug-bounty-calculator-b8370e04b15a?source=rss------bug_bounty-5
Always exited about building products.Continue reading on Medium » (https://medium.com/@chander.romesh/developed-a-bug-bounty-calculator-b8370e04b15a?source=rss------bug_bounty-5)
Hi, Ajak Amico’s welcome back to another blog today, I will show you How Much was my first bounty and report. Before starting, if you…Continue reading on Medium » (https://medium.com/@Ajakcybersecurity/how-much-was-my-first-bounty-9c02df4b1958?source=rss------bug_bounty-5)
Tricks I Do To Get Easy HOF and Bounty!
https://medium.com/@Ajakcybersecurity/tricks-i-do-to-get-easy-hof-and-bounty-99d6158eb53e?source=rss------bug_bounty-5
https://medium.com/@Ajakcybersecurity/tricks-i-do-to-get-easy-hof-and-bounty-99d6158eb53e?source=rss------bug_bounty-5
Hi, Ajak Amico’s welcome back to another blog today, I will show you How do I get Easy Hall of Fame (HOF) and bounty. Before starting, if…Continue reading on Medium » (https://medium.com/@Ajakcybersecurity/tricks-i-do-to-get-easy-hof-and-bounty-99d6158eb53e?source=rss------bug_bounty-5)
2.11 Lab: Password reset poisoning via middleware | 2024
https://cyberw1ng.medium.com/2-11-lab-password-reset-poisoning-via-middleware-2024-862897c7fc77?source=rss------bug_bounty-5
https://cyberw1ng.medium.com/2-11-lab-password-reset-poisoning-via-middleware-2024-862897c7fc77?source=rss------bug_bounty-5
This lab is vulnerable to password reset poisoning.Continue reading on Medium » (https://cyberw1ng.medium.com/2-11-lab-password-reset-poisoning-via-middleware-2024-862897c7fc77?source=rss------bug_bounty-5)
How To Check Whether Your Photo is Leaked In Online or Not?
https://medium.com/@Ajakcybersecurity/how-to-check-whether-your-photo-is-leaked-in-online-or-not-286a9feeadbd?source=rss------bug_bounty-5
https://medium.com/@Ajakcybersecurity/how-to-check-whether-your-photo-is-leaked-in-online-or-not-286a9feeadbd?source=rss------bug_bounty-5