From Novice to Ninja A Beginner’s Guide to Bug Bounty Hunting”
In the ever-evolving landscape of cybersecurity, bug bounty hunting has emerged as a lucrative and rewarding pursuit for aspiring ethical…Continue reading on Medium »
Read more...
In the ever-evolving landscape of cybersecurity, bug bounty hunting has emerged as a lucrative and rewarding pursuit for aspiring ethical…Continue reading on Medium »
Read more...
Medium
From Novice to Ninja A Beginner’s Guide to Bug Bounty Hunting”
In the ever-evolving landscape of cybersecurity, bug bounty hunting has emerged as a lucrative and rewarding pursuit for aspiring ethical…
“Bug Bounty Best Practices Lessons Learned from Industry Experts”
Bug bounty programs have become indispensable tools for organizations looking to bolster their cybersecurity defenses by harnessing the…Continue reading on Medium »
Read more...
Bug bounty programs have become indispensable tools for organizations looking to bolster their cybersecurity defenses by harnessing the…Continue reading on Medium »
Read more...
Medium
“Bug Bounty Best Practices Lessons Learned from Industry Experts”
Bug bounty programs have become indispensable tools for organizations looking to bolster their cybersecurity defenses by harnessing the…
The Story of How I Hacked a Website with a Simple Stored XSS Payload (And How Bugcrowd Turned Me…
https://medium.com/@iamrizwanvp/the-story-of-how-i-hacked-a-website-with-a-simple-stored-xss-payload-and-how-bugcrowd-turned-me-63773d5906ff?source=rss------bug_bounty-5
Hey guys,Continue reading on Medium » (https://medium.com/@iamrizwanvp/the-story-of-how-i-hacked-a-website-with-a-simple-stored-xss-payload-and-how-bugcrowd-turned-me-63773d5906ff?source=rss------bug_bounty-5)
https://medium.com/@iamrizwanvp/the-story-of-how-i-hacked-a-website-with-a-simple-stored-xss-payload-and-how-bugcrowd-turned-me-63773d5906ff?source=rss------bug_bounty-5
Hey guys,Continue reading on Medium » (https://medium.com/@iamrizwanvp/the-story-of-how-i-hacked-a-website-with-a-simple-stored-xss-payload-and-how-bugcrowd-turned-me-63773d5906ff?source=rss------bug_bounty-5)
The Story of How I Hacked a Website with a Simple Stored XSS Payload (And How Bugcrowd Turned Me…
Hey guys,Continue reading on Medium »
Read more...
Hey guys,Continue reading on Medium »
Read more...
Medium
The Story of How I Hacked a Website with a Simple Stored XSS Payload
Hey guys,
CVE-2024-23897 - Jenkins <= 2.441 & <= LTS 2.426.2 PoC And Scanner
http://www.kitploit.com/2024/02/cve-2024-23897-jenkins-2441-lts-24262.html
http://www.kitploit.com/2024/02/cve-2024-23897-jenkins-2441-lts-24262.html
Exploitation and scanning (https://www.kitploit.com/search/label/Scanning) tool specifically designed for Jenkins versions <= 2.441 & <= LTS 2.426.2. It leverages CVE-2024-23897 to assess and exploit vulnerabilities (https://www.kitploit.com/search/label/vulnerabilities) in Jenkins instances.
Usage
Ensure you have the necessary permissions to scan (https://www.kitploit.com/search/label/Scan) and exploit the target systems. Use this tool responsibly and ethically. python CVE-2024-23897.py -t -p -f
or python CVE-2024-23897.py -i -f
Parameters: - -t or --target: Specify the target IP(s). Supports single IP, IP range, comma-separated list, or CIDR (https://www.kitploit.com/search/label/CIDR) block. - -i or --input-file: Path to input file containing hosts in the format of http://1.2.3.4:8080/ (one per line). - -o or --output-file: Export results to file (optional). - -p or --port: Specify the port number. Default is 8080 (optional). - -f or --file: Specify the file to read on the target system.
Changelog
[27th January 2024] - Feature Request
Added scanning/exploiting via input file with hosts (-i INPUT_FILE). Added export to file (-o OUTPUT_FILE).
[26th January 2024] - Initial Release
Initial release.
Contributing
Contributions are welcome. Please feel free to fork, modify, and make pull requests or report issues.
Author
Alexander Hagenah - URL (https://primepage.de/) - Twitter (https://twitter.com/xaitax)
Disclaimer
This tool is meant for educational and professional purposes only. Unauthorized scanning and exploiting (https://www.kitploit.com/search/label/Exploiting) of systems is illegal and unethical. Always ensure you have explicit permission to test and exploit any systems you target.
Download CVE-2024-23897 (https://github.com/xaitax/CVE-2024-23897)
Usage
Ensure you have the necessary permissions to scan (https://www.kitploit.com/search/label/Scan) and exploit the target systems. Use this tool responsibly and ethically. python CVE-2024-23897.py -t -p -f
or python CVE-2024-23897.py -i -f
Parameters: - -t or --target: Specify the target IP(s). Supports single IP, IP range, comma-separated list, or CIDR (https://www.kitploit.com/search/label/CIDR) block. - -i or --input-file: Path to input file containing hosts in the format of http://1.2.3.4:8080/ (one per line). - -o or --output-file: Export results to file (optional). - -p or --port: Specify the port number. Default is 8080 (optional). - -f or --file: Specify the file to read on the target system.
Changelog
[27th January 2024] - Feature Request
Added scanning/exploiting via input file with hosts (-i INPUT_FILE). Added export to file (-o OUTPUT_FILE).
[26th January 2024] - Initial Release
Initial release.
Contributing
Contributions are welcome. Please feel free to fork, modify, and make pull requests or report issues.
Author
Alexander Hagenah - URL (https://primepage.de/) - Twitter (https://twitter.com/xaitax)
Disclaimer
This tool is meant for educational and professional purposes only. Unauthorized scanning and exploiting (https://www.kitploit.com/search/label/Exploiting) of systems is illegal and unethical. Always ensure you have explicit permission to test and exploit any systems you target.
Download CVE-2024-23897 (https://github.com/xaitax/CVE-2024-23897)
IntroductionContinue reading on Medium » (https://medium.com/@R00tendo/crlf-injection-ae26521c5e4c?source=rss------bug_bounty-5)
5 big political questions for 2024
https://www.reddit.com/r/redteamsec/comments/1azlnn1/5_big_political_questions_for_2024/
submitted by /u/hoang252 (https://www.reddit.com/user/hoang252)
[link] (https://devishop.gives/5-big-political-questions-for-2024/) [comments] (https://www.reddit.com/r/redteamsec/comments/1azlnn1/5_big_political_questions_for_2024/)
https://www.reddit.com/r/redteamsec/comments/1azlnn1/5_big_political_questions_for_2024/
submitted by /u/hoang252 (https://www.reddit.com/user/hoang252)
[link] (https://devishop.gives/5-big-political-questions-for-2024/) [comments] (https://www.reddit.com/r/redteamsec/comments/1azlnn1/5_big_political_questions_for_2024/)
I took over 10 Million Accounts, Easy API Hacking
I hacked 10 Million+ Accounts and here’s exactly how i did it. Easiest API hacking you’ll ever see.Continue reading on Medium »
Read more...
I hacked 10 Million+ Accounts and here’s exactly how i did it. Easiest API hacking you’ll ever see.Continue reading on Medium »
Read more...
Medium
I took over 10 Million Accounts, Easy API Hacking
I hacked 10 Million+ Accounts and here’s exactly how i did it. Easiest API hacking you’ll ever see.
I took over 10 Million Accounts, Easy API Hacking
https://infosecwriteups.com/i-took-over-10-million-accounts-easy-api-hacking-89a7092abe40?source=rss------bug_bounty-5
https://infosecwriteups.com/i-took-over-10-million-accounts-easy-api-hacking-89a7092abe40?source=rss------bug_bounty-5
I hacked 10 Million+ Accounts and here’s exactly how i did it. Easiest API hacking you’ll ever see.Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/i-took-over-10-million-accounts-easy-api-hacking-89a7092abe40?source=rss------bug_bounty-5)
10.5 Lab: Blind SSRF with out-of-band detection | 2024
This site uses analytics software which fetches the URL specified in the Referer header when a product page is loaded. To solve the lab…Continue reading on Medium »
Read more...
This site uses analytics software which fetches the URL specified in the Referer header when a product page is loaded. To solve the lab…Continue reading on Medium »
Read more...
10.5 Lab: Blind SSRF with out-of-band detection | 2024
https://cyberw1ng.medium.com/10-5-lab-blind-ssrf-with-out-of-band-detection-2024-2497bcf7859c?source=rss------bug_bounty-5
https://cyberw1ng.medium.com/10-5-lab-blind-ssrf-with-out-of-band-detection-2024-2497bcf7859c?source=rss------bug_bounty-5
This site uses analytics software which fetches the URL specified in the Referer header when a product page is loaded. To solve the lab…Continue reading on Medium » (https://cyberw1ng.medium.com/10-5-lab-blind-ssrf-with-out-of-band-detection-2024-2497bcf7859c?source=rss------bug_bounty-5)
Beyond the Wall: Bypassing OTP, WAF, and 403 for exploiting a SQL Injection
In this blog post, I’m going to share my experience exploiting a SQL Injection after bypassing WAF, the 403 Status Code, and OTP on a VDP…Continue reading on Medium »
Read more...
In this blog post, I’m going to share my experience exploiting a SQL Injection after bypassing WAF, the 403 Status Code, and OTP on a VDP…Continue reading on Medium »
Read more...
Medium
Beyond the Wall: Bypassing OTP, WAF, and 403 for exploiting a SQL Injection
In this blog post, I’m going to share my experience exploiting a SQL Injection after bypassing WAF, the 403 Status Code, and OTP on a VDP…