Threat actors misusing Quick Assist in social engineering attacks leading to ransomware
https://www.reddit.com/r/redteamsec/comments/1csqdxj/threat_actors_misusing_quick_assist_in_social/
submitted by /u/SCI_Rusher (https://www.reddit.com/user/SCI_Rusher)
[link] (https://aka.ms/MisusingQuickAssist) [comments] (https://www.reddit.com/r/redteamsec/comments/1csqdxj/threat_actors_misusing_quick_assist_in_social/)
https://www.reddit.com/r/redteamsec/comments/1csqdxj/threat_actors_misusing_quick_assist_in_social/
submitted by /u/SCI_Rusher (https://www.reddit.com/user/SCI_Rusher)
[link] (https://aka.ms/MisusingQuickAssist) [comments] (https://www.reddit.com/r/redteamsec/comments/1csqdxj/threat_actors_misusing_quick_assist_in_social/)
Why I want to become a bug bounty hunter
Instead of choosing the easy path of just finishing uni and then getting some tech job, I am teaching myself bug bounty hunting besides…Continue reading on Medium »
Read more...
Instead of choosing the easy path of just finishing uni and then getting some tech job, I am teaching myself bug bounty hunting besides…Continue reading on Medium »
Read more...
Why I want to become a bug bounty hunter
https://medium.com/@riccilovesdogs/why-i-want-to-become-a-bug-bounty-hunter-135e4f584af6?source=rss------bug_bounty-5
Instead of choosing the easy path of just finishing uni and then getting some tech job, I am teaching myself bug bounty hunting besides…Continue reading on Medium » (https://medium.com/@riccilovesdogs/why-i-want-to-become-a-bug-bounty-hunter-135e4f584af6?source=rss------bug_bounty-5)
https://medium.com/@riccilovesdogs/why-i-want-to-become-a-bug-bounty-hunter-135e4f584af6?source=rss------bug_bounty-5
Instead of choosing the easy path of just finishing uni and then getting some tech job, I am teaching myself bug bounty hunting besides…Continue reading on Medium » (https://medium.com/@riccilovesdogs/why-i-want-to-become-a-bug-bounty-hunter-135e4f584af6?source=rss------bug_bounty-5)
Breaking Barriers: A Personal Journey Through the World of Bug Bounty Hunting
The Journey BeginsContinue reading on Medium »
Read more...
The Journey BeginsContinue reading on Medium »
Read more...
Medium
Breaking Barriers: A Personal Journey Through the World of Bug Bounty Hunting
The Journey Begins
Breaking Barriers: A Personal Journey Through the World of Bug Bounty Hunting
https://medium.com/@un1tycyb3r/breaking-barriers-a-personal-journey-through-the-world-of-bug-bounty-hunting-a30331db12fa?source=rss------bug_bounty-5
https://medium.com/@un1tycyb3r/breaking-barriers-a-personal-journey-through-the-world-of-bug-bounty-hunting-a30331db12fa?source=rss------bug_bounty-5
The Journey BeginsContinue reading on Medium » (https://medium.com/@un1tycyb3r/breaking-barriers-a-personal-journey-through-the-world-of-bug-bounty-hunting-a30331db12fa?source=rss------bug_bounty-5)
How to Create a Cloud Lab for Anonymous Bug Bounty Hunting
In the world of cybersecurity, maintaining anonymity while conducting bug bounty hunting is paramount. A secure and anonymous environment…Continue reading on Medium »
Read more...
In the world of cybersecurity, maintaining anonymity while conducting bug bounty hunting is paramount. A secure and anonymous environment…Continue reading on Medium »
Read more...
Medium
How to Create a Cloud Lab for Anonymous Bug Bounty Hunting
In the world of cybersecurity, maintaining anonymity while conducting bug bounty hunting is paramount. A secure and anonymous environment…
How to Create a Cloud Lab for Anonymous Bug Bounty Hunting
https://medium.com/@paritoshblogs/how-to-create-a-cloud-lab-for-anonymous-bug-bounty-hunting-e80ed3a68d8c?source=rss------bug_bounty-5
https://medium.com/@paritoshblogs/how-to-create-a-cloud-lab-for-anonymous-bug-bounty-hunting-e80ed3a68d8c?source=rss------bug_bounty-5
In the world of cybersecurity, maintaining anonymity while conducting bug bounty hunting is paramount. A secure and anonymous environment…Continue reading on Medium » (https://medium.com/@paritoshblogs/how-to-create-a-cloud-lab-for-anonymous-bug-bounty-hunting-e80ed3a68d8c?source=rss------bug_bounty-5)
Unveiling a Surprising Bug in KYC Verification: The Discovery Worth $$$
IntroductionContinue reading on Medium »
Read more...
IntroductionContinue reading on Medium »
Read more...
Medium
Discovery Worth $$$ in KYC Verification Feature : Bug Bounty
Introduction
Discovery Worth $$$ in KYC Verification Feature : Bug Bounty
https://medium.com/@srishavinkumar/unveiling-a-surprising-bug-in-kyc-verification-the-discovery-worth-a82f3282b033?source=rss------bug_bounty-5
https://medium.com/@srishavinkumar/unveiling-a-surprising-bug-in-kyc-verification-the-discovery-worth-a82f3282b033?source=rss------bug_bounty-5
IntroductionContinue reading on Medium » (https://medium.com/@srishavinkumar/unveiling-a-surprising-bug-in-kyc-verification-the-discovery-worth-a82f3282b033?source=rss------bug_bounty-5)
Is this an open redirect vulnerability?
https://www.reddit.com/r/Pentesting/comments/1ct8anf/is_this_an_open_redirect_vulnerability/
<!-- SC_OFF -->Hey does this count as open redirect? If so how do I fix it? goodexample.com.badexample.com (http://goodexample.com.badexample.com/) <!-- SC_ON --> submitted by /u/Dev_null34 (https://www.reddit.com/user/Dev_null34)
[link] (https://www.reddit.com/r/Pentesting/comments/1ct8anf/is_this_an_open_redirect_vulnerability/) [comments] (https://www.reddit.com/r/Pentesting/comments/1ct8anf/is_this_an_open_redirect_vulnerability/)
https://www.reddit.com/r/Pentesting/comments/1ct8anf/is_this_an_open_redirect_vulnerability/
<!-- SC_OFF -->Hey does this count as open redirect? If so how do I fix it? goodexample.com.badexample.com (http://goodexample.com.badexample.com/) <!-- SC_ON --> submitted by /u/Dev_null34 (https://www.reddit.com/user/Dev_null34)
[link] (https://www.reddit.com/r/Pentesting/comments/1ct8anf/is_this_an_open_redirect_vulnerability/) [comments] (https://www.reddit.com/r/Pentesting/comments/1ct8anf/is_this_an_open_redirect_vulnerability/)
I found a new type of web vulnerability
https://www.reddit.com/r/Pentesting/comments/1ct94jj/i_found_a_new_type_of_web_vulnerability/
<!-- SC_OFF -->Checkout my blog post about it. it's a sibling to relative path overwrite but instead of css payload, it's file injection. Not many looking for this yet, but I'm spreading the word. https://www.linkedin.com/posts/iahickey_relative-path-file-injection-the-next-evolution-activity-7193955660420591616-MnJi?utm_source=share&utm_medium=member_android <!-- SC_ON --> submitted by /u/ihickey (https://www.reddit.com/user/ihickey)
[link] (https://www.reddit.com/r/Pentesting/comments/1ct94jj/i_found_a_new_type_of_web_vulnerability/) [comments] (https://www.reddit.com/r/Pentesting/comments/1ct94jj/i_found_a_new_type_of_web_vulnerability/)
https://www.reddit.com/r/Pentesting/comments/1ct94jj/i_found_a_new_type_of_web_vulnerability/
<!-- SC_OFF -->Checkout my blog post about it. it's a sibling to relative path overwrite but instead of css payload, it's file injection. Not many looking for this yet, but I'm spreading the word. https://www.linkedin.com/posts/iahickey_relative-path-file-injection-the-next-evolution-activity-7193955660420591616-MnJi?utm_source=share&utm_medium=member_android <!-- SC_ON --> submitted by /u/ihickey (https://www.reddit.com/user/ihickey)
[link] (https://www.reddit.com/r/Pentesting/comments/1ct94jj/i_found_a_new_type_of_web_vulnerability/) [comments] (https://www.reddit.com/r/Pentesting/comments/1ct94jj/i_found_a_new_type_of_web_vulnerability/)
Security architecture price
https://www.reddit.com/r/Pentesting/comments/1ct9thh/security_architecture_price/
<!-- SC_OFF -->Good morning, We are two cyber security engineers with a MSc degree in cybersecurity and 2 years of experience in the field. Following a ramsomware attack, we were contacted by a friend’s company to try to restore encrypted data. We finished the task and restored all possibile data without any payment as a favour to our friend. His company decided to rely on us as security architects to rebuild the entire network architecture. This architecture is briefly composed of 10 machines, a NAS and it is mandatory for the company having the possibility to access the NAS data everywhere. We are newbies in this specific field but at the same time we think we have the capabilities to do a great job. We would like to receive from this fantastic community suggestions on a possible fair price to offer for this project. To sum up, the service that we are going to offer is composed of: - Security design - Implementation of the designed solution - Creation of the documentation for maintenance - Security awareness of employees (e.g. phishing campaigns prevention) <!-- SC_ON --> submitted by /u/Damzap (https://www.reddit.com/user/Damzap)
[link] (https://www.reddit.com/r/Pentesting/comments/1ct9thh/security_architecture_price/) [comments] (https://www.reddit.com/r/Pentesting/comments/1ct9thh/security_architecture_price/)
https://www.reddit.com/r/Pentesting/comments/1ct9thh/security_architecture_price/
<!-- SC_OFF -->Good morning, We are two cyber security engineers with a MSc degree in cybersecurity and 2 years of experience in the field. Following a ramsomware attack, we were contacted by a friend’s company to try to restore encrypted data. We finished the task and restored all possibile data without any payment as a favour to our friend. His company decided to rely on us as security architects to rebuild the entire network architecture. This architecture is briefly composed of 10 machines, a NAS and it is mandatory for the company having the possibility to access the NAS data everywhere. We are newbies in this specific field but at the same time we think we have the capabilities to do a great job. We would like to receive from this fantastic community suggestions on a possible fair price to offer for this project. To sum up, the service that we are going to offer is composed of: - Security design - Implementation of the designed solution - Creation of the documentation for maintenance - Security awareness of employees (e.g. phishing campaigns prevention) <!-- SC_ON --> submitted by /u/Damzap (https://www.reddit.com/user/Damzap)
[link] (https://www.reddit.com/r/Pentesting/comments/1ct9thh/security_architecture_price/) [comments] (https://www.reddit.com/r/Pentesting/comments/1ct9thh/security_architecture_price/)
Earning from pentesting
https://www.reddit.com/r/Pentesting/comments/1cta76y/earning_from_pentesting/
<!-- SC_OFF -->I have been looking to do pentests projects to earn from there. Does anyone has some experience related to that. I would like to know how to do it and do it well. I have completed few courses and have my eyes on a certification after that. Also is there any discord group for pentesters? <!-- SC_ON --> submitted by /u/thededucer43 (https://www.reddit.com/user/thededucer43)
[link] (https://www.reddit.com/r/Pentesting/comments/1cta76y/earning_from_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/1cta76y/earning_from_pentesting/)
https://www.reddit.com/r/Pentesting/comments/1cta76y/earning_from_pentesting/
<!-- SC_OFF -->I have been looking to do pentests projects to earn from there. Does anyone has some experience related to that. I would like to know how to do it and do it well. I have completed few courses and have my eyes on a certification after that. Also is there any discord group for pentesters? <!-- SC_ON --> submitted by /u/thededucer43 (https://www.reddit.com/user/thededucer43)
[link] (https://www.reddit.com/r/Pentesting/comments/1cta76y/earning_from_pentesting/) [comments] (https://www.reddit.com/r/Pentesting/comments/1cta76y/earning_from_pentesting/)
Vulnerable WordPress April 2024 (Arasbaran)
Github Repo: https://github.com/onhexgroup/Vulnerable-WordPressContinue reading on Medium »
Read more...
Github Repo: https://github.com/onhexgroup/Vulnerable-WordPressContinue reading on Medium »
Read more...
Vulnerable WordPress April 2024 (Arasbaran)
https://medium.com/@onhexgroup/vulnerable-wordpress-april-2024-arasbaran-e9ae2acb8898?source=rss------bug_bounty-5
https://medium.com/@onhexgroup/vulnerable-wordpress-april-2024-arasbaran-e9ae2acb8898?source=rss------bug_bounty-5