Airbnb — When Bypassing JSON Encoding, XSS Filter, WAF, CSP, and Auditor turns into Eight…
Learn More About Cyber Security , Hacking And Get Your First Certificate For Free On …Continue reading on Medium »
Read more...
Learn More About Cyber Security , Hacking And Get Your First Certificate For Free On …Continue reading on Medium »
Read more...
C2 agnostic proxy?
https://www.reddit.com/r/redteamsec/comments/1dyxr67/c2_agnostic_proxy/
<!-- SC_OFF -->Hi Fellas, we are thinking of using C2 agnostic proxy. While the cobalstrike socks proxy works well, we have faced some issues (beacon dies without detection, etc). Our main goal is to have inline execution without fork and run. We have tried using with following issues - 1. Sharpsocks - doesn't work at all 2. SharpChisel - works through websockets which our redirectors don't support (azure frontdoor CDN) Any ideas? <!-- SC_ON --> submitted by /u/Remarkable-Injury877 (https://www.reddit.com/user/Remarkable-Injury877)
[link] (https://google.com/) [comments] (https://www.reddit.com/r/redteamsec/comments/1dyxr67/c2_agnostic_proxy/)
https://www.reddit.com/r/redteamsec/comments/1dyxr67/c2_agnostic_proxy/
<!-- SC_OFF -->Hi Fellas, we are thinking of using C2 agnostic proxy. While the cobalstrike socks proxy works well, we have faced some issues (beacon dies without detection, etc). Our main goal is to have inline execution without fork and run. We have tried using with following issues - 1. Sharpsocks - doesn't work at all 2. SharpChisel - works through websockets which our redirectors don't support (azure frontdoor CDN) Any ideas? <!-- SC_ON --> submitted by /u/Remarkable-Injury877 (https://www.reddit.com/user/Remarkable-Injury877)
[link] (https://google.com/) [comments] (https://www.reddit.com/r/redteamsec/comments/1dyxr67/c2_agnostic_proxy/)
Account Takeover via Weak Reset Token Entropy
Diving in how entropy can affect the security of reset tokens and may lead to account takeovers.Continue reading on Medium »
Read more...
Diving in how entropy can affect the security of reset tokens and may lead to account takeovers.Continue reading on Medium »
Read more...
Medium
Account Takeover via flawed reset mechanism
Diving in how entropy can affect the security of reset tokens and may lead to account takeovers.
Continue reading on Medium » (https://d3xxyz.medium.com/d%CE%BEx-bug-bounty-5e1d0c7f8408?source=rss------bug_bounty-5)
XSS TÜRLERİ TEST CASE
https://medium.com/@aarda418/xss-t%C3%BCrleri%CC%87-test-case-a4ab5849100f?source=rss------bug_bounty-5
Selamlar ben Arda Aslan. Gallipoli Bug Bounty topluluğunun ikinci task i olarak bu blogu hazırladım. Keyifli okumalar…Continue reading on Medium » (https://medium.com/@aarda418/xss-t%C3%BCrleri%CC%87-test-case-a4ab5849100f?source=rss------bug_bounty-5)
https://medium.com/@aarda418/xss-t%C3%BCrleri%CC%87-test-case-a4ab5849100f?source=rss------bug_bounty-5
Selamlar ben Arda Aslan. Gallipoli Bug Bounty topluluğunun ikinci task i olarak bu blogu hazırladım. Keyifli okumalar…Continue reading on Medium » (https://medium.com/@aarda418/xss-t%C3%BCrleri%CC%87-test-case-a4ab5849100f?source=rss------bug_bounty-5)
Airbnb — When Bypassing JSON Encoding, XSS Filter, WAF, CSP, and Auditor turns into Eight…
https://medium.com/@proseizala/airbnb-when-bypassing-json-encoding-xss-filter-waf-csp-and-auditor-turns-into-eight-92a004f1cbe8?source=rss------bug_bounty-5
https://medium.com/@proseizala/airbnb-when-bypassing-json-encoding-xss-filter-waf-csp-and-auditor-turns-into-eight-92a004f1cbe8?source=rss------bug_bounty-5
Learn More About Cyber Security , Hacking And Get Your First Certificate For Free On …Continue reading on Medium » (https://medium.com/@proseizala/airbnb-when-bypassing-json-encoding-xss-filter-waf-csp-and-auditor-turns-into-eight-92a004f1cbe8?source=rss------bug_bounty-5)
Account Takeover via Weak Reset Token Entropy
https://medium.com/@majix_de/account-takeover-via-weak-reset-token-entropy-c475268daae6?source=rss------bug_bounty-5
https://medium.com/@majix_de/account-takeover-via-weak-reset-token-entropy-c475268daae6?source=rss------bug_bounty-5
Diving in how entropy can affect the security of reset tokens and may lead to account takeovers.Continue reading on Medium » (https://medium.com/@majix_de/account-takeover-via-weak-reset-token-entropy-c475268daae6?source=rss------bug_bounty-5)
Nmap Cheat Sheet For Penetration Testing.
https://medium.com/@umarhere4u/nmap-cheat-sheet-for-penetration-testing-70b555b91285?source=rss------bug_bounty-5
https://medium.com/@umarhere4u/nmap-cheat-sheet-for-penetration-testing-70b555b91285?source=rss------bug_bounty-5
Target Specification:Continue reading on Medium » (https://medium.com/@umarhere4u/nmap-cheat-sheet-for-penetration-testing-70b555b91285?source=rss------bug_bounty-5)
Nmap Cheat Sheet For Penetration Testing.
Target Specification:Continue reading on Medium »
Read more...
Target Specification:Continue reading on Medium »
Read more...
Medium
Nmap Cheat Sheet For Penetration Testing.
Target Specification:
Need Tipps
https://www.reddit.com/r/Pentesting/comments/1dyzwds/need_tipps/
<!-- SC_OFF -->Hello Guys I want ask you all pentesters for Tipps for finding vurbebulitys in web applications. I know the basics like Owasp, Burpsuit and nmap but is there more tools or how can I find vurbebulitys manually. <!-- SC_ON --> submitted by /u/AirlineCurious3456 (https://www.reddit.com/user/AirlineCurious3456)
[link] (https://www.reddit.com/r/Pentesting/comments/1dyzwds/need_tipps/) [comments] (https://www.reddit.com/r/Pentesting/comments/1dyzwds/need_tipps/)
https://www.reddit.com/r/Pentesting/comments/1dyzwds/need_tipps/
<!-- SC_OFF -->Hello Guys I want ask you all pentesters for Tipps for finding vurbebulitys in web applications. I know the basics like Owasp, Burpsuit and nmap but is there more tools or how can I find vurbebulitys manually. <!-- SC_ON --> submitted by /u/AirlineCurious3456 (https://www.reddit.com/user/AirlineCurious3456)
[link] (https://www.reddit.com/r/Pentesting/comments/1dyzwds/need_tipps/) [comments] (https://www.reddit.com/r/Pentesting/comments/1dyzwds/need_tipps/)
Complex Attack Types: Sample Scenarios 38
In this article, we will hijack the machine in front of us with our technical knowledge and target-oriented cyber security tools. We will…Continue reading on Medium »
Read more...
In this article, we will hijack the machine in front of us with our technical knowledge and target-oriented cyber security tools. We will…Continue reading on Medium »
Read more...
Medium
Complex Attack Types: Sample Scenarios 38
In this article, we will hijack the machine in front of us with our technical knowledge and target-oriented cyber security tools. We will…
any good resources for learning powershell? also how am i supposed to virtualize these complex ad setups? do i just do small bits of it or what? im trying to start with red teaming
https://www.reddit.com/r/redteamsec/comments/1dz3d6o/any_good_resources_for_learning_powershell_also/
submitted by /u/Total_Ad7843 (https://www.reddit.com/user/Total_Ad7843)
[link] (https://github.com/davidprowe/BadBlood) [comments] (https://www.reddit.com/r/redteamsec/comments/1dz3d6o/any_good_resources_for_learning_powershell_also/)
https://www.reddit.com/r/redteamsec/comments/1dz3d6o/any_good_resources_for_learning_powershell_also/
submitted by /u/Total_Ad7843 (https://www.reddit.com/user/Total_Ad7843)
[link] (https://github.com/davidprowe/BadBlood) [comments] (https://www.reddit.com/r/redteamsec/comments/1dz3d6o/any_good_resources_for_learning_powershell_also/)
Seeking Advice from VAPT Experts in Our Community!
https://www.reddit.com/r/Pentesting/comments/1dz3bqh/seeking_advice_from_vapt_experts_in_our_community/
<!-- SC_OFF -->Hey everyone, I'm reaching out to our community of VAPT experts for some guidance. As someone enthusiastic about VAPT, I'm keen to hear from those who have extensive experience in this specialized field. Could you share your career journey and insights into VAPT? What certifications have been most valuable to you, and why? Any tips or advice you can offer would be incredibly helpful for someone like me who is passionate about entering this challenging yet rewarding area. Looking forward to hearing your thoughts and learning from your experiences! <!-- SC_ON --> submitted by /u/2x7r (https://www.reddit.com/user/2x7r)
[link] (https://www.reddit.com/r/Pentesting/comments/1dz3bqh/seeking_advice_from_vapt_experts_in_our_community/) [comments] (https://www.reddit.com/r/Pentesting/comments/1dz3bqh/seeking_advice_from_vapt_experts_in_our_community/)
https://www.reddit.com/r/Pentesting/comments/1dz3bqh/seeking_advice_from_vapt_experts_in_our_community/
<!-- SC_OFF -->Hey everyone, I'm reaching out to our community of VAPT experts for some guidance. As someone enthusiastic about VAPT, I'm keen to hear from those who have extensive experience in this specialized field. Could you share your career journey and insights into VAPT? What certifications have been most valuable to you, and why? Any tips or advice you can offer would be incredibly helpful for someone like me who is passionate about entering this challenging yet rewarding area. Looking forward to hearing your thoughts and learning from your experiences! <!-- SC_ON --> submitted by /u/2x7r (https://www.reddit.com/user/2x7r)
[link] (https://www.reddit.com/r/Pentesting/comments/1dz3bqh/seeking_advice_from_vapt_experts_in_our_community/) [comments] (https://www.reddit.com/r/Pentesting/comments/1dz3bqh/seeking_advice_from_vapt_experts_in_our_community/)