Business Logic Flaws A Critical Look at Business Application Security
In today’s rapidly evolving digital landscape, businesses rely heavily on complex applications to manage their operations, connect with…Continue reading on Medium »
Read more...
In today’s rapidly evolving digital landscape, businesses rely heavily on complex applications to manage their operations, connect with…Continue reading on Medium »
Read more...
Medium
Business Logic Flaws A Critical Look at Business Application Security
In today’s rapidly evolving digital landscape, businesses rely heavily on complex applications to manage their operations, connect with…
Zero-Day Vulnerabilities The Silent Threat to Cybersecurity
In the dynamic realm of cybersecurity, few threats are as elusive and potentially devastating as zero-day vulnerabilities. These security…Continue reading on Medium »
Read more...
In the dynamic realm of cybersecurity, few threats are as elusive and potentially devastating as zero-day vulnerabilities. These security…Continue reading on Medium »
Read more...
Medium
Zero-Day Vulnerabilities The Silent Threat to Cybersecurity
In the dynamic realm of cybersecurity, few threats are as elusive and potentially devastating as zero-day vulnerabilities. These security…
Discovering an XML File Upload Vulnerability Lead to SSRF: My Bug Hunting Journey
Author: Javroot, Bug HunterContinue reading on Medium »
Read more...
Author: Javroot, Bug HunterContinue reading on Medium »
Read more...
Basic Pentesting 1 Walkthrough
Hello, in this article I will show you step by step how to solve Basic Pentesting 1. The purpose of this CTF will be to become root. Click…Continue reading on Medium »
Read more...
Hello, in this article I will show you step by step how to solve Basic Pentesting 1. The purpose of this CTF will be to become root. Click…Continue reading on Medium »
Read more...
Medium
Basic Pentesting 1 Walkthrough
Hello, in this article I will show you step by step how to solve Basic Pentesting 1. The purpose of this CTF will be to become root. Click…
This is how i escalated self XSS with CSRF
https://medium.com/@pvnk24/this-is-how-i-escalated-self-xss-with-csrf-80113ab3080e?source=rss------bug_bounty-5
Hi guys, Hope you are doing great, i am Pavan, Today i am going to share how i escalated a self XSS with CSRF.Continue reading on Medium » (https://medium.com/@pvnk24/this-is-how-i-escalated-self-xss-with-csrf-80113ab3080e?source=rss------bug_bounty-5)
https://medium.com/@pvnk24/this-is-how-i-escalated-self-xss-with-csrf-80113ab3080e?source=rss------bug_bounty-5
Hi guys, Hope you are doing great, i am Pavan, Today i am going to share how i escalated a self XSS with CSRF.Continue reading on Medium » (https://medium.com/@pvnk24/this-is-how-i-escalated-self-xss-with-csrf-80113ab3080e?source=rss------bug_bounty-5)
does pentesting = 9-5 ?
https://www.reddit.com/r/Pentesting/comments/1e82py6/does_pentesting_95/
<!-- SC_OFF -->i’m wondering what the work hours of most pentesters are looking like . does pentesting only come in a full time 9-5 format ? how does it work ? after getting a pentesting job would i have time for any of my other work ? (modeling and music) <!-- SC_ON --> submitted by /u/AlexandreKingsworth (https://www.reddit.com/user/AlexandreKingsworth)
[link] (https://www.reddit.com/r/Pentesting/comments/1e82py6/does_pentesting_95/) [comments] (https://www.reddit.com/r/Pentesting/comments/1e82py6/does_pentesting_95/)
https://www.reddit.com/r/Pentesting/comments/1e82py6/does_pentesting_95/
<!-- SC_OFF -->i’m wondering what the work hours of most pentesters are looking like . does pentesting only come in a full time 9-5 format ? how does it work ? after getting a pentesting job would i have time for any of my other work ? (modeling and music) <!-- SC_ON --> submitted by /u/AlexandreKingsworth (https://www.reddit.com/user/AlexandreKingsworth)
[link] (https://www.reddit.com/r/Pentesting/comments/1e82py6/does_pentesting_95/) [comments] (https://www.reddit.com/r/Pentesting/comments/1e82py6/does_pentesting_95/)
Comp-Sci or Cybersecurity Degree?
https://www.reddit.com/r/Pentesting/comments/1e85r40/compsci_or_cybersecurity_degree/
<!-- SC_OFF -->Good afternoon, soldiers. I am currently employed as Desktop support (tier 2 support) and enrolled in WGU for Cyber Security with the career goal of becoming a Pen-tester / Ethical Hacker. I just secured my A+ certification and I am now working on Network+ then security+ before switching to computer science degree next term. I still have 5 months before I have to commit to my decision I wanted to ask you guys your opinions. As Pentesters do you believe there is more value in understanding computer architecture and programming or would it be better to stick to the security concepts and certifications that a Cyber degree offers? Personally I find programming more difficult than security concepts <!-- SC_ON --> submitted by /u/heavymetalusa (https://www.reddit.com/user/heavymetalusa)
[link] (https://www.reddit.com/r/Pentesting/comments/1e85r40/compsci_or_cybersecurity_degree/) [comments] (https://www.reddit.com/r/Pentesting/comments/1e85r40/compsci_or_cybersecurity_degree/)
https://www.reddit.com/r/Pentesting/comments/1e85r40/compsci_or_cybersecurity_degree/
<!-- SC_OFF -->Good afternoon, soldiers. I am currently employed as Desktop support (tier 2 support) and enrolled in WGU for Cyber Security with the career goal of becoming a Pen-tester / Ethical Hacker. I just secured my A+ certification and I am now working on Network+ then security+ before switching to computer science degree next term. I still have 5 months before I have to commit to my decision I wanted to ask you guys your opinions. As Pentesters do you believe there is more value in understanding computer architecture and programming or would it be better to stick to the security concepts and certifications that a Cyber degree offers? Personally I find programming more difficult than security concepts <!-- SC_ON --> submitted by /u/heavymetalusa (https://www.reddit.com/user/heavymetalusa)
[link] (https://www.reddit.com/r/Pentesting/comments/1e85r40/compsci_or_cybersecurity_degree/) [comments] (https://www.reddit.com/r/Pentesting/comments/1e85r40/compsci_or_cybersecurity_degree/)
TryHackMe — NahamStore — Walkthrough
In this room you will learn the basics of bug bounty hunting and web application hacking.Continue reading on Medium »
Read more...
In this room you will learn the basics of bug bounty hunting and web application hacking.Continue reading on Medium »
Read more...
Medium
TryHackMe — NahamStore — Walkthrough
In this room you will learn the basics of bug bounty hunting and web application hacking.
TryHackMe — NahamStore — Walkthrough
https://medium.com/@nayanjyoti16/tryhackme-nahamstore-walkthrough-d4ecfe586c96?source=rss------bug_bounty-5
In this room you will learn the basics of bug bounty hunting and web application hacking.Continue reading on Medium » (https://medium.com/@nayanjyoti16/tryhackme-nahamstore-walkthrough-d4ecfe586c96?source=rss------bug_bounty-5)
https://medium.com/@nayanjyoti16/tryhackme-nahamstore-walkthrough-d4ecfe586c96?source=rss------bug_bounty-5
In this room you will learn the basics of bug bounty hunting and web application hacking.Continue reading on Medium » (https://medium.com/@nayanjyoti16/tryhackme-nahamstore-walkthrough-d4ecfe586c96?source=rss------bug_bounty-5)
CVE-2024–40725 and CVE-2024–40898: Critical Vulnerabilities in Apache HTTP Server
Explore the details of CVE-2024–40725 and CVE-2024–40898, two critical vulnerabilities in Apache HTTP Server. Learn about the risks…Continue reading on InfoSec Write-ups »
Read more...
Explore the details of CVE-2024–40725 and CVE-2024–40898, two critical vulnerabilities in Apache HTTP Server. Learn about the risks…Continue reading on InfoSec Write-ups »
Read more...
Medium
CVE-2024–40725 and CVE-2024–40898: Critical Vulnerabilities in Apache HTTP Server
Explore the details of CVE-2024–40725 and CVE-2024–40898, two critical vulnerabilities in Apache HTTP Server. Learn about the risks…
CVE-2024–40725 and CVE-2024–40898: Critical Vulnerabilities in Apache HTTP Server
https://infosecwriteups.com/cve-2024-40725-and-cve-2024-40898-critical-vulnerabilities-in-apache-http-server-d292084255dc?source=rss------bug_bounty-5
https://infosecwriteups.com/cve-2024-40725-and-cve-2024-40898-critical-vulnerabilities-in-apache-http-server-d292084255dc?source=rss------bug_bounty-5
Explore the details of CVE-2024–40725 and CVE-2024–40898, two critical vulnerabilities in Apache HTTP Server. Learn about the risks…Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/cve-2024-40725-and-cve-2024-40898-critical-vulnerabilities-in-apache-http-server-d292084255dc?source=rss------bug_bounty-5)
How I bypassed payment in one of the popular mobile apk and got free subsciption
Helloo hackers, I hope you are doing well, in this blog I’m gonna show you how I bypassed the payment in one of the popular talking…Continue reading on Medium »
Read more...
Helloo hackers, I hope you are doing well, in this blog I’m gonna show you how I bypassed the payment in one of the popular talking…Continue reading on Medium »
Read more...
Medium
How I bypassed payment in one of the popular mobile apk and got free subsciption 😁
Helloo hackers, I hope you are doing well, in this blog I’m gonna show you how I bypassed the payment in one of the popular talking…
How To Setup Private Interactsh Server
Setting Up Your Own Private OOB Vulnerability Discovery ServerContinue reading on Medium »
Read more...
Setting Up Your Own Private OOB Vulnerability Discovery ServerContinue reading on Medium »
Read more...
Medium
How To Setup Private Interactsh Server
Setting Up Your Own Private OOB Vulnerability Discovery Server
14.27 Lab: Reflected XSS with event handlers and href attributes blocked
This lab contains a reflected XSS vulnerability with some whitelisted tags, but all events and anchor href attributes are blocked.Continue reading on Medium »
Read more...
This lab contains a reflected XSS vulnerability with some whitelisted tags, but all events and anchor href attributes are blocked.Continue reading on Medium »
Read more...
Medium
14.27 Lab: Reflected XSS with event handlers and href attributes blocked
This lab contains a reflected XSS vulnerability with some whitelisted tags, but all events and anchor href attributes are blocked. To solve…
Community Building in Bug Bounties: The Power of Networking and Collaboration
In the world of cybersecurity, the concept of community has always been a cornerstone of innovation and progress. From the early days of…Continue reading on Medium »
Read more...
In the world of cybersecurity, the concept of community has always been a cornerstone of innovation and progress. From the early days of…Continue reading on Medium »
Read more...
Medium
Community Building in Bug Bounties: The Power of Networking and Collaboration
In the world of cybersecurity, the concept of community has always been a cornerstone of innovation and progress. From the early days of…
Advanced XXE Injection
A Bug Hunter’s Poetic Reflection of a Blind Type Injection vulnerabilityContinue reading on ILLUMINATION »
Read more...
A Bug Hunter’s Poetic Reflection of a Blind Type Injection vulnerabilityContinue reading on ILLUMINATION »
Read more...
Medium
Advanced XXE Injection
A Bug Hunter’s Poetic Reflection of a Blind Type Injection vulnerability
How I bypassed payment in one of the popular mobile apk and got free subsciption
https://medium.com/@deepk007/how-i-bypassed-payment-in-one-of-the-popular-mobile-apk-and-got-free-subsciption-46e94f61c089?source=rss------bug_bounty-5
https://medium.com/@deepk007/how-i-bypassed-payment-in-one-of-the-popular-mobile-apk-and-got-free-subsciption-46e94f61c089?source=rss------bug_bounty-5
Helloo hackers, I hope you are doing well, in this blog I’m gonna show you how I bypassed the payment in one of the popular talking…Continue reading on Medium » (https://medium.com/@deepk007/how-i-bypassed-payment-in-one-of-the-popular-mobile-apk-and-got-free-subsciption-46e94f61c089?source=rss------bug_bounty-5)