Hello hackers, I am back with a new bug bounty write-up. In this blog, I am going to show how I was able to access deleted comments on a…Continue reading on Medium » (https://medium.com/@bilalresearcher/accessing-deleted-comment-for-a-bug-bounty-writeup-085e836660c1?source=rss------bug_bounty-5)
SQL Vulnerability in WordPress Automatic Plugin (CVE-2024–27956)
OverviewContinue reading on Medium »
Read more...
OverviewContinue reading on Medium »
Read more...
Medium
SQL Vulnerability in WordPress Automatic Plugin (CVE-2024–27956)
Overview
MacOS Red Teaming
https://www.reddit.com/r/redteamsec/comments/1ev4c3m/macos_red_teaming/
<!-- SC_OFF -->https://redteamrecipe.com/macos-red-teaming#heading-gathering-system-information-using-ioplatformexpertdevice <!-- SC_ON --> submitted by /u/0xAb4y98 (https://www.reddit.com/user/0xAb4y98)
[link] (https://redteamrecipe.com/macos-red-teaming#heading-gathering-system-information-using-ioplatformexpertdevice) [comments] (https://www.reddit.com/r/redteamsec/comments/1ev4c3m/macos_red_teaming/)
https://www.reddit.com/r/redteamsec/comments/1ev4c3m/macos_red_teaming/
<!-- SC_OFF -->https://redteamrecipe.com/macos-red-teaming#heading-gathering-system-information-using-ioplatformexpertdevice <!-- SC_ON --> submitted by /u/0xAb4y98 (https://www.reddit.com/user/0xAb4y98)
[link] (https://redteamrecipe.com/macos-red-teaming#heading-gathering-system-information-using-ioplatformexpertdevice) [comments] (https://www.reddit.com/r/redteamsec/comments/1ev4c3m/macos_red_teaming/)
How I Bypassed 2FA and Earned My First Bounty $$$
Hacker Summary:Continue reading on Medium »
Read more...
Hacker Summary:Continue reading on Medium »
Read more...
Medium
How I Bypassed 2FA and Earned My First Bounty $$$
Hacker Summary:
Day 15 of 30 Days — 30 Vulnerabilities | ClickJacking
Day 15: Mastering ClickJacking Vulnerability — Essential Tricks & Techniques Based on Personal Experience and Valuable POCsContinue reading on Medium »
Read more...
Day 15: Mastering ClickJacking Vulnerability — Essential Tricks & Techniques Based on Personal Experience and Valuable POCsContinue reading on Medium »
Read more...
Medium
Day 15 of 30 Days — 30 Vulnerabilities | ClickJacking
Day 15: Mastering ClickJacking Vulnerability — Essential Tricks & Techniques Based on Personal Experience and Valuable POCs
What to check after automated scan
https://www.reddit.com/r/Pentesting/comments/1ev37vh/what_to_check_after_automated_scan/
<!-- SC_OFF -->Hi, We’re currently using automated scanning tools for our web application, which effectively catch the usual vulnerabilities. I’m curious to know what additional checks or manual assessments you typically perform after the automated scans. For instance, do you focus on areas like error handling, access control, or something else? Any insights on key areas that might be overlooked by automated tools would be greatly appreciated! <!-- SC_ON --> submitted by /u/TheITSecGuy (https://www.reddit.com/user/TheITSecGuy)
[link] (https://www.reddit.com/r/Pentesting/comments/1ev37vh/what_to_check_after_automated_scan/) [comments] (https://www.reddit.com/r/Pentesting/comments/1ev37vh/what_to_check_after_automated_scan/)
https://www.reddit.com/r/Pentesting/comments/1ev37vh/what_to_check_after_automated_scan/
<!-- SC_OFF -->Hi, We’re currently using automated scanning tools for our web application, which effectively catch the usual vulnerabilities. I’m curious to know what additional checks or manual assessments you typically perform after the automated scans. For instance, do you focus on areas like error handling, access control, or something else? Any insights on key areas that might be overlooked by automated tools would be greatly appreciated! <!-- SC_ON --> submitted by /u/TheITSecGuy (https://www.reddit.com/user/TheITSecGuy)
[link] (https://www.reddit.com/r/Pentesting/comments/1ev37vh/what_to_check_after_automated_scan/) [comments] (https://www.reddit.com/r/Pentesting/comments/1ev37vh/what_to_check_after_automated_scan/)
HTML Injection in Mobile App Support Ticket Form on target.tech
Overview: I was invited to a private bug bounty program hosted on YesWeHack. After reviewing the program’s rules, during this testing…Continue reading on Medium »
Read more...
Overview: I was invited to a private bug bounty program hosted on YesWeHack. After reviewing the program’s rules, during this testing…Continue reading on Medium »
Read more...
Medium
HTML Injection in Mobile App Support Ticket Form on target.tech
Overview: I was invited to a private bug bounty program hosted on YesWeHack. After reviewing the program’s rules, during this testing…
Needing bug bounty results for a 6-month internship - does it make sense ?
https://www.reddit.com/r/Pentesting/comments/1ev83zk/needing_bug_bounty_results_for_a_6month/
<!-- SC_OFF -->Hi there, it's been a year since I decided to switch careers and focus on pentesting. I recently started looking for an internship in my area (Belgium) and found an interesting company. I saw they were seeking an intern for 6 months, but after some emails, I quickly hit a wall. They asked me for bug bounty history and ultimately chose someone else who had already had some success in bug bounties. Should an intern already be able to manage bug hunting independently? This situation left me a bit lost. I’ve spent a lot of time learning and practicing almost all types of web vulnerabilities, and I completed all the PortSwigger labs. I thought that would be an adequate level of knowledge to get an internship in the field. As I want to work at that company, I spent the weekend working on some programs listed on HackerOne, and I'll probably continue until I have at least one "credit" to put on my resume. But what are your thoughts on this? Should an intern already have that level of experience? What level do you expect when hiring an intern in pentesting? Thanks! <!-- SC_ON --> submitted by /u/Snoo_11846 (https://www.reddit.com/user/Snoo_11846)
[link] (https://www.reddit.com/r/Pentesting/comments/1ev83zk/needing_bug_bounty_results_for_a_6month/) [comments] (https://www.reddit.com/r/Pentesting/comments/1ev83zk/needing_bug_bounty_results_for_a_6month/)
https://www.reddit.com/r/Pentesting/comments/1ev83zk/needing_bug_bounty_results_for_a_6month/
<!-- SC_OFF -->Hi there, it's been a year since I decided to switch careers and focus on pentesting. I recently started looking for an internship in my area (Belgium) and found an interesting company. I saw they were seeking an intern for 6 months, but after some emails, I quickly hit a wall. They asked me for bug bounty history and ultimately chose someone else who had already had some success in bug bounties. Should an intern already be able to manage bug hunting independently? This situation left me a bit lost. I’ve spent a lot of time learning and practicing almost all types of web vulnerabilities, and I completed all the PortSwigger labs. I thought that would be an adequate level of knowledge to get an internship in the field. As I want to work at that company, I spent the weekend working on some programs listed on HackerOne, and I'll probably continue until I have at least one "credit" to put on my resume. But what are your thoughts on this? Should an intern already have that level of experience? What level do you expect when hiring an intern in pentesting? Thanks! <!-- SC_ON --> submitted by /u/Snoo_11846 (https://www.reddit.com/user/Snoo_11846)
[link] (https://www.reddit.com/r/Pentesting/comments/1ev83zk/needing_bug_bounty_results_for_a_6month/) [comments] (https://www.reddit.com/r/Pentesting/comments/1ev83zk/needing_bug_bounty_results_for_a_6month/)
Advanced Techniques and Emerging Trends in Web Cache Poisoning
Exploring the Mechanics, Risks, and Defense Strategies Against Web Cache Poisoning Attacks. Web cache poisoning is a sophisticated attack…Continue reading on Medium »
Read more...
Exploring the Mechanics, Risks, and Defense Strategies Against Web Cache Poisoning Attacks. Web cache poisoning is a sophisticated attack…Continue reading on Medium »
Read more...
Medium
Advanced Techniques and Emerging Trends in Web Cache Poisoning
Exploring the Mechanics, Risks, and Defense Strategies Against Web Cache Poisoning Attacks. Web cache poisoning is a sophisticated attack…
SQL Vulnerability in WordPress Automatic Plugin (CVE-2024–27956)
https://roadtooscp.medium.com/sql-vulnerability-in-wordpress-automatic-plugin-cve-2024-27956-3635f1d32b4e?source=rss------bug_bounty-5
https://roadtooscp.medium.com/sql-vulnerability-in-wordpress-automatic-plugin-cve-2024-27956-3635f1d32b4e?source=rss------bug_bounty-5
OverviewContinue reading on Medium » (https://roadtooscp.medium.com/sql-vulnerability-in-wordpress-automatic-plugin-cve-2024-27956-3635f1d32b4e?source=rss------bug_bounty-5)
How I Bypassed 2FA and Earned My First Bounty $$$
https://anonysm.medium.com/how-i-bypassed-2fa-and-earned-my-first-bounty-3fdc58938347?source=rss------bug_bounty-5
https://anonysm.medium.com/how-i-bypassed-2fa-and-earned-my-first-bounty-3fdc58938347?source=rss------bug_bounty-5
Hacker Summary:Continue reading on Medium » (https://anonysm.medium.com/how-i-bypassed-2fa-and-earned-my-first-bounty-3fdc58938347?source=rss------bug_bounty-5)
Day 15 of 30 Days — 30 Vulnerabilities | ClickJacking
https://it4chis3c.medium.com/day-15-of-30-days-30-vulnerabilities-clickjacking-592505aff54d?source=rss------bug_bounty-5
https://it4chis3c.medium.com/day-15-of-30-days-30-vulnerabilities-clickjacking-592505aff54d?source=rss------bug_bounty-5
Day 15: Mastering ClickJacking Vulnerability — Essential Tricks & Techniques Based on Personal Experience and Valuable POCsContinue reading on Medium » (https://it4chis3c.medium.com/day-15-of-30-days-30-vulnerabilities-clickjacking-592505aff54d?source=rss------bug_bounty-5)
HTML Injection in Mobile App Support Ticket Form on target.tech
https://medium.com/@shobitsharma/html-injection-in-mobile-app-support-ticket-form-on-target-tech-f45d2de510af?source=rss------bug_bounty-5
https://medium.com/@shobitsharma/html-injection-in-mobile-app-support-ticket-form-on-target-tech-f45d2de510af?source=rss------bug_bounty-5
Overview: I was invited to a private bug bounty program hosted on YesWeHack. After reviewing the program’s rules, during this testing…Continue reading on Medium » (https://medium.com/@shobitsharma/html-injection-in-mobile-app-support-ticket-form-on-target-tech-f45d2de510af?source=rss------bug_bounty-5)