Hunting in the Cyber World: Effective Recon Strategies for a Successful Bug Bounty
### **Introduction: What is Bug Bounty and Recon?**Continue reading on Medium »
Read more...
### **Introduction: What is Bug Bounty and Recon?**Continue reading on Medium »
Read more...
Medium
Hunting in the Cyber World: Effective Recon Strategies for a Successful Bug Bounty
### **Introduction: What is Bug Bounty and Recon?**
Google Dorks Secrets: Discover Hidden Endpoints & Parameters with Google Dorks
Introduction:Continue reading on Medium »
Read more...
Introduction:Continue reading on Medium »
Read more...
Medium
Google Dorks Secrets: Discover Hidden Endpoints & Parameters with Google Dorks
Introduction:
Just released a simple post exploitation tool for penetration testers and red teamers(Contributions and PRs are welcome!)
https://www.reddit.com/r/redteamsec/comments/1fb9rou/just_released_a_simple_post_exploitation_tool_for/
submitted by /u/Straight-Layer-6804 (https://www.reddit.com/user/Straight-Layer-6804)
[link] (https://github.com/alexdhital/Infiltrax) [comments] (https://www.reddit.com/r/redteamsec/comments/1fb9rou/just_released_a_simple_post_exploitation_tool_for/)
https://www.reddit.com/r/redteamsec/comments/1fb9rou/just_released_a_simple_post_exploitation_tool_for/
submitted by /u/Straight-Layer-6804 (https://www.reddit.com/user/Straight-Layer-6804)
[link] (https://github.com/alexdhital/Infiltrax) [comments] (https://www.reddit.com/r/redteamsec/comments/1fb9rou/just_released_a_simple_post_exploitation_tool_for/)
How to find XXE(XML External Entities) vulnerabilities during Secure Code Review
https://www.reddit.com/r/Pentesting/comments/1fb5ulf/how_to_find_xxexml_external_entities/
https://www.reddit.com/r/Pentesting/comments/1fb5ulf/how_to_find_xxexml_external_entities/
submitted by /u/Electronic_Village_8 (https://www.reddit.com/user/Electronic_Village_8)
[link] (https://www.youtube.com/watch?v=HKDe1z7_AII) [comments] (https://www.reddit.com/r/Pentesting/comments/1fb5ulf/how_to_find_xxexml_external_entities/)
[link] (https://www.youtube.com/watch?v=HKDe1z7_AII) [comments] (https://www.reddit.com/r/Pentesting/comments/1fb5ulf/how_to_find_xxexml_external_entities/)
Custom Scripts Location
https://www.reddit.com/r/Pentesting/comments/1fbbwur/custom_scripts_location/
<!-- SC_OFF -->Where do most pen testers store there custom scripts? Things they pull down fron github ect? What is considered the correct location? I've seen /usr/local/bin and /opt as recommended solutions. What locations do you guys use and why? I apologize if this has been asked and beat to death here before. Thank you for sharing your time and knowledge. <!-- SC_ON --> submitted by /u/Think-Tangelo-3710 (https://www.reddit.com/user/Think-Tangelo-3710)
[link] (https://www.reddit.com/r/Pentesting/comments/1fbbwur/custom_scripts_location/) [comments] (https://www.reddit.com/r/Pentesting/comments/1fbbwur/custom_scripts_location/)
https://www.reddit.com/r/Pentesting/comments/1fbbwur/custom_scripts_location/
<!-- SC_OFF -->Where do most pen testers store there custom scripts? Things they pull down fron github ect? What is considered the correct location? I've seen /usr/local/bin and /opt as recommended solutions. What locations do you guys use and why? I apologize if this has been asked and beat to death here before. Thank you for sharing your time and knowledge. <!-- SC_ON --> submitted by /u/Think-Tangelo-3710 (https://www.reddit.com/user/Think-Tangelo-3710)
[link] (https://www.reddit.com/r/Pentesting/comments/1fbbwur/custom_scripts_location/) [comments] (https://www.reddit.com/r/Pentesting/comments/1fbbwur/custom_scripts_location/)
My recon methodology for hunting CVE-2021–42063 led to discovering an RXSS vulnerability in the…
https://medium.com/@karthithehacker/my-recon-methodology-for-hunting-cve-2021-42063-led-to-discovering-an-rxss-vulnerability-in-the-80bd4ca0f623?source=rss------bug_bounty-5
https://medium.com/@karthithehacker/my-recon-methodology-for-hunting-cve-2021-42063-led-to-discovering-an-rxss-vulnerability-in-the-80bd4ca0f623?source=rss------bug_bounty-5
During one of my bug bounty hunting sessions, I came across an interesting vulnerability: CVE-2021–42063. Let me walk you through how I…Continue reading on Medium » (https://medium.com/@karthithehacker/my-recon-methodology-for-hunting-cve-2021-42063-led-to-discovering-an-rxss-vulnerability-in-the-80bd4ca0f623?source=rss------bug_bounty-5)
Find Your First 5 Bug Bounties in Easy Ways
https://infosecwriteups.com/find-your-first-5-bug-bounties-in-easy-ways-3aaca5c57a2d?source=rss------bug_bounty-5
https://infosecwriteups.com/find-your-first-5-bug-bounties-in-easy-ways-3aaca5c57a2d?source=rss------bug_bounty-5
Bug bounty hunting is a fun way to earn money by finding security issues in websites and apps. If you’re just starting, don’t worry! In…Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/find-your-first-5-bug-bounties-in-easy-ways-3aaca5c57a2d?source=rss------bug_bounty-5)
850$ IDOR:Unauthorized Session Revokation of any user
https://infosecwriteups.com/850-idor-unauthorized-session-revokation-of-any-user-93f9cb92fdfe?source=rss------bug_bounty-5
https://infosecwriteups.com/850-idor-unauthorized-session-revokation-of-any-user-93f9cb92fdfe?source=rss------bug_bounty-5
Hi Everyone, I’m thrilled to share another intriguing vulnerability I uncovered, this time in Codecov’s session management system. This…Continue reading on InfoSec Write-ups » (https://infosecwriteups.com/850-idor-unauthorized-session-revokation-of-any-user-93f9cb92fdfe?source=rss------bug_bounty-5)
Hunting in the Cyber World: Effective Recon Strategies for a Successful Bug Bounty
https://medium.com/@rootspaghetti/hunting-in-the-cyber-world-effective-recon-strategies-for-a-successful-bug-bounty-8ec5f27bd9ae?source=rss------bug_bounty-5
https://medium.com/@rootspaghetti/hunting-in-the-cyber-world-effective-recon-strategies-for-a-successful-bug-bounty-8ec5f27bd9ae?source=rss------bug_bounty-5
### **Introduction: What is Bug Bounty and Recon?**Continue reading on Medium » (https://medium.com/@rootspaghetti/hunting-in-the-cyber-world-effective-recon-strategies-for-a-successful-bug-bounty-8ec5f27bd9ae?source=rss------bug_bounty-5)
Google Dorks Secrets: Discover Hidden Endpoints & Parameters with Google Dorks
https://enigma96.medium.com/google-dorks-secrets-discover-hidden-endpoints-parameters-with-google-dorks-7c3bb3257ef9?source=rss------bug_bounty-5
https://enigma96.medium.com/google-dorks-secrets-discover-hidden-endpoints-parameters-with-google-dorks-7c3bb3257ef9?source=rss------bug_bounty-5